Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,149 CVEs1,726 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 255 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-0421 | SQL injection vulnerability in the Eventing (com_eventing) 1.6.x component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.04% | 5 February 2009 |
| CVE-2009-0420 | SQL injection vulnerability in the RD-Autos (com_rdautos) 1.5.5 Stable component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 5 February 2009 |
| CVE-2009-0388 | Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code via a large length value in a… | EXPLOIT ×2 ✓HIGH 10.0EPSS 13.3% | 4 February 2009 |
| CVE-2008-6057 | Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request. | EXPLOIT ✓MEDIUM 5.0EPSS 2.23% | 4 February 2009 |
| CVE-2008-6050 | SQL injection vulnerability in the Tech Articles (com_tech_article) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the item parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 4 February 2009 |
| CVE-2008-6049 | Rejected reason: SQL injection vulnerability in index.php in TinyMCE 2.0.1 allows remote attackers to execute arbitrary SQL commands via the menuID parameter. | EXPLOIT ✓UnscoredEPSS — | 4 February 2009 |
| CVE-2009-0410 | Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x, 7.0, 7.01, 7.02, 7.03, 7.03HP1a, and 8.0 allows remote attackers to execute arbitrary code via a long e-mail address in a malformed RCPT command, leading to… | EXPLOIT ✓HIGH 10.0EPSS 9.65% | 3 February 2009 |
| CVE-2009-0409 | SQL injection vulnerability in offline_auth.php in Max.Blog 1.0.6 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.10% | 3 February 2009 |
| CVE-2009-0407 | SQL injection vulnerability in admin/login.php in PHP-CMS Project 1 allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 3 February 2009 |
| CVE-2009-0406 | SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 3 February 2009 |
| CVE-2009-0405 | SQL injection vulnerability in articles.php in smartSite CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the var parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 3 February 2009 |
| CVE-2009-0403 | SQL injection vulnerability in admin/authenticate.php in Chipmunk Blogger Script allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 3 February 2009 |
| CVE-2009-0400 | SQL injection vulnerability in blog.php in SocialEngine 3.06 trial allows remote attackers to execute arbitrary SQL commands via the category_id parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.10% | 3 February 2009 |
| CVE-2009-0399 | Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.php. | EXPLOIT ✓HIGH 7.5EPSS 2.33% | 3 February 2009 |
| CVE-2009-0184 | Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute arbitrary code via (1) a long file name within a torrent file, (2) a long tracker URL in a… | EXPLOIT ×2 ✓HIGH 9.3EPSS 27.8% | 3 February 2009 |
| CVE-2009-0183 | Stack-based buffer overflow in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allows remote attackers to execute arbitrary code via a long Authorization header in an HTTP request. | EXPLOIT ×2 ✓HIGH 10.0EPSS 66.5% | 3 February 2009 |
| CVE-2008-6045 | Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTCsid parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.91% | 3 February 2009 |
| CVE-2008-6044 | Cross-site scripting (XSS) vulnerability in advanced_search_result.php in xt:Commerce 3.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.83% | 3 February 2009 |
| CVE-2008-6043 | Multiple SQL injection vulnerabilities in PHP Pro Bid (PPB) 6.04 allow remote attackers to execute arbitrary SQL commands via the (1) order_field and (2) order_type parameters to categories.php and unspecified other components. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 3 February 2009 |
| CVE-2008-6042 | SQL injection vulnerability in the re_search module in NetArtMedia Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the ad parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 3 February 2009 |
| CVE-2008-6039 | Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.06% | 3 February 2009 |
| CVE-2008-6038 | SQL injection vulnerability in index.php in MapCal 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an editevent action, possibly related to dsp_editevent.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 3 February 2009 |
| CVE-2008-6037 | SQL injection vulnerability in view.php in AvailScript Article Script allows remote attackers to execute arbitrary SQL commands via the v parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 3 February 2009 |
| CVE-2008-6036 | PHP remote file inclusion vulnerability in main.inc.php in BaseBuilder 2.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mj_config[src_path] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.47% | 3 February 2009 |
| CVE-2008-6034 | Cross-site scripting (XSS) vulnerability in dispatch.php in Achievo 1.3.2 allows remote attackers to inject arbitrary web script or HTML via the atkaction parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 3 February 2009 |
| CVE-2008-6033 | SQL injection vulnerability in comments.php in WSN Links 2.20 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 3 February 2009 |
| CVE-2008-6032 | SQL injection vulnerability in comments.php in WSN Links Free 4.0.34P allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 3 February 2009 |
| CVE-2008-6031 | SQL injection vulnerability in vote.php in WSN Links 2.22 and 2.23 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 3 February 2009 |
| CVE-2008-6030 | Multiple SQL injection vulnerabilities in NetArtMedia Jobs Portal 1.3 allow remote attackers to execute arbitrary SQL commands via (1) the job parameter to index.php in the search module or (2) the news_id parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 3 February 2009 |
| CVE-2008-6029 | SQL injection vulnerability in search.php in BuzzyWall 1.3.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.85% | 3 February 2009 |
| CVE-2008-6028 | SQL injection vulnerability in list.php in University of Queensland Library Fez 1.3 and 2.0 RC1 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter in a subject action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 3 February 2009 |
| CVE-2008-6026 | SQL injection vulnerability in tienda.php in BlueCUBE CMS allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 3 February 2009 |
| CVE-2008-6025 | Directory traversal vulnerability in scr/form.php in openElec 3.01 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.90% | 3 February 2009 |
| CVE-2009-0395 | SQL injection vulnerability in the login feature in NetArt Media Car Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 3 February 2009 |
| CVE-2009-0394 | SQL injection vulnerability in login.php in Pre Lecture Exercises (PLEs) CMS 1.0 beta 4.2 allows remote attackers to execute arbitrary SQL commands via the school parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 3 February 2009 |
| CVE-2009-0393 | Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to inject arbitrary web script or HTML via the page parameter. | EXPLOIT ✓LOW 3.5EPSS 1.24% | 3 February 2009 |
| CVE-2009-0392 | Directory traversal vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 2.34% | 3 February 2009 |
| CVE-2009-0390 | Argument injection vulnerability in Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows local users to send signals to arbitrary processes by populating the /tmp/enomalism2.pid file with command-line arguments for the kill… | EXPLOIT ✓HIGH 7.2EPSS 0.94% | 2 February 2009 |
| CVE-2009-0389 | Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attackers to (1) create and overwrite arbitrary files via the WriteIniFileString method, (2) execute arbitrary programs via the… | EXPLOIT ✓HIGH 9.3EPSS 8.79% | 2 February 2009 |
| CVE-2008-6023 | PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in a newer version of Xnova, possibly 0.8 sp1, allows remote attackers to execute arbitrary PHP code via a URL in the xnova_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.34% | 2 February 2009 |
| CVE-2008-6022 | PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in an older version of Xnova, possibly 0.8 sp1, allows remote attackers to execute arbitrary PHP code via a URL in the ugamela_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.34% | 2 February 2009 |
| CVE-2008-6019 | SQL injection vulnerability in index.php in EACOMM DO-CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the p parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 2 February 2009 |
| CVE-2008-6018 | Directory traversal vulnerability in index.php in MyPHPSite, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 4.08% | 2 February 2009 |
| CVE-2008-6017 | SQL injection vulnerability in messages.php in I-Rater Basic allows remote attackers to execute arbitrary SQL commands via the idp parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 2 February 2009 |
| CVE-2009-0384 | SQL injection vulnerability in autor.php in OwnRS CMS 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.87% | 2 February 2009 |
| CVE-2009-0383 | delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog posts via a direct request. | EXPLOIT ✓MEDIUM 6.4EPSS 2.96% | 2 February 2009 |
| CVE-2009-0381 | SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a products action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 2 February 2009 |
| CVE-2009-0380 | SQL injection vulnerability in the Sigsiu Online Business Index 2 (SOBI2, com_sobi2) RC 2.8.2 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the bid parameter in a showbiz action to index.php, a different… | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 2 February 2009 |
| CVE-2009-0379 | SQL injection vulnerability in the Prince Clan Chess Club (com_pcchess) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the game_id parameter in a showgame action to index.php, a different vector than CVE-2008-0761. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 2 February 2009 |
| CVE-2009-0378 | Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the pet parameter in a sign action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 2 February 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.