SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

397,901 CVEs1,725 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 238 of 501

CVESummaryPriorityPublished
CVE-2009-1488Directory traversal vulnerability in admin/load.php in FunGamez RC1 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.96%29 April 2009
CVE-2009-1487SQL injection vulnerability in pages/login.php in FunGamez RC1 allows remote attackers to execute arbitrary SQL commands via the login_user (aka username) parameter.EXPLOIT ✓HIGH 7.5EPSS 1.02%29 April 2009
CVE-2009-1486Directory traversal vulnerability in pmscript.php in Flatchat 3.0 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.33%29 April 2009
CVE-2009-1483Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable from index2.php, allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing…EXPLOIT ✓MEDIUM 6.8EPSS 4.14%29 April 2009
CVE-2009-1480SQL injection vulnerability in index.php Pragyan CMS 2.6.4 allows remote attackers to execute arbitrary SQL commands via the fileget parameter in a view action and other unspecified vectors.EXPLOIT ✓HIGH 7.5EPSS 0.99%29 April 2009
CVE-2008-6773Static code injection vulnerability in user/internettoolbar/edit.php in YourPlace 1.0.2 and earlier allows remote authenticated users to execute arbitrary PHP code into user/internettoolbar/index.php via the (1) fav1_url, (2) fav1_name, (3) fav2_url,…EXPLOIT ✓MEDIUM 6.5EPSS 1.92%29 April 2009
CVE-2008-6772login/register_form.php in YourPlace 1.0.2 and earlier does not check that a username already exists when a new account is created, which allows remote attackers to bypass intended access restrictions by registering a new account with the username of a…EXPLOIT ✓HIGH 7.5EPSS 2.32%29 April 2009
CVE-2008-6771YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a direct request to user/uploads/phpinfo.php, which calls the phpinfo function.EXPLOIT ✓MEDIUM 5.0EPSS 5.90%29 April 2009
CVE-2008-6770YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to a database containing user credentials via a direct request for users.txt.EXPLOIT ✓MEDIUM 5.0EPSS 5.90%29 April 2009
CVE-2008-6769Unrestricted file upload vulnerability in upload.php in YourPlace 1.0.2 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file.EXPLOIT ✓MEDIUM 6.0EPSS 4.93%29 April 2009
CVE-2008-6768Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in…EXPLOIT ✓MEDIUM 6.8EPSS 4.43%29 April 2009
CVE-2009-1478Multiple unspecified vulnerabilities in the DTrace ioctl handlers in Sun Solaris 10, and OpenSolaris before snv_114, allow local users to cause a denial of service (panic) via unknown vectors.EXPLOIT ✓MEDIUM 4.9EPSS 0.75%29 April 2009
CVE-2009-1430Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server;…EXPLOIT ✓HIGH 9.3EPSS 55.1%29 April 2009
CVE-2009-1429The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 before…EXPLOIT ×2 ✓HIGH 10.0EPSS 87.7%29 April 2009
CVE-2009-1458Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in razorCMS before 0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the slab parameter in an edit action, (2) the catname parameter in a showcats action, and…EXPLOIT ✓MEDIUM 4.3EPSS 1.79%28 April 2009
CVE-2009-1456Directory traversal vulnerability in admin.php in Malleo 1.2.3 allows remote authenticated administrators to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.5EPSS 2.05%28 April 2009
CVE-2009-1453SQL injection vulnerability in class.eport.php in Tiny Blogr 1.0.0 rc4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the txtUsername parameter (aka the Username field).EXPLOIT ✓MEDIUM 6.8EPSS 0.93%28 April 2009
CVE-2009-1452Multiple PHP remote file inclusion vulnerabilities in theme/format.php in SMA-DB 0.3.13 allow remote attackers to execute arbitrary PHP code via a URL in the (1) _page_css and (2) _page_javascript parameters.EXPLOIT ✓HIGH 7.5EPSS 2.34%28 April 2009
CVE-2008-6765ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a modified cart_name parameter.EXPLOIT ✓MEDIUM 5.0EPSS 2.43%28 April 2009
CVE-2008-6764Cross-site scripting (XSS) vulnerability in login.php in Silentum LoginSys 1.0.0 allows remote attackers to inject arbitrary web script or HTML via the message parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%28 April 2009
CVE-2008-6763login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged_in cookie to that account's username.EXPLOIT ✓HIGH 7.5EPSS 6.52%28 April 2009
CVE-2008-6761Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject arbitrary PHP code into const.inc.php via the installdbname parameter (aka the Database Name field).EXPLOIT ✓HIGH 10.0EPSS 6.32%28 April 2009
CVE-2008-6758Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduct persistent cross-site scripting (XSS) attacks via…EXPLOIT ✓MEDIUM 6.8EPSS 0.96%28 April 2009
CVE-2008-6757Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to inject arbitrary web script or HTML via the manuals_search parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.51%28 April 2009
CVE-2009-1451Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB 0.3.12 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.EXPLOIT ✓MEDIUM 4.3EPSS 1.26%28 April 2009
CVE-2009-1450PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP code via a URL in the _page_content parameter.EXPLOIT ✓HIGH 7.5EPSS 2.14%28 April 2009
CVE-2009-1449Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.1 allows remote attackers to execute arbitrary code via a skin file (skin.ini) with a large PlaylistSkin parameter.EXPLOIT ✓HIGH 9.3EPSS 5.86%27 April 2009
CVE-2009-1447Unrestricted file upload vulnerability in admin/editor/image.php in e-cart.biz Free Shopping Cart allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in…EXPLOIT ✓MEDIUM 6.8EPSS 3.51%27 April 2009
CVE-2009-1446Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in…EXPLOIT ✓MEDIUM 6.5EPSS 3.40%27 April 2009
CVE-2009-1445Multiple directory traversal vulnerabilities in WebPortal CMS 0.8-beta allow remote attackers to (1) read arbitrary files via directory traversal sequences in the lang parameter to libraries/helpdocs/help.php and (2) include and execute arbitrary local…EXPLOIT ✓HIGH 7.5EPSS 6.06%27 April 2009
CVE-2009-1444PHP remote file inclusion vulnerability in indexk.php in WebPortal CMS 0.8-beta allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.34%27 April 2009
CVE-2009-1443Multiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and attack vectors.EXPLOITHIGH 10.0EPSS 4.01%27 April 2009
CVE-2009-1437Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file.EXPLOIT ×3 ✓HIGH 9.3EPSS 14.0%27 April 2009
CVE-2009-1436The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive information by reading a database file.EXPLOIT ✓MEDIUM 4.9EPSS 0.89%27 April 2009
CVE-2009-1435NTRtScan.exe in Trend Micro OfficeScan Client 8.0 SP1 and 8.0 SP1 Patch 1 allows local users to cause a denial of service (application crash) via directories with long pathnames.EXPLOIT ✓LOW 2.1EPSS 0.85%27 April 2009
CVE-2009-1411SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the c parameter to plug.php.EXPLOIT ✓HIGH 7.5EPSS 2.31%24 April 2009
CVE-2009-1410SQL injection vulnerability in index.php in Quick.Cms.Lite 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%24 April 2009
CVE-2009-1409SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the hide parameter, a different vector…EXPLOIT ✓MEDIUM 5.1EPSS 0.95%24 April 2009
CVE-2009-1408Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover in nested BBcode tags, as…EXPLOIT ✓MEDIUM 4.3EPSS 2.02%24 April 2009
CVE-2009-1407Directory traversal vulnerability in config.php in NotFTP 1.3.1 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.88%24 April 2009
CVE-2009-1406Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.90%24 April 2009
CVE-2009-1405Directory traversal vulnerability in index.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.90%24 April 2009
CVE-2009-1404SQL injection vulnerability in admin.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user (Username) parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.93%24 April 2009
CVE-2009-1403SQL injection vulnerability in product_info.php in CRE Loaded 6.2 allows remote attackers to execute arbitrary SQL commands via the products_id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%24 April 2009
CVE-2008-6752adminlogin/password.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging does not verify the original password before changing passwords, which allows remote attackers to change the administrator's password and gain privileges via a direct…EXPLOIT ✓HIGH 7.5EPSS 6.35%24 April 2009
CVE-2008-6751Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request…EXPLOIT ✓MEDIUM 6.8EPSS 3.61%24 April 2009
CVE-2008-6750Unrestricted file upload vulnerability in add.php in FlexPHPDirectory 0.0.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photo/.EXPLOIT ✓MEDIUM 6.8EPSS 3.51%24 April 2009
CVE-2008-6749Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPDirectory 0.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) checkuser and (2) checkpass parameters.EXPLOIT ✓MEDIUM 6.8EPSS 1.98%24 April 2009
CVE-2008-6748Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the play action in a mega:// URI.EXPLOIT ×2 ✓HIGH 9.3EPSS 3.74%24 April 2009
CVE-2009-1357CRLF injection vulnerability in da/DA/Login in Sun Java System Delegated Administrator 6.2 through 6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the HELP_PAGE parameter.EXPLOIT ✓MEDIUM 6.8EPSS 7.18%23 April 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.