SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,020 CVEs1,725 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 247 of 501

CVESummaryPriorityPublished
CVE-2009-0815The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote attackers to read arbitrary files by…EXPLOIT ✓MEDIUM 5.0EPSS 42.2%5 March 2009
CVE-2009-0814Cross-site scripting (XSS) vulnerability in Widgets.aspx in Blogsa 1.0 Beta 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchText parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%5 March 2009
CVE-2009-0813Insecure method vulnerability in the ImeraIEPlugin ActiveX control (ImeraIEPlugin.dll 1.0.2.54) in Imera TeamLinks Client allows remote attackers to force the download and execution of arbitrary URLs via modified DownloadProtocol, DownloadHost,…EXPLOIT ✓HIGH 9.3EPSS 9.09%5 March 2009
CVE-2009-0367The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe…EXPLOIT ✓HIGH 9.3EPSS 10.9%5 March 2009
CVE-2009-0037The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or…EXPLOIT ✓MEDIUM 6.8EPSS 9.05%5 March 2009
CVE-2009-0812Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions allows remote attackers to execute arbitrary code via a crafted Intel Hex Code (.hex) file.EXPLOIT ×2 ✓HIGH 9.3EPSS 6.90%4 March 2009
CVE-2009-0811Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to execute arbitrary programs via an executable file name in the argument to the SetExternalPlayer method.EXPLOIT ✓HIGH 9.3EPSS 5.54%4 March 2009
CVE-2009-0810SQL injection vulnerability in login.php in xGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%4 March 2009
CVE-2009-0807zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php.EXPLOIT ✓HIGH 7.5EPSS 2.14%4 March 2009
CVE-2008-6396Cross-site scripting (XSS) vulnerability in account.php in Celerondude Uploader 6.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%4 March 2009
CVE-2008-6394SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the cs_cookies[customer_user_id] cookie parameter.EXPLOIT ✓HIGH 7.5EPSS 1.20%4 March 2009
CVE-2009-0756The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that triggers a parsing error, which is not properly handled by JBIG2SymbolDict::~JBIG2SymbolDict and…EXPLOIT ✓MEDIUM 5.0EPSS 10.1%3 March 2009
CVE-2009-0755The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file with an invalid Form Opt entry.EXPLOIT ✓MEDIUM 5.0EPSS 10.8%3 March 2009
CVE-2009-0754PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to…EXPLOIT ✓LOW 2.1EPSS 0.95%3 March 2009
CVE-2009-0753Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files via a leading "//" (double slash) in the filename.EXPLOIT ✓MEDIUM 5.0EPSS 5.80%3 March 2009
CVE-2008-6393PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an…EXPLOIT ✓HIGH 10.0EPSS 18.2%3 March 2009
CVE-2009-0751Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers.EXPLOIT ✓MEDIUM 5.0EPSS 10.4%2 March 2009
CVE-2009-0750SQL injection vulnerability in login.php in the smNews example script for txtSQL 2.2 Final allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOIT ✓HIGH 7.5EPSS 1.09%2 March 2009
CVE-2009-0368OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the…EXPLOIT ✓LOW 2.1EPSS 1.21%2 March 2009
CVE-2008-6392SQL injection vulnerability in showads.php in Z1Exchange allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%2 March 2009
CVE-2008-6391SQL injection vulnerability in main.asp in Jbook allows remote attackers to execute arbitrary SQL commands via the username (user parameter).EXPLOIT ✓HIGH 7.5EPSS 0.89%2 March 2009
CVE-2008-6390SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%2 March 2009
CVE-2008-6389SQL injection vulnerability in asadmin/default.asp in Rae Media Contact Management Software SOHO, Standard, and Enterprise allows remote attackers to execute arbitrary SQL commands via the Password parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%2 March 2009
CVE-2008-6388Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to cldb.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.23%2 March 2009
CVE-2008-6387Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to qtv.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.59%2 March 2009
CVE-2008-6386Cross-site scripting (XSS) vulnerability in showads.php in Z1Exchange 1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.46%2 March 2009
CVE-2008-6385Cross-site scripting (XSS) vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%2 March 2009
CVE-2008-6382ASP Portal 3.2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to ASPPortal.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.51%2 March 2009
CVE-2008-6381SQL injection vulnerability in modules/adresses/viewcat.php in bcoos 1.0.13, and possibly earlier, allows remote authenticated users with Addresses module permissions to execute arbitrary SQL commands via the cid parameter.EXPLOIT ✓MEDIUM 4.6EPSS 1.56%2 March 2009
CVE-2008-6380SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%2 March 2009
CVE-2008-6379SQL injection vulnerability in pics_pre.asp in Gallery MX 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%2 March 2009
CVE-2008-6378SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%2 March 2009
CVE-2008-6377PHP remote file inclusion vulnerability in include/global.php in Multi SEO phpBB 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the pfad parameter.EXPLOIT ✓HIGH 7.5EPSS 2.31%2 March 2009
CVE-2008-6376SQL injection vulnerability in main.asp in Jbook allows remote attackers to execute arbitrary SQL commands via the password (pass parameter).EXPLOIT ✓HIGH 7.5EPSS 0.97%2 March 2009
CVE-2008-6374CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to db/MailingList.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.59%2 March 2009
CVE-2008-6372SQL injection vulnerability in default.asp in Ocean12 FAQ Manager Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a Cat action.EXPLOIT ✓HIGH 7.5EPSS 0.97%2 March 2009
CVE-2008-6371SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the username (Username parameter).EXPLOIT ✓HIGH 7.5EPSS 2.00%2 March 2009
CVE-2008-6370Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to inject arbitrary web script or HTML via the DisplayFormat parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%2 March 2009
CVE-2008-6369SQL injection vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to execute arbitrary SQL commands via the Sort parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%2 March 2009
CVE-2008-6367Unrestricted file upload vulnerability in Photos/create_album.php in Social Groupie allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in…EXPLOIT ✓HIGH 8.5EPSS 3.40%2 March 2009
CVE-2008-6366SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, possibly related to the uname and pass parameters to…EXPLOIT ×2 ✓HIGH 7.5EPSS 3.35%2 March 2009
CVE-2008-6365SQL injection vulnerability in logon.jsp in Ad Server Solutions Ad Management Software Java allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, related to the uname or pass parameters to logon.jsp or…EXPLOIT ×2 ✓HIGH 7.5EPSS 3.35%2 March 2009
CVE-2008-6364SQL injection vulnerability in logon_process.jsp in Ad Server Solutions Banner Exchange Solution Java allows remote attackers to execute arbitrary SQL commands via the (1) username (uname parameter) and (2) password (pass parameter).EXPLOIT ✓HIGH 7.5EPSS 3.07%2 March 2009
CVE-2008-6363Stack-based buffer overflow in DesignWorks Professional 4.3.1 and 5.0.7 allows remote attackers to execute arbitrary code via a crafted .cct file.EXPLOIT ✓HIGH 9.3EPSS 5.59%2 March 2009
CVE-2008-6362SQL injection vulnerability in sitepage.php in Multiple Membership Script 2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%2 March 2009
CVE-2008-6361Directory traversal vulnerability in index.php in InSun Feed CMS 1.7.3 19Beta allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the lang parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.85%2 March 2009
CVE-2008-6358SQL injection vulnerability in group_index.php in Social Groupie allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%2 March 2009
CVE-2008-6357MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to mycal.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.59%2 March 2009
CVE-2008-6356evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to (1) evcal.mdb and (2) evcal97.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.59%2 March 2009
CVE-2008-6355The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to ASPired2Protect.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.33%2 March 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.