Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,901 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 234 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-1818 | SQL injection vulnerability in admin/admin_manager.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via an m_username cookie in an add action. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 29 May 2009 |
| CVE-2009-1817 | Multiple buffer overflows in DigiMode Maya 1.0.2 allow remote attackers to execute arbitrary code via a long string in a malformed (1) .m3u or (2) .m3l playlist file. | EXPLOIT ✓HIGH 9.3EPSS 5.55% | 29 May 2009 |
| CVE-2009-1816 | SQL injection vulnerability in admin.php in My Game Script 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka the username field). | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 29 May 2009 |
| CVE-2009-1815 | Stack-based buffer overflow in Sonic Spot Audioactive Player 1.93b allows remote attackers to execute arbitrary code via a long string in a playlist file, as demonstrated by a long .mp3 URL in a .m3u file. | EXPLOIT ×2 ✓HIGH 9.3EPSS 5.85% | 29 May 2009 |
| CVE-2009-1814 | SQL injection vulnerability in mail.php in PHPenpals 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 29 May 2009 |
| CVE-2009-1813 | Multiple SQL injection vulnerabilities in admin/index.php in Submitter Script 2 allow remote attackers to execute arbitrary SQL commands via (1) the uNev parameter (aka the username field) or (2) the uJelszo parameter (aka the Password field). | EXPLOIT ✓HIGH 7.5EPSS 2.31% | 29 May 2009 |
| CVE-2009-1812 | Multiple SQL injection vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to execute arbitrary SQL commands via (1) the formUser parameter (aka the Name field) to common/login.php, and allow remote authenticated users to execute… | EXPLOIT ✓MEDIUM 6.0EPSS 0.89% | 29 May 2009 |
| CVE-2009-1811 | Multiple cross-site scripting (XSS) vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to inject arbitrary web script or HTML via (1) the Page parameter in a List action to modules/ereignis.php, (2) the Kontext parameter in a Search… | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 29 May 2009 |
| CVE-2009-1810 | Multiple SQL injection vulnerabilities in myColex 1.4.2 allow remote attackers to execute arbitrary SQL commands via (1) the formUser parameter (aka the Name field) to common/login.php, and allow remote authenticated users to execute arbitrary SQL… | EXPLOIT ✓MEDIUM 6.0EPSS 0.89% | 29 May 2009 |
| CVE-2009-1809 | Multiple cross-site scripting (XSS) vulnerabilities in myColex 1.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the year parameter to modules/kalender.php, (2) the Page parameter in a List action to modules/ereignis.php, (3)… | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 29 May 2009 |
| CVE-2009-1808 | Microsoft Windows XP SP3 allows local users to cause a denial of service (system crash) by making an SPI_SETDESKWALLPAPER SystemParametersInfo call with an improperly terminated pvParam argument, followed by an SPI_GETDESKWALLPAPER SystemParametersInfo… | EXPLOIT ✓MEDIUM 4.9EPSS 2.83% | 28 May 2009 |
| CVE-2009-1807 | Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the SetAttributeValue method, as exploited in the wild in April and May 2009. | EXPLOIT ✓HIGH 9.3EPSS 7.53% | 28 May 2009 |
| CVE-2009-1804 | Multiple SQL injection vulnerabilities in admin/index.php in VideoScript.us YouTube Video Script allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 28 May 2009 |
| CVE-2009-1800 | Stack-based buffer overflow in the Chinagames CGAgent ActiveX control 1.x in CGAgent.dll, as distributed in Chinagames iGame 2009, allows remote attackers to execute arbitrary code via a long argument to the CreateChinagames method, as exploited in the… | EXPLOIT ✓HIGH 7.5EPSS 10.9% | 28 May 2009 |
| CVE-2009-1799 | Multiple SQL injection vulnerabilities in the getGalleryImage function in st_admin/gallery_output.php in ST-Gallery 0.1 alpha, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) gallery_category or… | EXPLOIT ✓MEDIUM 6.8EPSS 0.93% | 28 May 2009 |
| CVE-2008-6815 | mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a database backup by making a direct request, and then sending an unspecified request to the download page for the backup. | EXPLOIT ✓MEDIUM 5.0EPSS 2.81% | 28 May 2009 |
| CVE-2008-6814 | Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earlier for Mambo allows remote attackers to execute arbitrary code by uploading a file with an executable extension and an image/jpeg… | EXPLOIT ✓MEDIUM 6.8EPSS 3.33% | 28 May 2009 |
| CVE-2009-1789 | mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. | EXPLOIT ✓MEDIUM 4.3EPSS 8.49% | 26 May 2009 |
| CVE-2009-1787 | Multiple SQL injection vulnerabilities in PHP Dir Submit (aka WebsiteSubmitter and Submitter Script) allow remote attackers to bypass authentication and gain administrative access via the (1) username and (2) password parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 26 May 2009 |
| CVE-2009-1786 | The malloc subsystem in libc in IBM AIX 5.3 and 6.1 allows local users to create or overwrite arbitrary files via a symlink attack on the log file associated with the MALLOCDEBUG environment variable. | EXPLOIT ✓MEDIUM 6.9EPSS 0.67% | 26 May 2009 |
| CVE-2009-1634 | The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, which allows remote attackers to gain access to user accounts via unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 7.22% | 26 May 2009 |
| CVE-2009-1376 | Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote… | EXPLOIT ✓HIGH 9.3EPSS 13.3% | 26 May 2009 |
| CVE-2009-1781 | Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inject arbitrary PHP code into phpre_config.php via the form_aula parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.17% | 22 May 2009 |
| CVE-2009-1780 | admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters. | EXPLOIT ✓HIGH 7.5EPSS 3.76% | 22 May 2009 |
| CVE-2009-1779 | PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the form_include_template parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.85% | 22 May 2009 |
| CVE-2009-1778 | SQL injection vulnerability in the new user registration feature in BigACE CMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.17% | 22 May 2009 |
| CVE-2009-1777 | CRLF injection vulnerability in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the redirect parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 1.97% | 22 May 2009 |
| CVE-2009-1776 | Multiple cross-site scripting (XSS) vulnerabilities in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via javascript: URIs in the (1) request and (2) return_link_url… | EXPLOIT ✓MEDIUM 4.3EPSS 1.46% | 22 May 2009 |
| CVE-2009-1774 | Directory traversal vulnerability in plugins/ddb/foot.php in Strawberry 1.1.1 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 9.3EPSS 17.9% | 22 May 2009 |
| CVE-2009-1771 | index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which allows remote attackers to create or modify admin accounts via the (1) users[fullname], (2) users[email], (3) users[role_id], (4)… | EXPLOIT ✓HIGH 7.5EPSS 2.46% | 22 May 2009 |
| CVE-2009-1770 | Directory traversal vulnerability in includes/database/examples/addressbook.php in Flyspeck CMS 6.8 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.33% | 22 May 2009 |
| CVE-2009-1768 | Directory traversal vulnerability in download.php in Rama Zaiten CMS 0.9.8 and earlier allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.50% | 22 May 2009 |
| CVE-2009-1767 | admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.08% | 22 May 2009 |
| CVE-2009-1766 | SQL injection vulnerability in index.php in LightOpenCMS 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 0.85% | 22 May 2009 |
| CVE-2009-1765 | Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 15.0% | 22 May 2009 |
| CVE-2009-1764 | SQL injection vulnerability in inc/ajax.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a digg action. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 22 May 2009 |
| CVE-2009-1759 | Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent) 3.3.2 and probably earlier, and CTorrent 1.3.4, allows remote attackers to cause a denial of service (crash) and possibly execute… | EXPLOIT ✓HIGH 9.3EPSS 13.7% | 22 May 2009 |
| CVE-2009-1752 | exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which allows remote attackers to gain privileges a direct request. | EXPLOIT ✓HIGH 7.5EPSS 2.45% | 22 May 2009 |
| CVE-2009-1751 | SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 22 May 2009 |
| CVE-2009-1750 | Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors. | EXPLOIT ✓MEDIUM 6.0EPSS 2.72% | 22 May 2009 |
| CVE-2009-1749 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) userman_form and (2) webpages_form parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 3.01% | 22 May 2009 |
| CVE-2009-1748 | Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.33% | 22 May 2009 |
| CVE-2009-1747 | SQL injection vulnerability in index.php in 26th Avenue bSpeak 1.10 allows remote attackers to execute arbitrary SQL commands via the forumid parameter in a post action. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 22 May 2009 |
| CVE-2008-6813 | SQL injection vulnerability in index.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQL commands via the id_kat parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 22 May 2009 |
| CVE-2008-6812 | SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQL commands via the det parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 22 May 2009 |
| CVE-2009-1746 | SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 21 May 2009 |
| CVE-2009-1729 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the abperson_displayName parameter to uwc/abs/search.xml in… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 5.33% | 21 May 2009 |
| CVE-2009-1593 | Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "negative model," which allows remote attackers to conduct cross-site scripting (XSS) attacks via a modified end tag of a SCRIPT element. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 21 May 2009 |
| CVE-2009-1744 | InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows remote attackers to cause a denial of service (application crash) via a crafted Hollywood FX Compressed Archive (.hfz) file. | EXPLOIT ✓MEDIUM 4.3EPSS 2.17% | 21 May 2009 |
| CVE-2009-1743 | Directory traversal vulnerability in InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows remote attackers to create and overwrite arbitrary files via a filename containing a ..\ (dot dot… | EXPLOIT ✓HIGH 9.3EPSS 6.18% | 21 May 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.