SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

397,901 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 237 of 501

CVESummaryPriorityPublished
CVE-2009-1548SQL injection vulnerability in index.php in BluSky CMS allows remote attackers to execute arbitrary SQL commands via the news_id parameter in a read action.EXPLOIT ✓HIGH 7.5EPSS 1.04%6 May 2009
CVE-2009-1527Race condition in the ptrace_attach function in kernel/ptrace.c in the Linux kernel before 2.6.30-rc4 allows local users to gain privileges via a PTRACE_ATTACH ptrace call during an exec system call that is launching a setuid application, related to…EXPLOIT ✓MEDIUM 6.9EPSS 0.49%5 May 2009
CVE-2009-1526JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a certain temporary directory, related to a request for this temporary file in the PATH_INFO to the CMD_DB script…EXPLOIT ✓MEDIUM 6.9EPSS 0.55%5 May 2009
CVE-2009-1469CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and WebMail Server before 9.4.2 makes it easier for remote attackers to trick a user into disclosing credentials via CRLF sequences…EXPLOIT ✓MEDIUM 4.3EPSS 4.86%5 May 2009
CVE-2009-1468Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) sql and (2)…EXPLOIT ✓MEDIUM 6.5EPSS 1.93%5 May 2009
CVE-2009-1467Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the body of a message, related to the email view and incorrect HTML…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 4.10%5 May 2009
CVE-2009-1490Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.EXPLOIT ✓MEDIUM 5.0EPSS 12.6%5 May 2009
CVE-2009-1523Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal sequences in the URI.EXPLOIT ×2 ✓MEDIUM 5.0EPSS 25.8%5 May 2009
CVE-2008-4828Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, and 5.4.0.0 through 5.4.1.96, and the TSM Express…EXPLOIT ✓HIGH 10.0EPSS 71.5%5 May 2009
CVE-2009-1519Directory traversal vulnerability in index.php in Pecio CMS 1.1.5 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.73%4 May 2009
CVE-2008-6791PumpKIN TFTP Server 2.7.2.0 allows remote attackers to cause a denial of service via a write request with a long mode field.EXPLOIT ✓MEDIUM 5.0EPSS 7.11%4 May 2009
CVE-2008-6790The admin module in MindDezign Photo Gallery 2.2 allows remote attackers to add administrative users and gain privileges via a modified username parameter in an edit account action to index.php.EXPLOIT ✓MEDIUM 5.1EPSS 1.98%4 May 2009
CVE-2008-6789SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action to the admin module in index.php, a different vector than CVE-2008-6788.EXPLOIT ×2 ✓MEDIUM 5.1EPSS 0.93%4 May 2009
CVE-2008-6788SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in an info action to index.php.EXPLOIT ×2 ✓MEDIUM 5.1EPSS 0.92%4 May 2009
CVE-2009-1517Multiple insecure method vulnerabilities in the Symantec.EasySetup.1 ActiveX control in EasySetupInt.dll 14.0.4.30167 in the EasySetup wizard in Symantec Norton Ghost 14.0 allow remote attackers to cause a denial of service (browser crash) and possibly…EXPLOIT ✓MEDIUM 4.3EPSS 6.59%4 May 2009
CVE-2009-1516Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependent attackers to execute arbitrary code via a large value in the second argument to the Base64FileEncode…EXPLOIT ✓HIGH 7.5EPSS 3.21%4 May 2009
CVE-2009-1514Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a throw statement with a long exception value.EXPLOIT ✓MEDIUM 5.0EPSS 2.80%4 May 2009
CVE-2009-1512Static code injection vulnerability in X-Forum 0.6.2 allows remote authenticated administrators to inject arbitrary PHP code into Config.php via the adminEMail parameter to SaveConfig.php.EXPLOIT ✓MEDIUM 6.5EPSS 3.95%1 May 2009
CVE-2009-1511GDI+ in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (infinite loop) via a PNG file that contains a certain large btChunkLen value.EXPLOIT ✓HIGH 7.8EPSS 14.2%1 May 2009
CVE-2009-1510Multiple directory traversal vulnerabilities in KoschtIT Image Gallery 1.82 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the file parameter to (1) ki_makepic.php and (2) ki_nojsdisplayimage.php…EXPLOIT ✓HIGH 7.5EPSS 2.25%1 May 2009
CVE-2009-1509SQL injection vulnerability in ajaxp_backend.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%1 May 2009
CVE-2009-1508SQL injection vulnerability in the xforum_validateUser function in Common.php in X-Forum 0.6.2 allows remote attackers to execute arbitrary SQL commands, as demonstrated via the cookie_username parameter to Configure.php.EXPLOIT ✓HIGH 7.5EPSS 2.03%1 May 2009
CVE-2008-6787SQL injection vulnerability in administrator/index.php in Lizardware CMS 0.6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the user.EXPLOIT ✓HIGH 7.5EPSS 0.97%1 May 2009
CVE-2008-6785Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as…EXPLOIT ×2 ✓MEDIUM 6.8EPSS 3.13%1 May 2009
CVE-2009-1506SQL injection vulnerability in classes/Xp.php in eLitius 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to banner-details.php.EXPLOIT ✓MEDIUM 6.8EPSS 0.87%1 May 2009
CVE-2009-1504Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to "lvl=1&userid=1."EXPLOIT ✓HIGH 7.5EPSS 2.43%1 May 2009
CVE-2009-1503Multiple SQL injection vulnerabilities in login.php in Tiger Document Management System (DMS) allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.EXPLOIT ✓HIGH 7.5EPSS 1.01%1 May 2009
CVE-2009-1502Directory traversal vulnerability in plugin.php in S-Cms 1.1 Stable and 1.5.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.EXPLOIT ✓HIGH 7.5EPSS 2.35%1 May 2009
CVE-2009-1500SQL injection vulnerability in index.php in ProjectCMS 1.0 Beta allows remote attackers to execute arbitrary SQL commands via the sn parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.93%1 May 2009
CVE-2008-6784SQL injection vulnerability in directory.php in Scripts For Sites (SFS) EZ Adult Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.EXPLOIT ✓HIGH 7.5EPSS 1.02%1 May 2009
CVE-2008-6783SQL injection vulnerability in directory.php in Sites for Scripts (SFS) EZ Home Business Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.EXPLOIT ✓HIGH 7.5EPSS 1.02%1 May 2009
CVE-2008-6782SQL injection vulnerability in directory.php in Sites for Scripts (SFS) EZ Hosting Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.EXPLOIT ✓HIGH 7.5EPSS 1.02%1 May 2009
CVE-2008-6781SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.22%1 May 2009
CVE-2008-6780SQL injection vulnerability in directory.php in Scripts for Sites (SFS) SFS EZ Affiliate allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.EXPLOIT ✓HIGH 7.5EPSS 1.00%1 May 2009
CVE-2008-6779SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a showcontent action to modules.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%1 May 2009
CVE-2008-6778SQL injection vulnerability in viewfaqs.php in Scripts for Sites (SFS) EZ Auction allows remote attackers to execute arbitrary SQL commands via the cat parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%1 May 2009
CVE-2008-6777Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a confirm action, the (2) user parameter in a newconfirm action, and (3) reqpwd action to…EXPLOIT ✓MEDIUM 5.1EPSS 0.88%1 May 2009
CVE-2008-6776SQL injection vulnerability in viewcomments.php in Scripts For Sites (SFS) EZ Hot or Not allows remote attackers to execute arbitrary SQL commands via the phid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%1 May 2009
CVE-2009-1499SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in index.php.EXPLOIT ✓HIGH 7.5EPSS 1.84%1 May 2009
CVE-2009-1498Directory traversal vulnerability in inc/profilemain.php in Game Maker 2k Internet Discussion Boards (iDB) 0.2.5 Pre-Alpha SVN 243 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.88%1 May 2009
CVE-2009-1497Stack-based buffer overflow in srt2smi.exe in Gretech Online Movie Player (GOM Player) 2.1.16.4635 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in an SRT file.EXPLOIT ✓HIGH 9.3EPSS 6.77%1 May 2009
CVE-2009-1496Directory traversal vulnerability in the Cmi Marketplace (com_cmimarketplace) component 0.1 for Joomla! allows remote attackers to list arbitrary directories via a ..EXPLOIT ✓MEDIUM 5.0EPSS 7.18%1 May 2009
CVE-2009-1495Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/db.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.33%1 May 2009
CVE-2008-6775HTC Touch Pro and HTC Touch Cruise vCard allows remote attackers to cause denial of service (CPU consumption, SMS consumption, and connectivity loss) via a flood of vCards to UDP port 9204.EXPLOIT ✓HIGH 7.1EPSS 2.53%1 May 2009
CVE-2009-1313The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of service (memory corruption) and probably execute arbitrary code via unspecified vectors.EXPLOIT ✓HIGH 9.3EPSS 8.39%30 April 2009
CVE-2009-1493The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers…EXPLOIT ✓MEDIUM 6.8EPSS 21.8%30 April 2009
CVE-2009-1492The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and…EXPLOIT ✓HIGH 9.3EPSS 25.5%30 April 2009
CVE-2009-1416lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might allow remote attackers to spoof signatures on certificates or have unspecified other impact by…EXPLOIT ✓HIGH 7.5EPSS 3.90%30 April 2009
CVE-2009-1415lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a malformed DSA key…EXPLOIT ✓MEDIUM 4.3EPSS 7.92%30 April 2009
CVE-2009-1489includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by setting the user cookie parameter.EXPLOIT ✓HIGH 7.5EPSS 2.54%29 April 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.