Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,948 CVEs1,725 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 240 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-1321 | Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 17 April 2009 |
| CVE-2009-1319 | Directory traversal vulnerability in includes/ini.inc.php in GuestCal 2.1 allows remote attackers to include and execute arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.35% | 17 April 2009 |
| CVE-2009-1318 | Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions before 3.4.0 allows remote attackers to include arbitrary files via directory traversal sequences in the t parameter. | EXPLOIT ✓MEDIUM 6.5EPSS 1.95% | 17 April 2009 |
| CVE-2009-1317 | Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) userSID cookie parameter to droplets/functions/base.php and the (2) username parameter to… | EXPLOIT ✓MEDIUM 6.8EPSS 0.93% | 17 April 2009 |
| CVE-2009-1316 | Multiple SQL injection vulnerabilities in AbleSpace 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to events_view.php and the (2) id parameter to events_clndr_view.php. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 17 April 2009 |
| CVE-2009-1315 | Multiple cross-site scripting (XSS) vulnerabilities in AbleSpace 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter to groups_profile.php, (2) cat_id and (3) razd_id parameters to adv_cat.php, and the (4) URL to… | EXPLOIT ✓MEDIUM 4.3EPSS 1.75% | 17 April 2009 |
| CVE-2008-6726 | Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.0EPSS 2.13% | 17 April 2009 |
| CVE-2008-6725 | Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) index.php in a mythings page (mythings.php) and (2) the users page in admin.php. | EXPLOIT ✓MEDIUM 6.0EPSS 0.95% | 17 April 2009 |
| CVE-2009-1314 | body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the savefile action with a file parameter containing a filename that has an executable extension. | EXPLOIT ✓HIGH 10.0EPSS 10.1% | 17 April 2009 |
| CVE-2009-1294 | Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remote attackers to inject arbitrary web script or HTML via the (1) p_p_state or (2) p_p_mode parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 4.70% | 16 April 2009 |
| CVE-2008-4830 | Insecure method vulnerability in the KWEdit ActiveX control in SAP GUI 6.40 Patch 29 (KWEDIT.DLL 6400.1.1.41) and 7.10 Patch 5 (KWEDIT.DLL 7100.1.1.43) allows remote attackers to (1) overwrite arbitrary files via the SaveDocumentAs method or (2) read or… | EXPLOIT ✓HIGH 9.3EPSS 27.6% | 16 April 2009 |
| CVE-2007-2238 | Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2, allow remote attackers to execute arbitrary code via long arguments to the (1)… | EXPLOIT ✓HIGH 9.3EPSS 45.5% | 16 April 2009 |
| CVE-2009-0991 | Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2009-1970. | EXPLOIT ✓MEDIUM 5.0EPSS 15.6% | 15 April 2009 |
| CVE-2009-0981 | Unspecified vulnerability in the Application Express component in Oracle Database 11.1.0.7 allows remote authenticated users to affect confidentiality, related to APEX. | EXPLOIT ✓MEDIUM 4.0EPSS 5.28% | 15 April 2009 |
| CVE-2009-0553 | Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that… | EXPLOIT ✓HIGH 9.3EPSS 41.4% | 15 April 2009 |
| CVE-2009-0080 | The ThreadPool class in Windows Vista Gold and SP1, and Server 2008, does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows… | EXPLOIT ✓MEDIUM 6.9EPSS 2.36% | 15 April 2009 |
| CVE-2009-0079 | The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account,… | EXPLOIT ✓MEDIUM 6.9EPSS 4.06% | 15 April 2009 |
| CVE-2009-0078 | The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the… | EXPLOIT ✓HIGH 7.2EPSS 2.74% | 15 April 2009 |
| CVE-2008-6723 | TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLogged cookie to Administrator. | EXPLOIT ✓HIGH 7.5EPSS 2.59% | 14 April 2009 |
| CVE-2008-6721 | SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL commands via the txtName parameter (aka the username field). | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 14 April 2009 |
| CVE-2009-1290 | Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration interface in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to hijack the… | EXPLOIT ✓MEDIUM 6.8EPSS 0.98% | 13 April 2009 |
| CVE-2009-1288 | Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to inject arbitrary web script or HTML via (1) the username in a… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.76% | 13 April 2009 |
| CVE-2009-1287 | Cross-site scripting (XSS) vulnerability in Cisco Subscriber Edge Services Manager (SESM) allows remote attackers to inject arbitrary web script or HTML via the URI. | EXPLOIT ✓MEDIUM 4.3EPSS 23.1% | 13 April 2009 |
| CVE-2008-6720 | SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka the admin field). | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97% | 13 April 2009 |
| CVE-2008-6719 | U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) start.php, (2) aktivitet.php,… | EXPLOIT ✓HIGH 7.5EPSS 2.47% | 13 April 2009 |
| CVE-2008-6718 | U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) user_manual.php, (2) user_config.php, (3)… | EXPLOIT ✓HIGH 7.5EPSS 2.21% | 13 April 2009 |
| CVE-2008-6717 | U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) adminstart.php, (2) admineventtype.php, (3)… | EXPLOIT ✓HIGH 7.5EPSS 2.47% | 13 April 2009 |
| CVE-2008-6716 | homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows remote attackers to have an unspecified impact via a direct request. | EXPLOIT ✓HIGH 7.5EPSS 2.47% | 13 April 2009 |
| CVE-2008-6715 | Multiple cross-site scripting (XSS) vulnerabilities in Pre ADS Portal 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) homeadmin/adminhome.php and (2) homeadmin/signinform.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 13 April 2009 |
| CVE-2008-6714 | admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by setting the xecms_username cookie. | EXPLOIT ✓HIGH 7.5EPSS 12.0% | 10 April 2009 |
| CVE-2008-6713 | World in Conflict (WIC) 1.008 and earlier allows remote attackers to cause a denial of service (access violation and crash) via a zero-byte data block to TCP port 48000, which triggers a NULL pointer dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 7.79% | 10 April 2009 |
| CVE-2008-6712 | The HTTP/XML-RPC service in Crysis 1.21 (game version 1.1.1.6156) and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request, which triggers a NULL pointer dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 7.40% | 10 April 2009 |
| CVE-2008-6703 | Stack-based buffer overflow in the IPureServer::_Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to execute arbitrary code via a compressed 0x39 packet, which is decompressed by the… | EXPLOIT ✓HIGH 10.0EPSS 8.25% | 10 April 2009 |
| CVE-2008-6702 | S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (crash) via a long nickname, which triggers an exception. | EXPLOIT ✓MEDIUM 5.0EPSS 3.43% | 10 April 2009 |
| CVE-2008-6700 | Multiple cross-site scripting (XSS) vulnerabilities in Butterfly Organizer 2.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) mytable parameter to view.php, (2) mytable parameter to viewdb2.php, (3) tablehere parameter to… | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 10 April 2009 |
| CVE-2008-6683 | Cross-site scripting (XSS) vulnerability in listtest.php in Apartment Search Script allows remote attackers to inject arbitrary web script or HTML via the r parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 10 April 2009 |
| CVE-2009-1284 | Buffer overflow in BibTeX 0.99 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a long .bib bibliography file. | EXPLOIT ✓MEDIUM 5.0EPSS 11.9% | 9 April 2009 |
| CVE-2009-1283 | glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privileges by obtaining the hash and using it in the glf_password cookie, aka "User Masquerading." NOTE: this… | EXPLOIT ✓MEDIUM 6.8EPSS 1.26% | 9 April 2009 |
| CVE-2009-1282 | SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the glf_session cookie parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.72% | 9 April 2009 |
| CVE-2009-1281 | Cross-site scripting (XSS) vulnerability in glFusion before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | EXPLOIT ✓MEDIUM 4.3EPSS 1.49% | 9 April 2009 |
| CVE-2009-1278 | Static code injection vulnerability in forms/ajax/configure.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to inject arbitrary PHP code into config.php via the configure action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.31% | 9 April 2009 |
| CVE-2009-1277 | SQL injection vulnerability in index.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to execute arbitrary SQL commands via the member_id parameter in a viewprofile action. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97% | 9 April 2009 |
| CVE-2008-6678 | SQL injection vulnerability in asp/includes/contact.asp in QuickerSite 1.8.5 allows remote attackers to execute arbitrary SQL commands via the sNickName parameter in a profile action to default.asp. | EXPLOIT ✓HIGH 7.5EPSS 1.14% | 8 April 2009 |
| CVE-2008-6677 | Unrestricted file upload vulnerability in fckeditor251/editor/filemanager/connectors/asp/upload.asp in QuickerSite 1.8.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct… | EXPLOIT ✓HIGH 7.5EPSS 4.01% | 8 April 2009 |
| CVE-2008-6676 | QuickerSite 1.8.5 allows remote attackers to obtain sensitive information via a request to showThumb.aspx without any parameters, which reveals the installation path in an error message. | EXPLOIT ✓MEDIUM 5.0EPSS 3.04% | 8 April 2009 |
| CVE-2008-6675 | Multiple cross-site scripting (XSS) vulnerabilities in QuickerSite 1.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the close parameter to showThumb.aspx; (2) SB_redirect and (3) SB_feedback parameters in process_send.asp, as… | EXPLOIT ✓MEDIUM 4.3EPSS 1.72% | 8 April 2009 |
| CVE-2008-6674 | mailPage.asp in QuickerSite 1.8.5 allows remote attackers to flood e-mail accounts with messages via a large number of requests with a modified sEmail parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.73% | 8 April 2009 |
| CVE-2008-6673 | asp/bs_login.asp in QuickerSite 1.8.5 does not properly restrict access to administrative functionality, which allows remote attackers to (1) change the admin password via the cSaveAdminPW action; (2) modify site information, such as the contact… | EXPLOIT ✓HIGH 7.5EPSS 2.30% | 8 April 2009 |
| CVE-2008-6670 | Integer overflow in Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted packet to UDP port 27960. | EXPLOIT ✓MEDIUM 5.0EPSS 4.06% | 8 April 2009 |
| CVE-2008-6669 | viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in the var_filename parameter in a (1) tif or (2) pdf format action. | EXPLOIT ✓HIGH 7.5EPSS 4.23% | 8 April 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.