Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,901 CVEs1,725 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 238 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-1488 | Directory traversal vulnerability in admin/load.php in FunGamez RC1 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.96% | 29 April 2009 |
| CVE-2009-1487 | SQL injection vulnerability in pages/login.php in FunGamez RC1 allows remote attackers to execute arbitrary SQL commands via the login_user (aka username) parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 29 April 2009 |
| CVE-2009-1486 | Directory traversal vulnerability in pmscript.php in Flatchat 3.0 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.33% | 29 April 2009 |
| CVE-2009-1483 | Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable from index2.php, allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing… | EXPLOIT ✓MEDIUM 6.8EPSS 4.14% | 29 April 2009 |
| CVE-2009-1480 | SQL injection vulnerability in index.php Pragyan CMS 2.6.4 allows remote attackers to execute arbitrary SQL commands via the fileget parameter in a view action and other unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 29 April 2009 |
| CVE-2008-6773 | Static code injection vulnerability in user/internettoolbar/edit.php in YourPlace 1.0.2 and earlier allows remote authenticated users to execute arbitrary PHP code into user/internettoolbar/index.php via the (1) fav1_url, (2) fav1_name, (3) fav2_url,… | EXPLOIT ✓MEDIUM 6.5EPSS 1.92% | 29 April 2009 |
| CVE-2008-6772 | login/register_form.php in YourPlace 1.0.2 and earlier does not check that a username already exists when a new account is created, which allows remote attackers to bypass intended access restrictions by registering a new account with the username of a… | EXPLOIT ✓HIGH 7.5EPSS 2.32% | 29 April 2009 |
| CVE-2008-6771 | YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a direct request to user/uploads/phpinfo.php, which calls the phpinfo function. | EXPLOIT ✓MEDIUM 5.0EPSS 5.90% | 29 April 2009 |
| CVE-2008-6770 | YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to a database containing user credentials via a direct request for users.txt. | EXPLOIT ✓MEDIUM 5.0EPSS 5.90% | 29 April 2009 |
| CVE-2008-6769 | Unrestricted file upload vulnerability in upload.php in YourPlace 1.0.2 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file. | EXPLOIT ✓MEDIUM 6.0EPSS 4.93% | 29 April 2009 |
| CVE-2008-6768 | Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in… | EXPLOIT ✓MEDIUM 6.8EPSS 4.43% | 29 April 2009 |
| CVE-2009-1478 | Multiple unspecified vulnerabilities in the DTrace ioctl handlers in Sun Solaris 10, and OpenSolaris before snv_114, allow local users to cause a denial of service (panic) via unknown vectors. | EXPLOIT ✓MEDIUM 4.9EPSS 0.75% | 29 April 2009 |
| CVE-2009-1430 | Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server;… | EXPLOIT ✓HIGH 9.3EPSS 55.1% | 29 April 2009 |
| CVE-2009-1429 | The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 before… | EXPLOIT ×2 ✓HIGH 10.0EPSS 87.7% | 29 April 2009 |
| CVE-2009-1458 | Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in razorCMS before 0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the slab parameter in an edit action, (2) the catname parameter in a showcats action, and… | EXPLOIT ✓MEDIUM 4.3EPSS 1.79% | 28 April 2009 |
| CVE-2009-1456 | Directory traversal vulnerability in admin.php in Malleo 1.2.3 allows remote authenticated administrators to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.5EPSS 2.05% | 28 April 2009 |
| CVE-2009-1453 | SQL injection vulnerability in class.eport.php in Tiny Blogr 1.0.0 rc4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the txtUsername parameter (aka the Username field). | EXPLOIT ✓MEDIUM 6.8EPSS 0.93% | 28 April 2009 |
| CVE-2009-1452 | Multiple PHP remote file inclusion vulnerabilities in theme/format.php in SMA-DB 0.3.13 allow remote attackers to execute arbitrary PHP code via a URL in the (1) _page_css and (2) _page_javascript parameters. | EXPLOIT ✓HIGH 7.5EPSS 2.34% | 28 April 2009 |
| CVE-2008-6765 | ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a modified cart_name parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.43% | 28 April 2009 |
| CVE-2008-6764 | Cross-site scripting (XSS) vulnerability in login.php in Silentum LoginSys 1.0.0 allows remote attackers to inject arbitrary web script or HTML via the message parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 28 April 2009 |
| CVE-2008-6763 | login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged_in cookie to that account's username. | EXPLOIT ✓HIGH 7.5EPSS 6.52% | 28 April 2009 |
| CVE-2008-6761 | Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject arbitrary PHP code into const.inc.php via the installdbname parameter (aka the Database Name field). | EXPLOIT ✓HIGH 10.0EPSS 6.32% | 28 April 2009 |
| CVE-2008-6758 | Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduct persistent cross-site scripting (XSS) attacks via… | EXPLOIT ✓MEDIUM 6.8EPSS 0.96% | 28 April 2009 |
| CVE-2008-6757 | Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to inject arbitrary web script or HTML via the manuals_search parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 28 April 2009 |
| CVE-2009-1451 | Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB 0.3.12 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | EXPLOIT ✓MEDIUM 4.3EPSS 1.26% | 28 April 2009 |
| CVE-2009-1450 | PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP code via a URL in the _page_content parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.14% | 28 April 2009 |
| CVE-2009-1449 | Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.1 allows remote attackers to execute arbitrary code via a skin file (skin.ini) with a large PlaylistSkin parameter. | EXPLOIT ✓HIGH 9.3EPSS 5.86% | 27 April 2009 |
| CVE-2009-1447 | Unrestricted file upload vulnerability in admin/editor/image.php in e-cart.biz Free Shopping Cart allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in… | EXPLOIT ✓MEDIUM 6.8EPSS 3.51% | 27 April 2009 |
| CVE-2009-1446 | Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in… | EXPLOIT ✓MEDIUM 6.5EPSS 3.40% | 27 April 2009 |
| CVE-2009-1445 | Multiple directory traversal vulnerabilities in WebPortal CMS 0.8-beta allow remote attackers to (1) read arbitrary files via directory traversal sequences in the lang parameter to libraries/helpdocs/help.php and (2) include and execute arbitrary local… | EXPLOIT ✓HIGH 7.5EPSS 6.06% | 27 April 2009 |
| CVE-2009-1444 | PHP remote file inclusion vulnerability in indexk.php in WebPortal CMS 0.8-beta allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.34% | 27 April 2009 |
| CVE-2009-1443 | Multiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and attack vectors. | EXPLOITHIGH 10.0EPSS 4.01% | 27 April 2009 |
| CVE-2009-1437 | Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file. | EXPLOIT ×3 ✓HIGH 9.3EPSS 14.0% | 27 April 2009 |
| CVE-2009-1436 | The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive information by reading a database file. | EXPLOIT ✓MEDIUM 4.9EPSS 0.89% | 27 April 2009 |
| CVE-2009-1435 | NTRtScan.exe in Trend Micro OfficeScan Client 8.0 SP1 and 8.0 SP1 Patch 1 allows local users to cause a denial of service (application crash) via directories with long pathnames. | EXPLOIT ✓LOW 2.1EPSS 0.85% | 27 April 2009 |
| CVE-2009-1411 | SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the c parameter to plug.php. | EXPLOIT ✓HIGH 7.5EPSS 2.31% | 24 April 2009 |
| CVE-2009-1410 | SQL injection vulnerability in index.php in Quick.Cms.Lite 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 24 April 2009 |
| CVE-2009-1409 | SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the hide parameter, a different vector… | EXPLOIT ✓MEDIUM 5.1EPSS 0.95% | 24 April 2009 |
| CVE-2009-1408 | Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover in nested BBcode tags, as… | EXPLOIT ✓MEDIUM 4.3EPSS 2.02% | 24 April 2009 |
| CVE-2009-1407 | Directory traversal vulnerability in config.php in NotFTP 1.3.1 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.88% | 24 April 2009 |
| CVE-2009-1406 | Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.90% | 24 April 2009 |
| CVE-2009-1405 | Directory traversal vulnerability in index.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.90% | 24 April 2009 |
| CVE-2009-1404 | SQL injection vulnerability in admin.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user (Username) parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.93% | 24 April 2009 |
| CVE-2009-1403 | SQL injection vulnerability in product_info.php in CRE Loaded 6.2 allows remote attackers to execute arbitrary SQL commands via the products_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 24 April 2009 |
| CVE-2008-6752 | adminlogin/password.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging does not verify the original password before changing passwords, which allows remote attackers to change the administrator's password and gain privileges via a direct… | EXPLOIT ✓HIGH 7.5EPSS 6.35% | 24 April 2009 |
| CVE-2008-6751 | Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request… | EXPLOIT ✓MEDIUM 6.8EPSS 3.61% | 24 April 2009 |
| CVE-2008-6750 | Unrestricted file upload vulnerability in add.php in FlexPHPDirectory 0.0.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photo/. | EXPLOIT ✓MEDIUM 6.8EPSS 3.51% | 24 April 2009 |
| CVE-2008-6749 | Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPDirectory 0.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) checkuser and (2) checkpass parameters. | EXPLOIT ✓MEDIUM 6.8EPSS 1.98% | 24 April 2009 |
| CVE-2008-6748 | Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the play action in a mega:// URI. | EXPLOIT ×2 ✓HIGH 9.3EPSS 3.74% | 24 April 2009 |
| CVE-2009-1357 | CRLF injection vulnerability in da/DA/Login in Sun Java System Delegated Administrator 6.2 through 6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the HELP_PAGE parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 7.18% | 23 April 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.