Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,149 CVEs1,726 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 254 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-0443 | Stack-based buffer overflow in Elecard AVC HD PLAYER 5.5.90116 allows remote attackers to execute arbitrary code via an M3U file containing a long string in a URL. | EXPLOIT ✓HIGH 9.3EPSS 5.59% | 10 February 2009 |
| CVE-2009-0442 | Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 4.84% | 10 February 2009 |
| CVE-2009-0441 | PHP remote file inclusion vulnerability in skin_shop/standard/2_view_body/body_default.php in TECHNOTE 7.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the shop_this_skin_path parameter, a… | EXPLOIT ✓MEDIUM 6.8EPSS 3.92% | 10 February 2009 |
| CVE-2008-6068 | SQL injection vulnerability in the JoomlaDate (com_joomladate) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a viewProfile action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 10 February 2009 |
| CVE-2009-0498 | Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to guestbook.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.27% | 10 February 2009 |
| CVE-2009-0497 | Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the log parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 8.13% | 10 February 2009 |
| CVE-2009-0496 | Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) log parameter to (a) logviewer.jsp and (b) log.jsp; (2) search parameter to (c)… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 4.35% | 10 February 2009 |
| CVE-2009-0495 | PHP remote file inclusion vulnerability in include/define.php in REALTOR 747 4.11 allows remote attackers to execute arbitrary PHP code via a URL in the INC_DIR parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.10% | 10 February 2009 |
| CVE-2009-0494 | SQL injection vulnerability in the Portfol (com_portfol) 1.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the vcatid parameter in a viewcategory action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 10 February 2009 |
| CVE-2009-0493 | SQL injection vulnerability in login.php in IT!CMS 2.1a and earlier allows remote attackers to execute arbitrary SQL commands via the Username. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 10 February 2009 |
| CVE-2009-0491 | Stack-based buffer overflow in Elecard MPEG Player 5.5 build 15884.081218 allows remote attackers to execute arbitrary code via a M3U file containing a long URL. | EXPLOIT ✓HIGH 9.3EPSS 5.86% | 10 February 2009 |
| CVE-2009-0490 | Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions before 1.3.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary… | EXPLOIT ×3 ✓HIGH 9.3EPSS 16.6% | 10 February 2009 |
| CVE-2008-6097 | Multiple cross-site scripting (XSS) vulnerabilities in WikyBlog before 1.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to index.php/Special/Main/keywordSearch, (2) revNum parameter to… | EXPLOIT ✓MEDIUM 4.3EPSS 1.73% | 9 February 2009 |
| CVE-2008-6094 | Cross-site scripting (XSS) vulnerability in user.do in Celoxis Technologies Celoxis allows remote attackers to inject arbitrary web script or HTML via the ni.smessage parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 9 February 2009 |
| CVE-2008-6093 | SQL injection vulnerability in index.php in Noname CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) file_id parameter in a detailansicht action and the (2) kategorie parameter in a… | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 9 February 2009 |
| CVE-2008-6092 | phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie. | EXPLOIT ✓HIGH 7.5EPSS 2.63% | 9 February 2009 |
| CVE-2008-6091 | SQL injection vulnerability in plugins.php in BMForum 5.6, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tagname parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 9 February 2009 |
| CVE-2009-0479 | Multiple SQL injection vulnerabilities in admin/admin_login.php in Online Grades 3.2.4 allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pword parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 9 February 2009 |
| CVE-2009-0478 | Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c. | EXPLOIT ✓MEDIUM 5.0EPSS 72.0% | 8 February 2009 |
| CVE-2009-0476 | Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedia Soft audio components for .NET, allows remote attackers to execute arbitrary code via a long string in a playlist (.pls) file, as… | EXPLOIT ×7 ✓HIGH 9.3EPSS 37.0% | 8 February 2009 |
| CVE-2009-0470 | Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) level/15/exec/-/ or (2) exec/, a different… | EXPLOIT ✓MEDIUM 4.3EPSS 4.43% | 6 February 2009 |
| CVE-2008-6090 | Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 2.29% | 6 February 2009 |
| CVE-2008-6089 | Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.11% | 6 February 2009 |
| CVE-2008-6088 | SQL injection vulnerability in the Joomtracker (com_joomtracker) 1.01 module for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tordetails action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.10% | 6 February 2009 |
| CVE-2008-6087 | Cross-site scripting (XSS) vulnerability in topic.php in Camera Life 2.6.2b4 allows remote attackers to inject arbitrary web script or HTML via the name parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.60% | 6 February 2009 |
| CVE-2008-6086 | SQL injection vulnerability in album.php in Camera Life 2.6.2b4 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3355. | EXPLOIT ✓HIGH 7.5EPSS 1.10% | 6 February 2009 |
| CVE-2008-6084 | Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file… | EXPLOIT ✓MEDIUM 6.8EPSS 2.23% | 6 February 2009 |
| CVE-2008-6083 | Directory traversal vulnerability in header.php in TXTshop beta 1.0 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.66% | 6 February 2009 |
| CVE-2008-6082 | Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO command. | EXPLOIT ✓MEDIUM 5.0EPSS 44.6% | 6 February 2009 |
| CVE-2008-6081 | SQL injection vulnerability in contact.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.10% | 6 February 2009 |
| CVE-2008-6080 | Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 10.6% | 6 February 2009 |
| CVE-2008-6078 | SQL injection vulnerability in open.php in the Private Messaging (com_privmsg) component for Limbo CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a pms action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 6 February 2009 |
| CVE-2008-6077 | SQL injection vulnerability in loudblog/ajax.php in LoudBlog 0.8.0a and earlier allows remote authenticated users to execute arbitrary SQL commands via the colpick parameter in a singleread action. | EXPLOIT ✓MEDIUM 6.5EPSS 0.86% | 6 February 2009 |
| CVE-2008-6076 | SQL injection vulnerability in the Daily Message (com_dailymessage) 1.0.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 6 February 2009 |
| CVE-2008-6075 | SQL injection vulnerability in aspkat.asp in Bahar Download Script 2.0 allows remote attackers to execute arbitrary SQL commands via the kid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 6 February 2009 |
| CVE-2008-6074 | Directory traversal vulnerability in frame.php in phpcrs 2.06 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 5.1EPSS 1.98% | 6 February 2009 |
| CVE-2008-6066 | Multiple PHP remote file inclusion vulnerabilities in Meet#Web 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) modules.php, (2) ManagerResource.class.php, (3) ManagerRightsResource.class.php, (4)… | EXPLOIT ×6 ✓HIGH 7.5EPSS 2.54% | 5 February 2009 |
| CVE-2008-6065 | Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that are aliased in a CREATE OR REPLACE DIRECTORY statement, which allows remote authenticated users with CREATE ANY DIRECTORY privileges to gain… | EXPLOIT ✓MEDIUM 5.1EPSS 2.20% | 5 February 2009 |
| CVE-2008-6064 | Multiple SQL injection vulnerabilities in DomPHP 0.81 allow remote attackers to execute arbitrary SQL commands via the cat parameter to agenda/index.php, and unspecified other vectors. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 5 February 2009 |
| CVE-2008-6061 | Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) controller files created by Techsmith Camtasia Studio before 5 allows remote attackers to inject arbitrary additional SWF content via a URL in the csPreloader… | EXPLOIT ✓MEDIUM 4.3EPSS 4.08% | 5 February 2009 |
| CVE-2008-6060 | Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by InfoSoft FusionCharts allows remote attackers to inject arbitrary additional SWF content via a URL in the SRC attribute of an IMG element in the… | EXPLOIT ✓MEDIUM 4.3EPSS 2.05% | 5 February 2009 |
| CVE-2009-0431 | SQL injection vulnerability in Default.asp in LinksPro Standard Edition allows remote attackers to execute arbitrary SQL commands via the OrderDirection parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.84% | 5 February 2009 |
| CVE-2009-0430 | Multiple cross-site scripting (XSS) vulnerabilities in Active Bids allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to search.asp and the (2) URL parameter to tellafriend.asp. | EXPLOIT ✓MEDIUM 4.3EPSS 1.19% | 5 February 2009 |
| CVE-2009-0429 | Multiple SQL injection vulnerabilities in Active Bids allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to search.asp, (2) SortDir parameter to auctionsended.asp, and the (3) catid parameter to wishlist.php. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 5 February 2009 |
| CVE-2009-0428 | SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Secure Document Library 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.19% | 5 February 2009 |
| CVE-2009-0427 | SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.19% | 5 February 2009 |
| CVE-2009-0426 | SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 5 February 2009 |
| CVE-2009-0425 | SQL injection vulnerability in index.php in Blue Eye CMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the clanek parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 5 February 2009 |
| CVE-2009-0423 | Directory traversal vulnerability in index.php in Php Photo Album (PHPPA) 0.8 BETA allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 6.06% | 5 February 2009 |
| CVE-2009-0422 | Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the… | EXPLOIT ✓HIGH 7.5EPSS 6.20% | 5 February 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.