Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,901 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 236 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-1625 | Directory traversal vulnerability in index.php in Thickbox Gallery 2 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 2.10% | 12 May 2009 |
| CVE-2009-1624 | Directory traversal vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.89% | 12 May 2009 |
| CVE-2009-1623 | Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary web script or HTML via the PID parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.36% | 12 May 2009 |
| CVE-2009-1622 | SQL injection vulnerability in user.php in EcShop 2.5.0 allows remote attackers to execute arbitrary SQL commands via the order_sn parameter in an order_query action. | EXPLOIT ✓HIGH 7.5EPSS 1.08% | 12 May 2009 |
| CVE-2009-1621 | Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 6.44% | 12 May 2009 |
| CVE-2009-1620 | Multiple cross-site scripting (XSS) vulnerabilities in input.php in MataChat allow remote attackers to inject arbitrary web script or HTML via the (1) nickname and (2) color parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.19% | 12 May 2009 |
| CVE-2009-1619 | Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1. | EXPLOIT ✓HIGH 7.5EPSS 2.54% | 12 May 2009 |
| CVE-2009-1618 | Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value for the TWLHadmin cookie. | EXPLOIT ✓HIGH 7.5EPSS 2.54% | 12 May 2009 |
| CVE-2009-1617 | Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&lvl=1 value for the twLTadmin cookie. | EXPLOIT ✓HIGH 7.5EPSS 2.54% | 12 May 2009 |
| CVE-2008-6808 | SQL injection vulnerability in links.php in Scripts for Sites (SFS) EZ Link Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 12 May 2009 |
| CVE-2008-6807 | PHP remote file inclusion vulnerability in ListRecords.php in osprey 1.0a4.1 allows remote attackers to execute arbitrary PHP code via a URL in the xml_dir parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.05% | 12 May 2009 |
| CVE-2008-6806 | Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in… | EXPLOIT ✓MEDIUM 6.8EPSS 4.73% | 12 May 2009 |
| CVE-2009-1616 | Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remote attackers to inject arbitrary web script or HTML via the css parameter, a different vector than CVE-2008-0505. | EXPLOIT ✓MEDIUM 4.3EPSS 1.65% | 11 May 2009 |
| CVE-2009-1615 | Unrestricted file upload vulnerability in Leap CMS 0.1.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via an admin.system.files (aka Manage Files) request to the default URI, then accessing the file… | EXPLOIT ✓MEDIUM 6.8EPSS 2.88% | 11 May 2009 |
| CVE-2009-1614 | Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the msg parameter (aka the message in an article comment) or (2) the searchterm parameter (aka the search post… | EXPLOIT ✓LOW 2.6EPSS 1.27% | 11 May 2009 |
| CVE-2009-1613 | Multiple SQL injection vulnerabilities in leap.php in Leap CMS 0.1.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchterm or (2) email parameter. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 0.96% | 11 May 2009 |
| CVE-2009-1612 | Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary code via a long argument to the OnBeforeVideoDownload method, as exploited in the wild in April and… | EXPLOIT ×2 ✓HIGH 9.3EPSS 33.3% | 11 May 2009 |
| CVE-2008-6805 | Multiple SQL injection vulnerabilities in Mic_Blog 0.0.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to category.php, the (2) user parameter to login.php, and the (3) site… | EXPLOIT ✓MEDIUM 6.8EPSS 1.12% | 11 May 2009 |
| CVE-2008-6804 | Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOKIE_LAST_ADMIN_LANG cookies. | EXPLOIT ✓HIGH 7.5EPSS 2.56% | 11 May 2009 |
| CVE-2008-6803 | SQL injection vulnerability in diziler.asp in Yigit Aybuga Dizi Portali allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 11 May 2009 |
| CVE-2009-1611 | Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 257 reply to a CWD command. | EXPLOIT ×2 ✓HIGH 10.0EPSS 7.19% | 11 May 2009 |
| CVE-2009-1610 | admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator password and gain administrator privileges via a direct request. | EXPLOIT ✓HIGH 7.5EPSS 6.11% | 11 May 2009 |
| CVE-2009-1609 | Unrestricted file upload vulnerability in admin/uploadform.asp in Battle Blog 1.25 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file. | EXPLOIT ✓MEDIUM 6.8EPSS 3.62% | 11 May 2009 |
| CVE-2009-1608 | Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrary code via a .MCP project file with long (1) FILE_INFO, (2) CAT_FILTERS, and possibly other fields. | EXPLOIT ✓HIGH 9.3EPSS 11.2% | 11 May 2009 |
| CVE-2009-1607 | Cross-site scripting (XSS) vulnerability in the administrator panel in phpForm.net LinkBase 2.0 allows remote attackers to inject arbitrary web script or HTML via the username in a registration, which is not properly handled when the administrator… | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 11 May 2009 |
| CVE-2009-1602 | Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outage or CPU consumption) via multiple long SMTP commands, as demonstrated by HELO commands. | EXPLOIT ✓MEDIUM 5.0EPSS 2.76% | 11 May 2009 |
| CVE-2009-1595 | The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action. | EXPLOIT ✓MEDIUM 4.0EPSS 2.23% | 11 May 2009 |
| CVE-2009-1592 | Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long banner. | EXPLOIT ×2 ✓HIGH 10.0EPSS 7.10% | 8 May 2009 |
| CVE-2009-1587 | index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by setting the login_id, group_id, login_name, user_id, and user_type cookies to certain values. | EXPLOIT ✓HIGH 7.5EPSS 2.61% | 7 May 2009 |
| CVE-2009-1586 | Stack-based buffer overflow in the NZB importer feature in GrabIt 1.7.2 Beta 3 and earlier allows remote attackers to execute arbitrary code via a crafted DTD reference in a DOCTYPE element in an NZB file. | EXPLOIT ×2 ✓HIGH 9.3EPSS 9.62% | 7 May 2009 |
| CVE-2009-1585 | Multiple SQL injection vulnerabilities in TemaTres 1.031, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id_correo_electronico and (2) id_password parameters to login.php. | EXPLOIT ✓MEDIUM 4.4EPSS 0.88% | 7 May 2009 |
| CVE-2009-1584 | Multiple SQL injection vulnerabilities in TemaTres 1.0.3 and 1.031, when magic_quotes_gpc is disabled, allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the (1) mail, (2) password, and (3) letra parameters to… | EXPLOIT ×2 ✓MEDIUM 6.0EPSS 2.61% | 7 May 2009 |
| CVE-2009-1583 | Multiple cross-site scripting (XSS) vulnerabilities in TemaTres 1.0.3 and 1.031 allow remote attackers to inject arbitrary web script or HTML via the (1) search form; (2) _expresion_de_busqueda, (3) letra, (4) estado_id, and (5) tema parameters to… | EXPLOIT ✓MEDIUM 4.3EPSS 3.54% | 7 May 2009 |
| CVE-2009-1582 | Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request to admin.home.php after visiting admin.php. | EXPLOIT ✓HIGH 7.5EPSS 2.80% | 7 May 2009 |
| CVE-2008-6802 | Multiple SQL injection vulnerabilities in index.php in phPhotoGallery 0.92 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields. | EXPLOIT ✓HIGH 7.5EPSS 1.75% | 7 May 2009 |
| CVE-2008-6799 | connection.php in FlashChat 5.0.8 allows remote attackers to bypass the role filter mechanism and gain administrative privileges by setting the s parameter to "7." | EXPLOIT ✓HIGH 7.5EPSS 2.83% | 7 May 2009 |
| CVE-2008-6798 | Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL commands via (1) the us parameter (aka the Username field) or (2) the ps parameter (aka the Password field). | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 7 May 2009 |
| CVE-2008-6796 | SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the username1 parameter (aka the Admin field or Username field). | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 7 May 2009 |
| CVE-2008-6795 | SQL injection vulnerability in view_news.php in nicLOR Vibro-School-CMS allows remote attackers to execute arbitrary SQL commands via the nID parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97% | 7 May 2009 |
| CVE-2008-6794 | SQL injection vulnerability in directory.php in Scripts For Sites (SFS) EZ Pub Site allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 7 May 2009 |
| CVE-2008-6793 | The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters after an arg1= sequence in a filename within a forensic image. | EXPLOIT ✓MEDIUM 6.8EPSS 6.93% | 7 May 2009 |
| CVE-2009-1574 | racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a payload, which triggers a NULL pointer dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 11.6% | 6 May 2009 |
| CVE-2009-1561 | Cross-site request forgery (CSRF) vulnerability in administration.cgi on the Cisco Linksys WRT54GC router with firmware 1.05.7 allows remote attackers to hijack the intranet connectivity of arbitrary users for requests that change the administrator… | EXPLOIT ✓MEDIUM 6.8EPSS 3.36% | 6 May 2009 |
| CVE-2009-1558 | Directory traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allows remote attackers to read arbitrary files via a %2e. | EXPLOIT ✓HIGH 7.8EPSS 29.8% | 6 May 2009 |
| CVE-2009-1557 | Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allow remote attackers to inject arbitrary web script or HTML via the next_file parameter to (1) main.cgi, (2)… | EXPLOIT ✓MEDIUM 4.3EPSS 7.47% | 6 May 2009 |
| CVE-2009-1554 | Cross-site scripting (XSS) vulnerability in ThemeServlet.java in Sun Woodstock 4.2, as used in Sun GlassFish Enterprise Server and other products, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 string in the PATH_INFO, which… | EXPLOIT ✓MEDIUM 4.3EPSS 4.05% | 6 May 2009 |
| CVE-2009-1553 | Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) applications/applications.jsf, (2)… | EXPLOIT ×8 ✓MEDIUM 4.3EPSS 8.20% | 6 May 2009 |
| CVE-2009-1551 | Multiple PHP remote file inclusion vulnerabilities in Qt quickteam 2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) qte_web_path parameter to qte_web.php and the (2) qte_root parameter to bin/qte_init.php. | EXPLOIT ✓HIGH 7.5EPSS 27.0% | 6 May 2009 |
| CVE-2009-1550 | Zakkis Technology ABC Advertise 1.0 does not properly restrict access to admin.inc.php, which allows remote attackers to obtain the administrator login name and password via a direct request. | EXPLOIT ✓MEDIUM 5.0EPSS 2.29% | 6 May 2009 |
| CVE-2009-1549 | AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto." | EXPLOIT ✓HIGH 7.5EPSS 8.61% | 6 May 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.