Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,094 CVEs1,726 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 252 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-6165 | SQL injection vulnerability in gestion.php in CSPartner 0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) pseudo and (2) passe parameters. | EXPLOIT ✓MEDIUM 6.8EPSS 0.95% | 19 February 2009 |
| CVE-2009-0646 | Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) password parameters to pcgi/4site.pl, (3) page parameter to print/print.shtml, (4) s and (5) i… | EXPLOIT ✓HIGH 7.5EPSS 3.60% | 18 February 2009 |
| CVE-2009-0645 | Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.5EPSS 6.28% | 18 February 2009 |
| CVE-2009-0639 | PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the Azione parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.57% | 18 February 2009 |
| CVE-2009-0611 | Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterprise Server 1.x allow remote attackers to inject arbitrary web script or HTML via (1) the siteloc parameter in a displayaddsite… | EXPLOIT ✓MEDIUM 4.3EPSS 2.23% | 17 February 2009 |
| CVE-2009-0610 | Multiple static code injection vulnerabilities in post.php in Simple PHP News 1.0 final allow remote attackers to inject arbitrary PHP code into news.txt via the (1) title or (2) date parameter, and then execute the code via a direct request to… | EXPLOIT ✓HIGH 7.5EPSS 4.82% | 17 February 2009 |
| CVE-2008-6158 | Multiple unspecified vulnerabilities in the admin backend in w3b>cms (aka w3blabor CMS) before 3.2.0 have unknown impact and remote attack vectors. | EXPLOIT ✓HIGH 10.0EPSS 2.91% | 17 February 2009 |
| CVE-2008-6157 | SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent attackers to obtain sensitive information. | EXPLOIT ✓HIGH 7.5EPSS 2.96% | 17 February 2009 |
| CVE-2009-0604 | SQL injection vulnerability in index.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary SQL commands via the searching parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 16 February 2009 |
| CVE-2009-0602 | Unrestricted file upload vulnerability in upload.php in WikkiTikkiTavi 1.11 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in img/. | EXPLOIT ✓HIGH 7.5EPSS 4.55% | 16 February 2009 |
| CVE-2008-6156 | SQL injection vulnerability in editCampaign.php in AdMan 1.1.20070907 allows remote authenticated users to execute arbitrary SQL commands via the campaignId parameter. | EXPLOIT ✓MEDIUM 6.5EPSS 0.86% | 16 February 2009 |
| CVE-2008-6155 | SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idtl parameter in a buy action. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 16 February 2009 |
| CVE-2008-6154 | SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idcat parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 16 February 2009 |
| CVE-2009-0598 | SQL injection vulnerability in index.php in PhpMesFilms 1.0 and 1.8 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 16 February 2009 |
| CVE-2009-0597 | SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the benutzername parameter (aka Username field) in a login action. | EXPLOIT ✓MEDIUM 6.8EPSS 1.97% | 16 February 2009 |
| CVE-2009-0596 | Directory traversal vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the TplSuffix parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.90% | 16 February 2009 |
| CVE-2009-0595 | PHP remote file inclusion vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the theme parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 22.2% | 16 February 2009 |
| CVE-2009-0594 | Cross-site scripting (XSS) vulnerability in index.php in phpSkelSite 1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 16 February 2009 |
| CVE-2009-0593 | SQL injection vulnerability in members.php in plx Auto Reminder 3.7 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a newar action. | EXPLOIT ✓MEDIUM 6.5EPSS 0.86% | 16 February 2009 |
| CVE-2009-0592 | Multiple directory traversal vulnerabilities in PNphpBB2 1.2i and earlier allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 28.8% | 16 February 2009 |
| CVE-2008-6153 | SQL injection vulnerability in Photo.asp in Jay Patel Pixel8 Web Photo Album 3.0 allows remote attackers to execute arbitrary SQL commands via the AlbumID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 16 February 2009 |
| CVE-2008-6152 | SQL injection vulnerability in deptdisplay.asp in SepCity Faculty Portal allows remote attackers to execute arbitrary SQL commands via the ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 16 February 2009 |
| CVE-2008-6151 | SQL injection vulnerability in shpdetails.asp in SepCity Shopping Mall allows remote attackers to execute arbitrary SQL commands via the ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 16 February 2009 |
| CVE-2008-6150 | SQL injection vulnerability in classdis.asp in SepCity Classified Ads allows remote attackers to execute arbitrary SQL commands via the ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 16 February 2009 |
| CVE-2008-6149 | SQL injection vulnerability in the mDigg (com_mdigg) component 2.2.8 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cagtegory parameter in a story_lists action to index.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.16% | 16 February 2009 |
| CVE-2008-6148 | SQL injection vulnerability in the Live Ticker (com_liveticker) module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a viewticker action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 16 February 2009 |
| CVE-2008-6147 | ForumApp 3.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) data/8690.mdb or (2) data/8690BAK.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.23% | 16 February 2009 |
| CVE-2008-6146 | SQL injection vulnerability in pm.php in DeluxeBB 1.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a delete##### parameter in a Delete action, a different vector than CVE-2005-2989. | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 16 February 2009 |
| CVE-2008-6143 | OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account name in the username cookie. | EXPLOIT ✓HIGH 7.5EPSS 6.12% | 16 February 2009 |
| CVE-2008-6142 | Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPic 0.0.4 and FlexPHPic Pro 0.0.3, and other 0.0.x versions, allow remote attackers to execute arbitrary SQL commands via (1) the checkuser parameter (aka username field), or (2) the… | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 16 February 2009 |
| CVE-2008-6139 | Directory traversal vulnerability in faqsupport/wce.download.php in WebBiscuits Modules Controller 1.1 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.67% | 14 February 2009 |
| CVE-2008-6138 | PHP remote file inclusion vulnerability in adminhead.php in WebBiscuits Modules Controller 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 14 February 2009 |
| CVE-2008-6133 | SQL injection vulnerability in arsaprint.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3942. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 13 February 2009 |
| CVE-2008-6132 | Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via the start_date parameter. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 26.1% | 13 February 2009 |
| CVE-2008-6126 | Multiple directory traversal vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.89% | 13 February 2009 |
| CVE-2009-0574 | SQL injection vulnerability in index.php in Easy CafeEngine allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-4604. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 13 February 2009 |
| CVE-2009-0573 | Multiple cross-site scripting (XSS) vulnerabilities in FotoWeb 6.0 (Build 273) allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to cmdrequest/Login.fwx and the (2) search parameter to Grid.fwx. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.48% | 13 February 2009 |
| CVE-2009-0572 | PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enabled and magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in… | EXPLOIT ✓MEDIUM 5.1EPSS 6.34% | 13 February 2009 |
| CVE-2009-0571 | admin.php in Ninja Designs Mailist 3.0 stores backup copies of maillist.php under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the backup directory. | EXPLOIT ✓MEDIUM 5.0EPSS 2.33% | 13 February 2009 |
| CVE-2009-0570 | Directory traversal vulnerability in send.php in Ninja Designs Mailist 3.0, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 5.1EPSS 1.96% | 13 February 2009 |
| CVE-2009-0360 | Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration… | EXPLOIT ✓MEDIUM 6.2EPSS 0.69% | 13 February 2009 |
| CVE-2009-0546 | Stack-based buffer overflow in NewsGator FeedDemon 2.7 and earlier allows user-assisted remote attackers to execute arbitrary code via a long text attribute in an outline element in a .opml file. | EXPLOIT ×4 ✓HIGH 9.3EPSS 36.5% | 12 February 2009 |
| CVE-2009-0545 | cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action. | EXPLOIT ✓HIGH 10.0EPSS 90.4% | 12 February 2009 |
| CVE-2009-0544 | Buffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large ARC2 key length. | EXPLOIT ✓HIGH 10.0EPSS 11.5% | 12 February 2009 |
| CVE-2009-0543 | ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres. | EXPLOIT ✓MEDIUM 6.8EPSS 15.8% | 12 February 2009 |
| CVE-2009-0542 | SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which introduces a "'" (single quote) character during variable substitution by… | EXPLOIT ×2 ✓HIGH 7.5EPSS 73.8% | 12 February 2009 |
| CVE-2009-0535 | Directory traversal vulnerability in export.php in Thyme 1.3 and earlier, when register_globals is disabled, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.32% | 11 February 2009 |
| CVE-2009-0534 | SQL injection vulnerability in FlexCMS allows remote attackers to execute arbitrary SQL commands via the catId parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.00% | 11 February 2009 |
| CVE-2009-0531 | SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote attackers to execute arbitrary SQL commands via the entry parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 11 February 2009 |
| CVE-2009-0530 | Multiple PHP remote file inclusion vulnerabilities in SnippetMaster 2.2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SCRIPT_PATH] parameter to includes/vars.inc.php and the (2)… | EXPLOIT ✓MEDIUM 6.8EPSS 1.86% | 11 February 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.