Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,401 CVEs1,726 in CISA KEV17,261 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 258 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-5957 | SQL injection vulnerability in the Mydyngallery (com_mydyngallery) component 1.4.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the directory parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 23 January 2009 |
| CVE-2008-5956 | Wbstreet (aka PHPSTREET Webboard) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request to connect.inc. | EXPLOIT ✓MEDIUM 5.0EPSS 3.14% | 23 January 2009 |
| CVE-2008-5955 | SQL injection vulnerability in show.php in Wbstreet (aka PHPSTREET Webboard) 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97% | 23 January 2009 |
| CVE-2008-5954 | SQL injection vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lname parameter in a login action to an unspecified component. | EXPLOIT ✓MEDIUM 6.8EPSS 0.87% | 23 January 2009 |
| CVE-2008-5953 | Directory traversal vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.42% | 23 January 2009 |
| CVE-2008-5952 | SQL injection vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the tid parameter in a vtech action to the default URI. | EXPLOIT ✓MEDIUM 6.0EPSS 0.83% | 23 January 2009 |
| CVE-2008-5951 | ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for workDB/templatemonster.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.23% | 23 January 2009 |
| CVE-2008-5950 | SQL injection vulnerability in media/media_level.asp in ASP Template Creature allows remote attackers to execute arbitrary SQL commands via the mcatid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 23 January 2009 |
| CVE-2008-5949 | Multiple PHP remote file inclusion vulnerabilities in ccTiddly 1.7.4 and 1.7.6 allow remote attackers to execute arbitrary PHP code via a URL in the cct_base parameter to (1) index.php; (2) handle/proxy.php; (3) header.php, (4) include.php, and (5)… | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.57% | 23 January 2009 |
| CVE-2008-5948 | Directory traversal vulnerability in index.php in BNCwi 1.04 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.30% | 23 January 2009 |
| CVE-2009-0259 | The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as… | EXPLOIT ✓HIGH 9.3EPSS 7.50% | 22 January 2009 |
| CVE-2009-0253 | Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Status Bar Obfuscation" and "Clickjacking" attack. | EXPLOIT ✓MEDIUM 6.8EPSS 2.53% | 22 January 2009 |
| CVE-2009-0252 | Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands via the (1) Login parameter (aka username field) or the (2) Password parameter (aka password field). | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 22 January 2009 |
| CVE-2009-0251 | Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/footer via the footer parameter. | EXPLOIT ✓MEDIUM 6.5EPSS 5.56% | 22 January 2009 |
| CVE-2009-0250 | Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the file containing the administrator's password hash via a direct request for config/password. | EXPLOIT ✓MEDIUM 5.0EPSS 6.28% | 22 January 2009 |
| CVE-2009-0249 | Katy Whitton RankEm stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for database/topsites.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.29% | 22 January 2009 |
| CVE-2009-0248 | Cross-site scripting (XSS) vulnerability in rankup.asp in Katy Whitton RankEm allows remote attackers to inject arbitrary web script or HTML via the siteID parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 22 January 2009 |
| CVE-2008-5947 | PHP remote file inclusion vulnerability in include/class_yapbbcooker.php in YapBB 1.2.Beta 2 allows remote attackers to execute arbitrary PHP code via a URL in the cfgIncludeDirectory parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.83% | 22 January 2009 |
| CVE-2008-5946 | SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 22 January 2009 |
| CVE-2008-5945 | Nukeviet 2.0 Beta allows remote attackers to bypass authentication and gain administrative access by setting the admf cookie to 1. | EXPLOIT ✓HIGH 7.5EPSS 2.34% | 22 January 2009 |
| CVE-2008-5944 | Cross-site scripting (XSS) vulnerability in modules.php in NavBoard 16 (2.6.0) allows remote attackers to inject arbitrary web script or HTML via the module parameter. | EXPLOIT ✓LOW 2.6EPSS 1.50% | 22 January 2009 |
| CVE-2008-5943 | Multiple directory traversal vulnerabilities in NavBoard 16 (2.6.0) allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.56% | 22 January 2009 |
| CVE-2008-5939 | Cross-site scripting (XSS) vulnerability in index.php in MODx CMS 0.9.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in the username field, possibly related to snippet.ditto.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.71% | 22 January 2009 |
| CVE-2008-5938 | PHP remote file inclusion vulnerability in assets/snippets/reflect/snippet.reflect.php in MODx CMS 0.9.6.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the reflect_base parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.39% | 22 January 2009 |
| CVE-2008-5937 | AyeView 2.20 allows user-assisted attackers to cause a denial of service (memory consumption or application crash) via a bitmap (aka .bmp) file with large height and width values. | EXPLOIT ✓HIGH 7.8EPSS 2.74% | 22 January 2009 |
| CVE-2008-5936 | front-end/edit.php in mini-pub 0.3 and earlier allows remote attackers to read files and obtain PHP source code via a filename in the sFileName parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.44% | 22 January 2009 |
| CVE-2009-0026 | Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 26.8% | 21 January 2009 |
| CVE-2008-5934 | SQL injection vulnerability in index.php in CMS ISWEB 3.0 allows remote attackers to execute arbitrary SQL commands via the id_sezione parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 21 January 2009 |
| CVE-2008-5933 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in CMS ISWEB 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the strcerca parameter (aka the input field for the cerca action) or (2) the id_oggetto parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.52% | 21 January 2009 |
| CVE-2008-5932 | CodeAvalanche FreeForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for _private/CAForum.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 6.20% | 21 January 2009 |
| CVE-2008-5931 | The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for admin/blog.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.62% | 21 January 2009 |
| CVE-2008-5930 | SQL injection vulnerability in admin/blog_comments.asp in The Net Guys ASPired2Blog allows remote attackers to execute arbitrary SQL commands via the BlogID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 21 January 2009 |
| CVE-2008-5929 | VP-ASP Shopping Cart 6.50 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database containing the password via a direct request for database/shopping650.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.59% | 21 January 2009 |
| CVE-2008-5928 | SQL injection vulnerability in redir.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 21 January 2009 |
| CVE-2008-5927 | Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPNews 0.0.6 allow remote attackers to execute arbitrary SQL commands via the (1) checkuser parameter (aka username field) or (2) checkpass parameter (aka password field) to… | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 21 January 2009 |
| CVE-2008-5926 | Multiple SQL injection vulnerabilities in login.asp in ASP-DEv Internal E-Mail System allow remote attackers to execute arbitrary SQL commands via the (1) login parameter (aka user field) or the (2) password parameter (aka pass field). | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 21 January 2009 |
| CVE-2008-5923 | SQL injection vulnerability in default.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL commands the cat parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 21 January 2009 |
| CVE-2008-5922 | Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Cant Find A Gaming CMS (CFAGCMS) 1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) main and (2) right parameters. | EXPLOIT ✓HIGH 7.5EPSS 2.47% | 21 January 2009 |
| CVE-2008-5921 | SQL injection vulnerability in albums.php in Umer Inc Songs Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 21 January 2009 |
| CVE-2009-0241 | Stack-based buffer overflow in the process_path function in gmetad/server.c in Ganglia 3.1.1 allows remote attackers to cause a denial of service (crash) via a request to the gmetad service with a long pathname. | EXPLOIT ✓HIGH 7.5EPSS 5.35% | 21 January 2009 |
| CVE-2008-5920 | The create_anchors function in utils.inc in WebSVN 1.x allows remote attackers to execute arbitrary PHP code via a crafted username that is processed by the preg_replace function with the eval switch. | EXPLOIT ✓HIGH 7.5EPSS 2.99% | 21 January 2009 |
| CVE-2008-5919 | Directory traversal vulnerability in rss.php in WebSVN 2.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to overwrite arbitrary files via directory traversal sequences in the rev parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 6.31% | 21 January 2009 |
| CVE-2008-5918 | Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php in WebSVN 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | EXPLOIT ✓MEDIUM 4.3EPSS 4.46% | 21 January 2009 |
| CVE-2009-0182 | Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in a File line in a .pls file, as demonstrated by an http URL on a File1 line. | EXPLOIT ×2 ✓HIGH 8.8EPSS 48.4% | 20 January 2009 |
| CVE-2008-4388 | The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly validate downloaded files, which allows remote attackers to execute arbitrary code via the installAppMgr method and… | EXPLOIT ✓HIGH 9.3EPSS 37.7% | 20 January 2009 |
| CVE-2009-0177 | vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6.5.1 build 126130, 6.5.1 and earlier; VMware Player 2.5.1 build 126130, 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 2.0.x before 2.0.1… | EXPLOIT ✓MEDIUM 5.0EPSS 8.64% | 20 January 2009 |
| CVE-2009-0175 | Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in an invalid .mp3 file. | EXPLOIT ✓HIGH 9.3EPSS 5.55% | 20 January 2009 |
| CVE-2009-0174 | Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in the HREF attribute of a REF element in a .asx file. | EXPLOIT ×4 ✓HIGH 9.3EPSS 11.7% | 20 January 2009 |
| CVE-2009-0172 | Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream. | EXPLOIT ✓MEDIUM 5.0EPSS 8.47% | 16 January 2009 |
| CVE-2008-3821 | Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 11.0 through 12.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the ping program or (2) unspecified other aspects of the URI. | EXPLOIT ✓MEDIUM 4.3EPSS 5.45% | 16 January 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.