SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,149 CVEs1,726 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 254 of 501

CVESummaryPriorityPublished
CVE-2009-0443Stack-based buffer overflow in Elecard AVC HD PLAYER 5.5.90116 allows remote attackers to execute arbitrary code via an M3U file containing a long string in a URL.EXPLOIT ✓HIGH 9.3EPSS 5.59%10 February 2009
CVE-2009-0442Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 4.84%10 February 2009
CVE-2009-0441PHP remote file inclusion vulnerability in skin_shop/standard/2_view_body/body_default.php in TECHNOTE 7.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the shop_this_skin_path parameter, a…EXPLOIT ✓MEDIUM 6.8EPSS 3.92%10 February 2009
CVE-2008-6068SQL injection vulnerability in the JoomlaDate (com_joomladate) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a viewProfile action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.00%10 February 2009
CVE-2009-0498Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to guestbook.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.27%10 February 2009
CVE-2009-0497Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the log parameter.EXPLOIT ✓MEDIUM 5.0EPSS 8.13%10 February 2009
CVE-2009-0496Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) log parameter to (a) logviewer.jsp and (b) log.jsp; (2) search parameter to (c)…EXPLOIT ×3 ✓MEDIUM 4.3EPSS 4.35%10 February 2009
CVE-2009-0495PHP remote file inclusion vulnerability in include/define.php in REALTOR 747 4.11 allows remote attackers to execute arbitrary PHP code via a URL in the INC_DIR parameter.EXPLOIT ✓HIGH 7.5EPSS 2.10%10 February 2009
CVE-2009-0494SQL injection vulnerability in the Portfol (com_portfol) 1.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the vcatid parameter in a viewcategory action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.95%10 February 2009
CVE-2009-0493SQL injection vulnerability in login.php in IT!CMS 2.1a and earlier allows remote attackers to execute arbitrary SQL commands via the Username.EXPLOIT ✓HIGH 7.5EPSS 0.99%10 February 2009
CVE-2009-0491Stack-based buffer overflow in Elecard MPEG Player 5.5 build 15884.081218 allows remote attackers to execute arbitrary code via a M3U file containing a long URL.EXPLOIT ✓HIGH 9.3EPSS 5.86%10 February 2009
CVE-2009-0490Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions before 1.3.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary…EXPLOIT ×3 ✓HIGH 9.3EPSS 16.6%10 February 2009
CVE-2008-6097Multiple cross-site scripting (XSS) vulnerabilities in WikyBlog before 1.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to index.php/Special/Main/keywordSearch, (2) revNum parameter to…EXPLOIT ✓MEDIUM 4.3EPSS 1.73%9 February 2009
CVE-2008-6094Cross-site scripting (XSS) vulnerability in user.do in Celoxis Technologies Celoxis allows remote attackers to inject arbitrary web script or HTML via the ni.smessage parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.47%9 February 2009
CVE-2008-6093SQL injection vulnerability in index.php in Noname CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) file_id parameter in a detailansicht action and the (2) kategorie parameter in a…EXPLOIT ✓MEDIUM 6.8EPSS 0.91%9 February 2009
CVE-2008-6092phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie.EXPLOIT ✓HIGH 7.5EPSS 2.63%9 February 2009
CVE-2008-6091SQL injection vulnerability in plugins.php in BMForum 5.6, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tagname parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.91%9 February 2009
CVE-2009-0479Multiple SQL injection vulnerabilities in admin/admin_login.php in Online Grades 3.2.4 allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pword parameter.EXPLOIT ✓HIGH 7.5EPSS 0.91%9 February 2009
CVE-2009-0478Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c.EXPLOIT ✓MEDIUM 5.0EPSS 72.0%8 February 2009
CVE-2009-0476Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedia Soft audio components for .NET, allows remote attackers to execute arbitrary code via a long string in a playlist (.pls) file, as…EXPLOIT ×7 ✓HIGH 9.3EPSS 37.0%8 February 2009
CVE-2009-0470Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) level/15/exec/-/ or (2) exec/, a different…EXPLOIT ✓MEDIUM 4.3EPSS 4.43%6 February 2009
CVE-2008-6090Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a ..EXPLOIT ✓MEDIUM 4.3EPSS 2.29%6 February 2009
CVE-2008-6089Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 3.11%6 February 2009
CVE-2008-6088SQL injection vulnerability in the Joomtracker (com_joomtracker) 1.01 module for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tordetails action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.10%6 February 2009
CVE-2008-6087Cross-site scripting (XSS) vulnerability in topic.php in Camera Life 2.6.2b4 allows remote attackers to inject arbitrary web script or HTML via the name parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.60%6 February 2009
CVE-2008-6086SQL injection vulnerability in album.php in Camera Life 2.6.2b4 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3355.EXPLOIT ✓HIGH 7.5EPSS 1.10%6 February 2009
CVE-2008-6084Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file…EXPLOIT ✓MEDIUM 6.8EPSS 2.23%6 February 2009
CVE-2008-6083Directory traversal vulnerability in header.php in TXTshop beta 1.0 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.66%6 February 2009
CVE-2008-6082Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO command.EXPLOIT ✓MEDIUM 5.0EPSS 44.6%6 February 2009
CVE-2008-6081SQL injection vulnerability in contact.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.10%6 February 2009
CVE-2008-6080Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 10.6%6 February 2009
CVE-2008-6078SQL injection vulnerability in open.php in the Private Messaging (com_privmsg) component for Limbo CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a pms action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%6 February 2009
CVE-2008-6077SQL injection vulnerability in loudblog/ajax.php in LoudBlog 0.8.0a and earlier allows remote authenticated users to execute arbitrary SQL commands via the colpick parameter in a singleread action.EXPLOIT ✓MEDIUM 6.5EPSS 0.86%6 February 2009
CVE-2008-6076SQL injection vulnerability in the Daily Message (com_dailymessage) 1.0.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%6 February 2009
CVE-2008-6075SQL injection vulnerability in aspkat.asp in Bahar Download Script 2.0 allows remote attackers to execute arbitrary SQL commands via the kid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.96%6 February 2009
CVE-2008-6074Directory traversal vulnerability in frame.php in phpcrs 2.06 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 5.1EPSS 1.98%6 February 2009
CVE-2008-6066Multiple PHP remote file inclusion vulnerabilities in Meet#Web 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) modules.php, (2) ManagerResource.class.php, (3) ManagerRightsResource.class.php, (4)…EXPLOIT ×6 ✓HIGH 7.5EPSS 2.54%5 February 2009
CVE-2008-6065Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that are aliased in a CREATE OR REPLACE DIRECTORY statement, which allows remote authenticated users with CREATE ANY DIRECTORY privileges to gain…EXPLOIT ✓MEDIUM 5.1EPSS 2.20%5 February 2009
CVE-2008-6064Multiple SQL injection vulnerabilities in DomPHP 0.81 allow remote attackers to execute arbitrary SQL commands via the cat parameter to agenda/index.php, and unspecified other vectors.EXPLOIT ✓HIGH 7.5EPSS 0.93%5 February 2009
CVE-2008-6061Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) controller files created by Techsmith Camtasia Studio before 5 allows remote attackers to inject arbitrary additional SWF content via a URL in the csPreloader…EXPLOIT ✓MEDIUM 4.3EPSS 4.08%5 February 2009
CVE-2008-6060Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by InfoSoft FusionCharts allows remote attackers to inject arbitrary additional SWF content via a URL in the SRC attribute of an IMG element in the…EXPLOIT ✓MEDIUM 4.3EPSS 2.05%5 February 2009
CVE-2009-0431SQL injection vulnerability in Default.asp in LinksPro Standard Edition allows remote attackers to execute arbitrary SQL commands via the OrderDirection parameter.EXPLOIT ✓HIGH 7.5EPSS 1.84%5 February 2009
CVE-2009-0430Multiple cross-site scripting (XSS) vulnerabilities in Active Bids allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to search.asp and the (2) URL parameter to tellafriend.asp.EXPLOIT ✓MEDIUM 4.3EPSS 1.19%5 February 2009
CVE-2009-0429Multiple SQL injection vulnerabilities in Active Bids allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to search.asp, (2) SortDir parameter to auctionsended.asp, and the (3) catid parameter to wishlist.php.EXPLOIT ✓HIGH 7.5EPSS 0.91%5 February 2009
CVE-2009-0428SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Secure Document Library 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.19%5 February 2009
CVE-2009-0427SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.19%5 February 2009
CVE-2009-0426SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%5 February 2009
CVE-2009-0425SQL injection vulnerability in index.php in Blue Eye CMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the clanek parameter.EXPLOIT ✓HIGH 7.5EPSS 0.95%5 February 2009
CVE-2009-0423Directory traversal vulnerability in index.php in Php Photo Album (PHPPA) 0.8 BETA allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 6.06%5 February 2009
CVE-2009-0422Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the…EXPLOIT ✓HIGH 7.5EPSS 6.20%5 February 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.