SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

397,948 CVEs1,725 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 240 of 501

CVESummaryPriorityPublished
CVE-2009-1321Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.47%17 April 2009
CVE-2009-1319Directory traversal vulnerability in includes/ini.inc.php in GuestCal 2.1 allows remote attackers to include and execute arbitrary files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.35%17 April 2009
CVE-2009-1318Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions before 3.4.0 allows remote attackers to include arbitrary files via directory traversal sequences in the t parameter.EXPLOIT ✓MEDIUM 6.5EPSS 1.95%17 April 2009
CVE-2009-1317Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) userSID cookie parameter to droplets/functions/base.php and the (2) username parameter to…EXPLOIT ✓MEDIUM 6.8EPSS 0.93%17 April 2009
CVE-2009-1316Multiple SQL injection vulnerabilities in AbleSpace 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to events_view.php and the (2) id parameter to events_clndr_view.php.EXPLOIT ✓HIGH 7.5EPSS 1.02%17 April 2009
CVE-2009-1315Multiple cross-site scripting (XSS) vulnerabilities in AbleSpace 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter to groups_profile.php, (2) cat_id and (3) razd_id parameters to adv_cat.php, and the (4) URL to…EXPLOIT ✓MEDIUM 4.3EPSS 1.75%17 April 2009
CVE-2008-6726Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.0EPSS 2.13%17 April 2009
CVE-2008-6725Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) index.php in a mythings page (mythings.php) and (2) the users page in admin.php.EXPLOIT ✓MEDIUM 6.0EPSS 0.95%17 April 2009
CVE-2009-1314body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the savefile action with a file parameter containing a filename that has an executable extension.EXPLOIT ✓HIGH 10.0EPSS 10.1%17 April 2009
CVE-2009-1294Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remote attackers to inject arbitrary web script or HTML via the (1) p_p_state or (2) p_p_mode parameters.EXPLOIT ✓MEDIUM 4.3EPSS 4.70%16 April 2009
CVE-2008-4830Insecure method vulnerability in the KWEdit ActiveX control in SAP GUI 6.40 Patch 29 (KWEDIT.DLL 6400.1.1.41) and 7.10 Patch 5 (KWEDIT.DLL 7100.1.1.43) allows remote attackers to (1) overwrite arbitrary files via the SaveDocumentAs method or (2) read or…EXPLOIT ✓HIGH 9.3EPSS 27.6%16 April 2009
CVE-2007-2238Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2, allow remote attackers to execute arbitrary code via long arguments to the (1)…EXPLOIT ✓HIGH 9.3EPSS 45.5%16 April 2009
CVE-2009-0991Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2009-1970.EXPLOIT ✓MEDIUM 5.0EPSS 15.6%15 April 2009
CVE-2009-0981Unspecified vulnerability in the Application Express component in Oracle Database 11.1.0.7 allows remote authenticated users to affect confidentiality, related to APEX.EXPLOIT ✓MEDIUM 4.0EPSS 5.28%15 April 2009
CVE-2009-0553Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that…EXPLOIT ✓HIGH 9.3EPSS 41.4%15 April 2009
CVE-2009-0080The ThreadPool class in Windows Vista Gold and SP1, and Server 2008, does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows…EXPLOIT ✓MEDIUM 6.9EPSS 2.36%15 April 2009
CVE-2009-0079The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account,…EXPLOIT ✓MEDIUM 6.9EPSS 4.06%15 April 2009
CVE-2009-0078The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the…EXPLOIT ✓HIGH 7.2EPSS 2.74%15 April 2009
CVE-2008-6723TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLogged cookie to Administrator.EXPLOIT ✓HIGH 7.5EPSS 2.59%14 April 2009
CVE-2008-6721SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL commands via the txtName parameter (aka the username field).EXPLOIT ✓HIGH 7.5EPSS 0.97%14 April 2009
CVE-2009-1290Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration interface in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to hijack the…EXPLOIT ✓MEDIUM 6.8EPSS 0.98%13 April 2009
CVE-2009-1288Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to inject arbitrary web script or HTML via (1) the username in a…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.76%13 April 2009
CVE-2009-1287Cross-site scripting (XSS) vulnerability in Cisco Subscriber Edge Services Manager (SESM) allows remote attackers to inject arbitrary web script or HTML via the URI.EXPLOIT ✓MEDIUM 4.3EPSS 23.1%13 April 2009
CVE-2008-6720SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka the admin field).EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97%13 April 2009
CVE-2008-6719U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) start.php, (2) aktivitet.php,…EXPLOIT ✓HIGH 7.5EPSS 2.47%13 April 2009
CVE-2008-6718U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) user_manual.php, (2) user_config.php, (3)…EXPLOIT ✓HIGH 7.5EPSS 2.21%13 April 2009
CVE-2008-6717U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) adminstart.php, (2) admineventtype.php, (3)…EXPLOIT ✓HIGH 7.5EPSS 2.47%13 April 2009
CVE-2008-6716homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows remote attackers to have an unspecified impact via a direct request.EXPLOIT ✓HIGH 7.5EPSS 2.47%13 April 2009
CVE-2008-6715Multiple cross-site scripting (XSS) vulnerabilities in Pre ADS Portal 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) homeadmin/adminhome.php and (2) homeadmin/signinform.php.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%13 April 2009
CVE-2008-6714admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by setting the xecms_username cookie.EXPLOIT ✓HIGH 7.5EPSS 12.0%10 April 2009
CVE-2008-6713World in Conflict (WIC) 1.008 and earlier allows remote attackers to cause a denial of service (access violation and crash) via a zero-byte data block to TCP port 48000, which triggers a NULL pointer dereference.EXPLOIT ✓MEDIUM 5.0EPSS 7.79%10 April 2009
CVE-2008-6712The HTTP/XML-RPC service in Crysis 1.21 (game version 1.1.1.6156) and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request, which triggers a NULL pointer dereference.EXPLOIT ✓MEDIUM 5.0EPSS 7.40%10 April 2009
CVE-2008-6703Stack-based buffer overflow in the IPureServer::_Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to execute arbitrary code via a compressed 0x39 packet, which is decompressed by the…EXPLOIT ✓HIGH 10.0EPSS 8.25%10 April 2009
CVE-2008-6702S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (crash) via a long nickname, which triggers an exception.EXPLOIT ✓MEDIUM 5.0EPSS 3.43%10 April 2009
CVE-2008-6700Multiple cross-site scripting (XSS) vulnerabilities in Butterfly Organizer 2.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) mytable parameter to view.php, (2) mytable parameter to viewdb2.php, (3) tablehere parameter to…EXPLOIT ✓MEDIUM 4.3EPSS 1.51%10 April 2009
CVE-2008-6683Cross-site scripting (XSS) vulnerability in listtest.php in Apartment Search Script allows remote attackers to inject arbitrary web script or HTML via the r parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%10 April 2009
CVE-2009-1284Buffer overflow in BibTeX 0.99 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a long .bib bibliography file.EXPLOIT ✓MEDIUM 5.0EPSS 11.9%9 April 2009
CVE-2009-1283glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privileges by obtaining the hash and using it in the glf_password cookie, aka "User Masquerading." NOTE: this…EXPLOIT ✓MEDIUM 6.8EPSS 1.26%9 April 2009
CVE-2009-1282SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the glf_session cookie parameter.EXPLOIT ✓HIGH 7.5EPSS 2.72%9 April 2009
CVE-2009-1281Cross-site scripting (XSS) vulnerability in glFusion before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.EXPLOIT ✓MEDIUM 4.3EPSS 1.49%9 April 2009
CVE-2009-1278Static code injection vulnerability in forms/ajax/configure.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to inject arbitrary PHP code into config.php via the configure action to index.php.EXPLOIT ✓HIGH 7.5EPSS 2.31%9 April 2009
CVE-2009-1277SQL injection vulnerability in index.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to execute arbitrary SQL commands via the member_id parameter in a viewprofile action.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97%9 April 2009
CVE-2008-6678SQL injection vulnerability in asp/includes/contact.asp in QuickerSite 1.8.5 allows remote attackers to execute arbitrary SQL commands via the sNickName parameter in a profile action to default.asp.EXPLOIT ✓HIGH 7.5EPSS 1.14%8 April 2009
CVE-2008-6677Unrestricted file upload vulnerability in fckeditor251/editor/filemanager/connectors/asp/upload.asp in QuickerSite 1.8.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct…EXPLOIT ✓HIGH 7.5EPSS 4.01%8 April 2009
CVE-2008-6676QuickerSite 1.8.5 allows remote attackers to obtain sensitive information via a request to showThumb.aspx without any parameters, which reveals the installation path in an error message.EXPLOIT ✓MEDIUM 5.0EPSS 3.04%8 April 2009
CVE-2008-6675Multiple cross-site scripting (XSS) vulnerabilities in QuickerSite 1.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the close parameter to showThumb.aspx; (2) SB_redirect and (3) SB_feedback parameters in process_send.asp, as…EXPLOIT ✓MEDIUM 4.3EPSS 1.72%8 April 2009
CVE-2008-6674mailPage.asp in QuickerSite 1.8.5 allows remote attackers to flood e-mail accounts with messages via a large number of requests with a modified sEmail parameter.EXPLOIT ✓MEDIUM 5.0EPSS 2.73%8 April 2009
CVE-2008-6673asp/bs_login.asp in QuickerSite 1.8.5 does not properly restrict access to administrative functionality, which allows remote attackers to (1) change the admin password via the cSaveAdminPW action; (2) modify site information, such as the contact…EXPLOIT ✓HIGH 7.5EPSS 2.30%8 April 2009
CVE-2008-6670Integer overflow in Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted packet to UDP port 27960.EXPLOIT ✓MEDIUM 5.0EPSS 4.06%8 April 2009
CVE-2008-6669viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in the var_filename parameter in a (1) tif or (2) pdf format action.EXPLOIT ✓HIGH 7.5EPSS 4.23%8 April 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.