SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,094 CVEs1,726 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 253 of 501

CVESummaryPriorityPublished
CVE-2009-0529Cross-site scripting (XSS) vulnerability in index.php in SnippetMaster Webpage Editor 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the language parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.48%11 February 2009
CVE-2009-0528SQL injection vulnerability in frame.php in Rhadrix If-CMS 2.07 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%11 February 2009
CVE-2009-0527PHP remote file inclusion vulnerability in plugins/rss_importer_functions.php in AdaptCMS Lite 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the sitepath parameter.EXPLOIT ✓MEDIUM 6.8EPSS 3.92%11 February 2009
CVE-2009-0526Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdaptCMS Lite 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) url and (2) acuparam parameters, and (3) the URI.EXPLOIT ✓MEDIUM 4.3EPSS 1.48%11 February 2009
CVE-2009-0036Buffer overflow in the proxyReadClientSocket function in proxy/libvirt_proxy.c in libvirt_proxy 0.5.1 might allow local users to gain privileges by sending a portion of the header of a virProxyPacket packet, and then sending the remainder of the packet…EXPLOIT ✓MEDIUM 4.4EPSS 1.17%11 February 2009
CVE-2008-6122The web management interface in Netgear WGR614v9 allows remote attackers to cause a denial of service (crash) via a request that contains a question mark ("?").EXPLOIT ✓HIGH 7.8EPSS 3.18%11 February 2009
CVE-2008-6119Static code injection vulnerability in gooplecms/admin/account/action/editpass.php in Goople CMS 1.7 allows remote attackers to inject arbitrary PHP code into admin/userandpass.php via the (1) username and (2) password parameters.EXPLOIT ✓HIGH 7.5EPSS 2.21%11 February 2009
CVE-2008-6118win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1.EXPLOIT ×2 ✓HIGH 7.5EPSS 2.89%11 February 2009
CVE-2008-6117SQL injection vulnerability in homepage.php in PG Job Site Pro allows remote attackers to execute arbitrary SQL commands via the poll_view_id parameter in a results action.EXPLOIT ✓HIGH 7.5EPSS 1.00%11 February 2009
CVE-2008-6116SQL injection vulnerability in the EXtrovert Software Thyme (com_thyme) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.10%11 February 2009
CVE-2008-6115SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL commands via the id parameter in a deadlink action, a different vector than CVE-2008-2083.EXPLOIT ✓HIGH 7.5EPSS 1.14%11 February 2009
CVE-2008-6114SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attackers to execute arbitrary SQL commands via the product parameter.EXPLOIT ✓HIGH 7.5EPSS 1.10%11 February 2009
CVE-2008-6112Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 3.02%11 February 2009
CVE-2008-6111SQL injection vulnerability in blog.php in NetArt Media Vlog System 1.1 allows remote attackers to execute arbitrary SQL commands via the note parameter.EXPLOIT ✓HIGH 7.5EPSS 1.14%11 February 2009
CVE-2009-0517Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class.EXPLOIT ✓HIGH 10.0EPSS 48.9%11 February 2009
CVE-2009-0516SQL injection vulnerability in the classified page (classified.php) in BusinessSpace 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.02%11 February 2009
CVE-2009-0515Directory traversal vulnerability in check_lang.php in Yet Another NOCC (YANOCC) 0.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.98%11 February 2009
CVE-2009-0514Multiple directory traversal vulnerabilities in WebFrame 0.76 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) currentmod and (2) LANG parameters to mod/index.php.EXPLOIT ✓HIGH 7.5EPSS 2.30%11 February 2009
CVE-2009-0513Multiple PHP remote file inclusion vulnerabilities in WebFrame 0.76 allow remote attackers to execute arbitrary PHP code via a URL in the classFiles parameter to (1) admin/doc/index.php, (2) index.php, and (3) base/menu.php in mod/.EXPLOIT ✓HIGH 7.5EPSS 2.10%11 February 2009
CVE-2009-0455Cross-site scripting (XSS) vulnerability in the anonymous comments feature in lib-comment.php in glFusion 1.1.0, 1.1.1, and earlier versions allows remote attackers to inject arbitrary web script or HTML via the username parameter to comment.php.EXPLOIT ✓LOW 2.6EPSS 1.62%11 February 2009
CVE-2009-0076Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the zoom style directive in conjunction with unspecified other directives in a malformed Cascading Style Sheets (CSS) stylesheet in a…EXPLOIT ×4 ✓HIGH 9.3EPSS 33.5%10 February 2009
CVE-2009-0075Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to CFunctionPointer and the appending of document…EXPLOIT ×6 ✓HIGH 9.3EPSS 85.3%10 February 2009
CVE-2008-6104SQL injection vulnerability in A4Desk PHP Event Calendar allows remote attackers to execute arbitrary SQL commands via the eventid parameter to admin/index.php.EXPLOIT ✓HIGH 7.5EPSS 0.96%10 February 2009
CVE-2008-6103PHP remote file inclusion vulnerability in index.php in A4Desk Event Calendar, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the v parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.02%10 February 2009
CVE-2008-6102SQL injection vulnerability in ratelink.php in Link Trader Script allows remote attackers to execute arbitrary SQL commands via the lnkid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.11%10 February 2009
CVE-2008-6101SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary SQL commands via the targetid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.19%10 February 2009
CVE-2008-6100Multiple SQL injection vulnerabilities in Discussion Forums 2k 3.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter to (a) RSS1.php and (b) RSS2.php in misc/; and the (2) SubID…EXPLOIT ✓MEDIUM 6.8EPSS 0.91%10 February 2009
CVE-2008-6099PHP remote file inclusion vulnerability in index.php in RPortal 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_op parameter.EXPLOIT ✓HIGH 7.5EPSS 2.65%10 February 2009
CVE-2009-0468Multiple cross-site request forgery (CSRF) vulnerabilities in ajax.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allow remote attackers to hijack the authentication of administrators for requests that (1) shutdown the server, (2) send ping…EXPLOIT ✓MEDIUM 6.8EPSS 0.97%10 February 2009
CVE-2009-0467Cross-site scripting (XSS) vulnerability in proxy.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allows remote attackers to inject arbitrary web script or HTML via the proxy parameter in a deny_log manage action.EXPLOIT ✓MEDIUM 4.3EPSS 1.48%10 February 2009
CVE-2009-0465The SaveDoc method in the All_In_The_Box.AllBox ActiveX control in ALL_IN_THE_BOX.OCX in Synactis ALL In-The-Box ActiveX 3 allows remote attackers to create and overwrite arbitrary files via an argument ending in a '\0' character, which bypasses the…EXPLOIT ✓HIGH 9.3EPSS 3.64%10 February 2009
CVE-2009-0464PHP remote file inclusion vulnerability in includes/header.php in Groone GBook 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.EXPLOIT ✓MEDIUM 5.1EPSS 5.31%10 February 2009
CVE-2009-0463PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.26%10 February 2009
CVE-2009-0462Multiple SQL injection vulnerabilities in customer_login_check.asp in ClickTech ClickCart 6.0 allow remote attackers to execute arbitrary SQL commands via (1) the txtEmail parameter (aka E-MAIL field) or (2) the txtPassword parameter (aka password…EXPLOIT ✓HIGH 7.5EPSS 0.99%10 February 2009
CVE-2009-0461Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.EXPLOIT ×2 ✓HIGH 7.5EPSS 2.83%10 February 2009
CVE-2009-0460Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.EXPLOIT ×2 ✓HIGH 7.5EPSS 2.83%10 February 2009
CVE-2009-0459Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password…EXPLOIT ×2 ✓HIGH 7.5EPSS 2.14%10 February 2009
CVE-2009-0458Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Ware Support 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field).EXPLOIT ×2 ✓HIGH 7.5EPSS 2.34%10 February 2009
CVE-2009-0457Multiple directory traversal vulnerabilities in AJA Portal 1.2 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the currentlang parameter to admin/case.php in the (1) Contact_Plus and (2) Reviews…EXPLOIT ✓HIGH 7.5EPSS 6.11%10 February 2009
CVE-2009-0456PHP remote file inclusion vulnerability in examples/example_clientside_javascript.php in patForms, as used in Sourdough 0.3.5, allows remote attackers to execute arbitrary PHP code via a URL in the neededFiles[patForms] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.10%10 February 2009
CVE-2009-0453Online Grades 3.2.4 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.EXPLOIT ✓MEDIUM 5.0EPSS 2.62%10 February 2009
CVE-2009-0452Multiple SQL injection vulnerabilities in parents/login.php in Online Grades 3.2.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pass parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.94%10 February 2009
CVE-2009-0451SQL injection vulnerability in Skalfa SkaLinks 1.5 allows remote attackers to execute arbitrary SQL commands via the Admin name field to the default URI under admin/.EXPLOIT ✓HIGH 7.5EPSS 0.95%10 February 2009
CVE-2009-0450Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code via a long string in a playlist (aka .plf) file.EXPLOIT ×4 ✓HIGH 9.3EPSS 10.1%10 February 2009
CVE-2009-0449Buffer overflow in klim5.sys in Kaspersky Anti-Virus for Workstations 6.0 and Anti-Virus 2008 allows local users to gain privileges via an IOCTL 0x80052110 call.EXPLOIT ✓HIGH 7.2EPSS 0.96%10 February 2009
CVE-2009-0448Directory traversal vulnerability in admin/modules/aa/preview.php in Syntax Desktop 2.7 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.33%10 February 2009
CVE-2009-0447Multiple SQL injection vulnerabilities in default.asp in MyDesign Sayac 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the user parameter (aka UserName field) or (2) the pass parameter (aka Pass field) to (a) admin/admin.asp or (b)…EXPLOIT ✓HIGH 7.5EPSS 0.99%10 February 2009
CVE-2009-0446SQL injection vulnerability in photo.php in WEBalbum 2.4b allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.95%10 February 2009
CVE-2009-0445SQL injection vulnerability in index.php in Dreampics Gallery Builder allows remote attackers to execute arbitrary SQL commands via the exhibition_id parameter in a gallery.viewPhotos action.EXPLOIT ✓HIGH 7.5EPSS 1.18%10 February 2009
CVE-2009-0444Multiple PHP remote file inclusion vulnerabilities in GRBoard 1.8, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) theme parameter to (a)…EXPLOIT ✓HIGH 7.5EPSS 2.46%10 February 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.