Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,948 CVEs1,725 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 243 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-6572 | SQL injection vulnerability in search_results.php in ABK-Soft AbleDating 2.4 allows remote attackers to execute arbitrary SQL commands via the keyword parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 31 March 2009 |
| CVE-2008-6565 | Cross-site scripting (XSS) vulnerability in Invision Power Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an IFRAME tag in the signature. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 31 March 2009 |
| CVE-2008-6563 | Buffer overflow in the XML parser in Trillian 3.1.9.0, and possibly earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DTD file. | EXPLOIT ✓HIGH 9.3EPSS 5.63% | 31 March 2009 |
| CVE-2008-6562 | Cross-site scripting (XSS) vulnerability in jax_linklists.php in Jack (tR) Jax LinkLists 1.00 allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.21% | 31 March 2009 |
| CVE-2005-4880 | Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and… | EXPLOIT ×4 ✓MEDIUM 5.0EPSS 2.39% | 31 March 2009 |
| CVE-2005-4879 | Multiple cross-site scripting (XSS) vulnerabilities in jax_guestbook.php in Jax Guestbook 3.1 and 3.31 allow remote attackers to inject arbitrary web script or HTML via the (1) gmt_ofs and (2) language parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 31 March 2009 |
| CVE-2009-1171 | The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via an input command in a "$$" sequence, which causes LaTeX to include the contents of the file. | EXPLOIT ✓MEDIUM 4.3EPSS 6.24% | 30 March 2009 |
| CVE-2008-6559 | Merge mcd in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges via a crafted -d argument that contains .. | EXPLOIT ✓HIGH 7.2EPSS 0.80% | 30 March 2009 |
| CVE-2008-6558 | Untrusted search path vulnerability in (1) hvdisp and (2) rcvm in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges by modifying the RELIANT_PATH environment variable to point to a malicious bin/hvenv program. | EXPLOIT ✓HIGH 7.2EPSS 0.87% | 30 March 2009 |
| CVE-2008-6555 | cgi-bin/webutil.pl in The Puppet Master WebUtil allows remote attackers to execute arbitrary commands via shell metacharacters in the dig command. | EXPLOIT ✓HIGH 10.0EPSS 4.49% | 30 March 2009 |
| CVE-2008-6553 | microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an administrator, which allows remote attackers to (1) create administrative accounts via an add_admin action, (2) remove… | EXPLOIT ✓HIGH 7.5EPSS 2.47% | 30 March 2009 |
| CVE-2008-6551 | Multiple directory traversal vulnerabilities in e-Vision CMS 2.0.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 5.1EPSS 1.91% | 30 March 2009 |
| CVE-2008-6550 | Cross-site scripting (XSS) vulnerability in glossaire.php in Glossaire 2.0 allows remote attackers to inject arbitrary web script or HTML via the letter parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 30 March 2009 |
| CVE-2008-6545 | PHP remote file inclusion vulnerability in news/include/createdb.php in Web Server Creator Web Portal 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the langfile parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.33% | 30 March 2009 |
| CVE-2008-6544 | Multiple PHP remote file inclusion vulnerabilities in Simple Machines Forum (SMF) 1.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) settings[default_theme_dir] parameter to Sources/Subs-Graphics.php and (2)… | EXPLOIT ✓HIGH 7.5EPSS 2.93% | 30 March 2009 |
| CVE-2008-6543 | Multiple PHP remote file inclusion vulnerabilities in ComScripts TEAM Quick Classifieds 1.0 via the DOCUMENT_ROOT parameter to (1) index.php3, (2) locate.php3, (3) search_results.php3, (4) classifieds/index.php3, and (5) classifieds/view.php3; (6)… | EXPLOIT ×36 ✓HIGH 7.5EPSS 2.54% | 30 March 2009 |
| CVE-2008-6540 | DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access… | EXPLOIT ✓MEDIUM 5.1EPSS 2.48% | 30 March 2009 |
| CVE-2008-6539 | Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitrary administrators and inject arbitrary Python code into destar_cfg.py via a crafted pin parameter. | EXPLOIT ✓MEDIUM 6.5EPSS 2.24% | 30 March 2009 |
| CVE-2008-6538 | DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser. | EXPLOIT ✓MEDIUM 5.0EPSS 2.46% | 30 March 2009 |
| CVE-2008-6537 | LightNEasy/lightneasy.php in LightNEasy No database version 1.2 allows remote attackers to obtain the hash of the administrator password via the setup "do" action to LightNEasy.php, which is cleared from $_GET but later accessed using $_REQUEST. | EXPLOIT ✓MEDIUM 5.0EPSS 6.27% | 30 March 2009 |
| CVE-2009-1169 | The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XML file with a crafted XSLT transform. | EXPLOIT ✓HIGH 9.3EPSS 10.5% | 27 March 2009 |
| CVE-2008-6535 | admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the administrative password via a direct request with a modified NewAdmin parameter. | EXPLOIT ✓HIGH 7.5EPSS 6.33% | 26 March 2009 |
| CVE-2008-6534 | Incomplete blacklist vulnerability in NULL FTP Server Free and Pro 1.1.0.7 allows remote authenticated users to execute arbitrary commands via a custom SITE command containing shell metacharacters such as "&" (ampersand) in the middle of an argument. | EXPLOIT ✓HIGH 7.1EPSS 4.13% | 26 March 2009 |
| CVE-2008-6530 | Unrestricted file upload vulnerability in editimage.php in eZoneScripts Living Local 1.1 allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to… | EXPLOIT ✓MEDIUM 6.5EPSS 2.12% | 26 March 2009 |
| CVE-2008-6529 | Cross-site scripting (XSS) vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to inject arbitrary web script or HTML via the r parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.60% | 26 March 2009 |
| CVE-2009-1152 | Siemens Gigaset SE461 WiMAX router 1.5-BL024.9.6401, and possibly other versions, allows remote attackers to cause a denial of service (device restart and loss of configuration) by connecting to TCP port 53, then closing the connection. | EXPLOIT ✓HIGH 7.3EPSS 4.55% | 26 March 2009 |
| CVE-2009-1151 | phpMyAdmin Remote Code Execution Vulnerability | KEVEXPLOIT ×3 ✓CRITICAL 9.8EPSS 96.6% | 26 March 2009 |
| CVE-2008-6528 | NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to the URL, which accesses the alternate data stream. | EXPLOIT ✓MEDIUM 5.0EPSS 3.34% | 26 March 2009 |
| CVE-2009-1071 | Stack-based buffer overflow in Icarus 2.0 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted Portable Game Notation (.pgn) file. | EXPLOIT ×2 ✓HIGH 9.3EPSS 6.03% | 26 March 2009 |
| CVE-2009-1070 | Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the avatar parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.72% | 26 March 2009 |
| CVE-2009-1068 | Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long hostname in a .bsl playlist file. | EXPLOIT ×2 ✓HIGH 9.3EPSS 15.0% | 26 March 2009 |
| CVE-2009-1067 | Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web script or HTML via the x parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.69% | 26 March 2009 |
| CVE-2009-1066 | SQL injection vulnerability in the referral function in admin/lib/lib_logs.php in Pixie CMS 1.01a allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header in a request. | EXPLOIT ✓HIGH 7.5EPSS 2.39% | 26 March 2009 |
| CVE-2009-1064 | Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allows remote attackers to overwrite arbitrary files via whitespace and a command-line switch, followed by a full pathname, in the third… | EXPLOIT ✓MEDIUM 5.8EPSS 3.72% | 26 March 2009 |
| CVE-2009-1063 | Buffer overflow in eXeScope 6.50 allows user-assisted remote attackers to execute arbitrary code via a crafted executable (.exe) file. | EXPLOIT ✓MEDIUM 6.8EPSS 4.75% | 26 March 2009 |
| CVE-2009-1041 | The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel memory via an out-of-bounds timer value. | EXPLOIT ✓HIGH 7.2EPSS 0.78% | 26 March 2009 |
| CVE-2009-1092 | Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR systems allows remote attackers to execute arbitrary code by calling the GetAudioPlayingTime method with certain arguments. | EXPLOIT ✓HIGH 9.3EPSS 8.81% | 25 March 2009 |
| CVE-2009-1088 | Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Java code via a crafted XSLT stylesheet with "extension elements and extension functions" that trigger code execution by Xalan-Java, as… | EXPLOIT ✓HIGH 9.0EPSS 12.0% | 25 March 2009 |
| CVE-2009-1087 | Multiple argument injection vulnerabilities in PPLive.exe in PPLive 1.9.21 and earlier allow remote attackers to execute arbitrary code via a UNC share pathname in the LoadModule argument to the (1) synacast, (2) Play, (3) pplsv, or (4) ppvod URI handler. | EXPLOIT ✓HIGH 9.3EPSS 5.14% | 25 March 2009 |
| CVE-2008-6527 | SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the iFor parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.10% | 25 March 2009 |
| CVE-2008-6526 | SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2008-1838. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 25 March 2009 |
| CVE-2008-6525 | SQL injection vulnerability in the Admin Panel in Nice PHP FAQ Script (Knowledge base Script) allows remote attackers to execute arbitrary SQL commands via the Password parameter (aka the pass field). | EXPLOIT ✓HIGH 7.5EPSS 1.99% | 25 March 2009 |
| CVE-2008-6524 | resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. | EXPLOIT ✓MEDIUM 6.5EPSS 2.04% | 25 March 2009 |
| CVE-2008-6523 | auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the oiauth cookie. | EXPLOIT ✓HIGH 7.5EPSS 2.56% | 25 March 2009 |
| CVE-2008-6522 | Multiple directory traversal vulnerabilities in the RenderFile function in ContentRender.class.php in Terracotta (aka OpenTerracotta) 0.6.1, and possibly other versions, allow remote attackers to list arbitrary directories and read arbitrary files via a… | EXPLOIT ✓MEDIUM 6.8EPSS 1.90% | 25 March 2009 |
| CVE-2008-6519 | Format string vulnerability in Xitami Web Server 2.2a through 2.5c2, and possibly other versions, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in a Long Running Web… | EXPLOIT ✓HIGH 10.0EPSS 5.94% | 25 March 2009 |
| CVE-2008-6518 | Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users to execute arbitrary code by uploading a PHP file as an Avatar, then accessing the avatar via a direct request. | EXPLOIT ✓MEDIUM 6.5EPSS 3.30% | 25 March 2009 |
| CVE-2008-6517 | SQL injection vulnerability in NewsHOWLER 1.03 Beta allows remote attackers to execute arbitrary SQL commands via the news_user cookie parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 25 March 2009 |
| CVE-2008-6516 | Multiple directory traversal vulnerabilities in phpKF-Portal 1.10 allow remote attackers to include arbitrary files via a .. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.58% | 25 March 2009 |
| CVE-2009-0215 | Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors. | EXPLOIT ✓HIGH 9.3EPSS 36.3% | 25 March 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.