Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,020 CVEs1,725 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 247 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-0815 | The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote attackers to read arbitrary files by… | EXPLOIT ✓MEDIUM 5.0EPSS 42.2% | 5 March 2009 |
| CVE-2009-0814 | Cross-site scripting (XSS) vulnerability in Widgets.aspx in Blogsa 1.0 Beta 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchText parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 5 March 2009 |
| CVE-2009-0813 | Insecure method vulnerability in the ImeraIEPlugin ActiveX control (ImeraIEPlugin.dll 1.0.2.54) in Imera TeamLinks Client allows remote attackers to force the download and execution of arbitrary URLs via modified DownloadProtocol, DownloadHost,… | EXPLOIT ✓HIGH 9.3EPSS 9.09% | 5 March 2009 |
| CVE-2009-0367 | The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe… | EXPLOIT ✓HIGH 9.3EPSS 10.9% | 5 March 2009 |
| CVE-2009-0037 | The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or… | EXPLOIT ✓MEDIUM 6.8EPSS 9.05% | 5 March 2009 |
| CVE-2009-0812 | Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions allows remote attackers to execute arbitrary code via a crafted Intel Hex Code (.hex) file. | EXPLOIT ×2 ✓HIGH 9.3EPSS 6.90% | 4 March 2009 |
| CVE-2009-0811 | Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to execute arbitrary programs via an executable file name in the argument to the SetExternalPlayer method. | EXPLOIT ✓HIGH 9.3EPSS 5.54% | 4 March 2009 |
| CVE-2009-0810 | SQL injection vulnerability in login.php in xGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 4 March 2009 |
| CVE-2009-0807 | zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php. | EXPLOIT ✓HIGH 7.5EPSS 2.14% | 4 March 2009 |
| CVE-2008-6396 | Cross-site scripting (XSS) vulnerability in account.php in Celerondude Uploader 6.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 4 March 2009 |
| CVE-2008-6394 | SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the cs_cookies[customer_user_id] cookie parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 4 March 2009 |
| CVE-2009-0756 | The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that triggers a parsing error, which is not properly handled by JBIG2SymbolDict::~JBIG2SymbolDict and… | EXPLOIT ✓MEDIUM 5.0EPSS 10.1% | 3 March 2009 |
| CVE-2009-0755 | The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file with an invalid Form Opt entry. | EXPLOIT ✓MEDIUM 5.0EPSS 10.8% | 3 March 2009 |
| CVE-2009-0754 | PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to… | EXPLOIT ✓LOW 2.1EPSS 0.95% | 3 March 2009 |
| CVE-2009-0753 | Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files via a leading "//" (double slash) in the filename. | EXPLOIT ✓MEDIUM 5.0EPSS 5.80% | 3 March 2009 |
| CVE-2008-6393 | PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an… | EXPLOIT ✓HIGH 10.0EPSS 18.2% | 3 March 2009 |
| CVE-2009-0751 | Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers. | EXPLOIT ✓MEDIUM 5.0EPSS 10.4% | 2 March 2009 |
| CVE-2009-0750 | SQL injection vulnerability in login.php in the smNews example script for txtSQL 2.2 Final allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.09% | 2 March 2009 |
| CVE-2009-0368 | OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the… | EXPLOIT ✓LOW 2.1EPSS 1.21% | 2 March 2009 |
| CVE-2008-6392 | SQL injection vulnerability in showads.php in Z1Exchange allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 2 March 2009 |
| CVE-2008-6391 | SQL injection vulnerability in main.asp in Jbook allows remote attackers to execute arbitrary SQL commands via the username (user parameter). | EXPLOIT ✓HIGH 7.5EPSS 0.89% | 2 March 2009 |
| CVE-2008-6390 | SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 2 March 2009 |
| CVE-2008-6389 | SQL injection vulnerability in asadmin/default.asp in Rae Media Contact Management Software SOHO, Standard, and Enterprise allows remote attackers to execute arbitrary SQL commands via the Password parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 2 March 2009 |
| CVE-2008-6388 | Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to cldb.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.23% | 2 March 2009 |
| CVE-2008-6387 | Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to qtv.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.59% | 2 March 2009 |
| CVE-2008-6386 | Cross-site scripting (XSS) vulnerability in showads.php in Z1Exchange 1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.46% | 2 March 2009 |
| CVE-2008-6385 | Cross-site scripting (XSS) vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 2 March 2009 |
| CVE-2008-6382 | ASP Portal 3.2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to ASPPortal.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.51% | 2 March 2009 |
| CVE-2008-6381 | SQL injection vulnerability in modules/adresses/viewcat.php in bcoos 1.0.13, and possibly earlier, allows remote authenticated users with Addresses module permissions to execute arbitrary SQL commands via the cid parameter. | EXPLOIT ✓MEDIUM 4.6EPSS 1.56% | 2 March 2009 |
| CVE-2008-6380 | SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 2 March 2009 |
| CVE-2008-6379 | SQL injection vulnerability in pics_pre.asp in Gallery MX 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 2 March 2009 |
| CVE-2008-6378 | SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 2 March 2009 |
| CVE-2008-6377 | PHP remote file inclusion vulnerability in include/global.php in Multi SEO phpBB 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the pfad parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.31% | 2 March 2009 |
| CVE-2008-6376 | SQL injection vulnerability in main.asp in Jbook allows remote attackers to execute arbitrary SQL commands via the password (pass parameter). | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 2 March 2009 |
| CVE-2008-6374 | CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to db/MailingList.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.59% | 2 March 2009 |
| CVE-2008-6372 | SQL injection vulnerability in default.asp in Ocean12 FAQ Manager Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a Cat action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 2 March 2009 |
| CVE-2008-6371 | SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the username (Username parameter). | EXPLOIT ✓HIGH 7.5EPSS 2.00% | 2 March 2009 |
| CVE-2008-6370 | Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to inject arbitrary web script or HTML via the DisplayFormat parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 2 March 2009 |
| CVE-2008-6369 | SQL injection vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to execute arbitrary SQL commands via the Sort parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 2 March 2009 |
| CVE-2008-6367 | Unrestricted file upload vulnerability in Photos/create_album.php in Social Groupie allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in… | EXPLOIT ✓HIGH 8.5EPSS 3.40% | 2 March 2009 |
| CVE-2008-6366 | SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, possibly related to the uname and pass parameters to… | EXPLOIT ×2 ✓HIGH 7.5EPSS 3.35% | 2 March 2009 |
| CVE-2008-6365 | SQL injection vulnerability in logon.jsp in Ad Server Solutions Ad Management Software Java allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, related to the uname or pass parameters to logon.jsp or… | EXPLOIT ×2 ✓HIGH 7.5EPSS 3.35% | 2 March 2009 |
| CVE-2008-6364 | SQL injection vulnerability in logon_process.jsp in Ad Server Solutions Banner Exchange Solution Java allows remote attackers to execute arbitrary SQL commands via the (1) username (uname parameter) and (2) password (pass parameter). | EXPLOIT ✓HIGH 7.5EPSS 3.07% | 2 March 2009 |
| CVE-2008-6363 | Stack-based buffer overflow in DesignWorks Professional 4.3.1 and 5.0.7 allows remote attackers to execute arbitrary code via a crafted .cct file. | EXPLOIT ✓HIGH 9.3EPSS 5.59% | 2 March 2009 |
| CVE-2008-6362 | SQL injection vulnerability in sitepage.php in Multiple Membership Script 2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 2 March 2009 |
| CVE-2008-6361 | Directory traversal vulnerability in index.php in InSun Feed CMS 1.7.3 19Beta allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the lang parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.85% | 2 March 2009 |
| CVE-2008-6358 | SQL injection vulnerability in group_index.php in Social Groupie allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 2 March 2009 |
| CVE-2008-6357 | MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to mycal.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.59% | 2 March 2009 |
| CVE-2008-6356 | evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to (1) evcal.mdb and (2) evcal97.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.59% | 2 March 2009 |
| CVE-2008-6355 | The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to ASPired2Protect.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.33% | 2 March 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.