Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,094 CVEs1,726 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 251 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-0650 | Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a STATS line with a long pwd… | EXPLOIT ✓HIGH 10.0EPSS 12.8% | 20 February 2009 |
| CVE-2009-0649 | The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) via JavaScript code that calls the setAttributeNode method. | EXPLOIT ✓HIGH 7.8EPSS 8.33% | 20 February 2009 |
| CVE-2008-6217 | Cross-site scripting (XSS) vulnerability in index.php in Extrakt Framework 0.7 allows remote attackers to inject arbitrary web script or HTML via the plugins[file][id] parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 20 February 2009 |
| CVE-2008-6216 | SQL injection vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to execute arbitrary SQL commands via the OfertaID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.36% | 20 February 2009 |
| CVE-2008-6215 | Cross-site scripting (XSS) vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to inject arbitrary web script or HTML via the OfertaID parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.74% | 20 February 2009 |
| CVE-2008-6214 | SQL injection vulnerability in poll_results.php in Harlandscripts Pro Traffic One allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 20 February 2009 |
| CVE-2008-6213 | SQL injection vulnerability in mypage.php in Harlandscripts Pro Traffic One allows remote attackers to execute arbitrary SQL commands via the trg parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.31% | 20 February 2009 |
| CVE-2009-0643 | Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary PHP code into news.txt via the post parameter, and then execute the code via a direct request to display.php. | EXPLOIT ✓MEDIUM 5.1EPSS 4.81% | 20 February 2009 |
| CVE-2009-0641 | sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a… | EXPLOIT ✓HIGH 9.3EPSS 9.32% | 20 February 2009 |
| CVE-2009-0640 | Directory traversal vulnerability in the administrative web server in Swann DVR4-SecuraNet allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.77% | 20 February 2009 |
| CVE-2008-6164 | Cross-site scripting (XSS) vulnerability in index.php in DreamCost HostAdmin 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 20 February 2009 |
| CVE-2008-6163 | SQL injection vulnerability in www/delivery/ac.php in OpenX 2.6.1 allows remote attackers to execute arbitrary SQL commands via the bannerid parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.35% | 20 February 2009 |
| CVE-2008-6162 | Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1 and the usNick cookie to admin. | EXPLOIT ✓HIGH 7.5EPSS 2.56% | 20 February 2009 |
| CVE-2008-6212 | Cross-site scripting (XSS) vulnerability in admin.php in Php-Stats 0.1.9.1 allows remote attackers to inject arbitrary web script or HTML via the (1) sel_mese and (2) sel_anno parameters in a systems action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 20 February 2009 |
| CVE-2008-6211 | Multiple cross-site scripting (XSS) vulnerabilities in PhpForums.net mcGallery 1.1 allow remote attackers to inject arbitrary web script or HTML via the lang parameter to (1) admin.php, (2) index.php, (3) sess.php, (4) stats.php, (5) detail.php, (6)… | EXPLOIT ×7 ✓MEDIUM 4.3EPSS 1.48% | 20 February 2009 |
| CVE-2008-6210 | SQL injection vulnerability in index.php in dream4 Koobi 4.4 and 5.4 allows remote attackers to execute arbitrary SQL commands via the img_id parameter in the gallerypic page. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97% | 20 February 2009 |
| CVE-2008-6209 | SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 20 February 2009 |
| CVE-2008-6206 | Multiple PHP remote file inclusion vulnerabilities in RobotStats 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter to (1) graph.php and (2) robotstats.inc.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.54% | 20 February 2009 |
| CVE-2008-6205 | Cross-site scripting (XSS) vulnerability in seeurl.php in Xavier Flahaut URLStreet 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) language, (2) order, and (3) filter parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 20 February 2009 |
| CVE-2008-6204 | Multiple SQL injection vulnerabilities in SuperNET Shop 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to secure/admin/guncelle.asp, (2) kulad and sifre parameters to secure/admin/giris.asp, and (3)… | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 20 February 2009 |
| CVE-2008-6203 | SQL injection vulnerability in adminler.asp in CoBaLT 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 20 February 2009 |
| CVE-2008-6202 | SQL injection vulnerability in CoBaLT 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) urun.asp, (2) admin/bayi_listele.asp, (3) admin/urun_grup_listele.asp, and (4) admin/urun_listele.asp. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 20 February 2009 |
| CVE-2008-6201 | Directory traversal vulnerability in help.php in the eskuel module in KwsPHP 1.3.456, as available before 20080416, allows remote attackers to execute arbitrary commands via the action parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 3.06% | 20 February 2009 |
| CVE-2008-6200 | Multiple cross-site scripting (XSS) vulnerabilities in Swiki 1.5 allow remote attackers to inject arbitrary web script or HTML via (1) the query string and (2) a new wiki entry. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 20 February 2009 |
| CVE-2008-6199 | 2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via a direct request to backup.php, which creates backup.sql under the web root with insufficient access control. | EXPLOIT ✓MEDIUM 4.0EPSS 1.86% | 20 February 2009 |
| CVE-2008-6198 | SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 20 February 2009 |
| CVE-2008-6197 | SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arbitrary SQL commands via the id_gal parameter in a gal action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 20 February 2009 |
| CVE-2008-6196 | Multiple PHP remote file inclusion vulnerabilities in Philippe CROCHAT EasySite 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the EASYSITE_BASE parameter to (1) browser.php, (2) image_editor.php and (3) skin_chooser.php in… | EXPLOIT ×3 ✓HIGH 7.5EPSS 2.54% | 20 February 2009 |
| CVE-2008-6195 | Directory traversal vulnerability in the PXE TFTP Service (PXEMTFTP.exe) in LANDesk Management Suite (LDMS) 8.80.1.1 and earlier allows remote attackers to read arbitrary files via a subdirectory name followed by ".." sequences, a different… | EXPLOIT ✓HIGH 7.8EPSS 2.88% | 20 February 2009 |
| CVE-2008-6193 | Sam Crew MyBlog stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information. | EXPLOIT ✓MEDIUM 5.0EPSS 2.12% | 19 February 2009 |
| CVE-2008-6189 | SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, which is not properly handled in database-pgsql.php. | EXPLOIT ✓HIGH 7.5EPSS 2.32% | 19 February 2009 |
| CVE-2008-6188 | SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.31% | 19 February 2009 |
| CVE-2008-6187 | SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.31% | 19 February 2009 |
| CVE-2008-6186 | Stack-based buffer overflow in RaidenFTPD 2.4 build 3620 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via long (1) CWD and (2) MLST commands. | EXPLOIT ✓HIGH 9.0EPSS 5.30% | 19 February 2009 |
| CVE-2008-6185 | NoticeWare Email Server NG 5.1.2.2 allows remote attackers to cause a denial of service (crash) via multiple POP3 requests with a long PASS command. | EXPLOIT ✓MEDIUM 5.0EPSS 2.70% | 19 February 2009 |
| CVE-2008-6184 | SQL injection vulnerability in the OwnBiblio (com_ownbiblio) component 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a catalogue action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 19 February 2009 |
| CVE-2008-6183 | Multiple directory traversal vulnerabilities in index.php in My PHP Indexer 1.0 allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 2.84% | 19 February 2009 |
| CVE-2008-6182 | SQL injection vulnerability in the Ignite Gallery (com_ignitegallery) component 0.8.0 through 0.8.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gallery parameter in a view action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.00% | 19 February 2009 |
| CVE-2008-6181 | SQL injection vulnerability in the Mad4Joomla Mailforms (com_mad4joomla) component before 1.1.8.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the jid parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 19 February 2009 |
| CVE-2008-6180 | SQL injection vulnerability in system/nlb_user.class.php in NewLife Blogger 3.0 and earlier, and possibly 3.3.1, allows remote attackers to execute arbitrary SQL commands via the nlb3 cookie. | EXPLOIT ✓HIGH 7.5EPSS 1.68% | 19 February 2009 |
| CVE-2008-6179 | SQL injection vulnerability in sug_cat.php in IndexScript 3.0 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter, a different vector than CVE-2007-4069. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 19 February 2009 |
| CVE-2008-6178 | Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4 CMS, Nuke ET, and other products, allows remote attackers to execute arbitrary code by creating a file with PHP… | EXPLOIT ×2 ✓HIGH 7.5EPSS 7.81% | 19 February 2009 |
| CVE-2008-6177 | Multiple directory traversal vulnerabilities in LightBlog 9.8, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.86% | 19 February 2009 |
| CVE-2008-6175 | SilverSHielD 1.0.2.34 allows remote attackers to cause a denial of service (application crash) via a crafted argument to the opendir SFTP command. | EXPLOIT ✓MEDIUM 5.0EPSS 6.08% | 19 February 2009 |
| CVE-2008-6174 | Cross-site scripting (XSS) vulnerability in admin/postlister/index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the liste parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 19 February 2009 |
| CVE-2008-6173 | Cross-site scripting (XSS) vulnerability in fullscreen.php in ClipShare Pro 4.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 19 February 2009 |
| CVE-2008-6172 | Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal… | EXPLOIT ✓MEDIUM 6.8EPSS 12.3% | 19 February 2009 |
| CVE-2008-6168 | Cross-site scripting (XSS) vulnerability in search.php in miniPortail 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified argument, probably the search string. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 19 February 2009 |
| CVE-2008-6167 | Directory traversal vulnerability in search.php in miniPortail 2.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 19 February 2009 |
| CVE-2008-6166 | SQL injection vulnerability in the KBase (com_kbase) 1.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 19 February 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.