Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,401 CVEs1,726 in CISA KEV17,261 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 259 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2009-0134 | Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers to create and overwrite arbitrary files via the (1) DoSaveFile or (2) DoSaveHtmlFile method. | EXPLOIT ✓HIGH 9.3EPSS 8.86% | 16 January 2009 |
| CVE-2009-0133 | Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564. | EXPLOIT ×7 ✓HIGH 10.0EPSS 67.0% | 15 January 2009 |
| CVE-2008-5904 | The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading to a buffer overflow. | EXPLOIT ✓HIGH 7.5EPSS 7.35% | 15 January 2009 |
| CVE-2009-0121 | SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 allows remote attackers to execute arbitrary SQL commands via the password parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.89% | 15 January 2009 |
| CVE-2009-0120 | The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by sending data over an established SSL connection, as demonstrated by the abc\r\n\r\n string data. | EXPLOIT ✓HIGH 7.8EPSS 3.55% | 15 January 2009 |
| CVE-2003-1566 | Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection. | EXPLOIT ✓MEDIUM 5.0EPSS 28.1% | 15 January 2009 |
| CVE-2009-0119 | Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .chm file. | EXPLOIT ✓HIGH 10.0EPSS 36.7% | 14 January 2009 |
| CVE-2008-5457 | Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity,… | EXPLOIT ×2 ✓HIGH 10.0EPSS 61.3% | 14 January 2009 |
| CVE-2008-5444 | Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2008-5448 and… | EXPLOIT ✓HIGH 10.0EPSS 60.6% | 14 January 2009 |
| CVE-2008-3979 | Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. | EXPLOIT ✓MEDIUM 5.5EPSS 32.4% | 14 January 2009 |
| CVE-2008-5517 | The web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related to (1) git_snapshot and (2) git_object. | EXPLOITHIGH 7.5EPSS 11.9% | 13 January 2009 |
| CVE-2008-5901 | iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a direct request for db/iyziforum.mdb. | EXPLOIT ✓HIGH 7.5EPSS 2.42% | 12 January 2009 |
| CVE-2008-5900 | CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CAArticles.mdb. | EXPLOIT ✓HIGH 7.5EPSS 6.36% | 12 January 2009 |
| CVE-2008-5899 | CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CAFFAPage.mdb. | EXPLOIT ✓HIGH 7.5EPSS 6.36% | 12 January 2009 |
| CVE-2008-5898 | CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CADirectory.mdb. | EXPLOIT ✓HIGH 7.5EPSS 6.36% | 12 January 2009 |
| CVE-2008-5897 | CodeAvalanche FreeWallpaper stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for… | EXPLOIT ✓HIGH 7.5EPSS 6.36% | 12 January 2009 |
| CVE-2008-5896 | CodeAvalanche RateMySite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for… | EXPLOIT ✓HIGH 7.5EPSS 2.44% | 12 January 2009 |
| CVE-2008-5895 | SQL injection vulnerability in connection.php in Mediatheka 4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 12 January 2009 |
| CVE-2008-5894 | Directory traversal vulnerability in index.php in Mediatheka 4.2 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.92% | 12 January 2009 |
| CVE-2008-5893 | Cross-site scripting (XSS) vulnerability in admin_dblayers.asp in ClickAndEmail allows remote attackers to inject arbitrary web script or HTML via the tablename parameter in an update action. | EXPLOIT ✓LOW 2.6EPSS 1.58% | 12 January 2009 |
| CVE-2008-5892 | Multiple SQL injection vulnerabilities in ClickAndEmail allow remote attackers to execute arbitrary SQL commands via (1) the ID parameter to admin_dblayers.asp in an update action, (2) the adminid parameter to admin_loginCheck.asp (aka the USERNAME… | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 12 January 2009 |
| CVE-2008-5891 | Cross-site scripting (XSS) vulnerability in the profile editing functionality in Injader before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 12 January 2009 |
| CVE-2008-5890 | SQL injection vulnerability in feeds.php in Injader before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.03% | 12 January 2009 |
| CVE-2008-5889 | Cross-site scripting (XSS) vulnerability in user.asp in Click&Rank allows remote attackers to inject arbitrary web script or HTML via the action parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.22% | 12 January 2009 |
| CVE-2008-5888 | Multiple SQL injection vulnerabilities in Click&Rank allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) hitcounter.asp, (2) user_delete.asp, and (3) user_update.asp; (4) the userid parameter to admin_login.asp (aka the… | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 12 January 2009 |
| CVE-2008-5886 | TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a direct request for _private/discussion.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.59% | 12 January 2009 |
| CVE-2008-5885 | The Net Guys ASPired2Quote stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for admin/quote.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 6.28% | 12 January 2009 |
| CVE-2008-5884 | AyeView 2.20 allows user-assisted attackers to cause a denial of service (application crash) via a GIF file with a malformed header. | EXPLOIT ✓MEDIUM 4.3EPSS 2.12% | 12 January 2009 |
| CVE-2008-5883 | Absolute path traversal vulnerability in front-end/dir.php in mini-pub 0.3 and earlier allows remote attackers to list arbitrary directories via a full pathname in the sDir parameter. | EXPLOIT ✓HIGH 7.8EPSS 2.58% | 12 January 2009 |
| CVE-2009-0113 | Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! | EXPLOIT ✓MEDIUM 5.0EPSS 6.58% | 9 January 2009 |
| CVE-2009-0111 | SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 9 January 2009 |
| CVE-2009-0110 | SQL injection vulnerability in read.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 9 January 2009 |
| CVE-2009-0109 | SQL injection vulnerability in index.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 9 January 2009 |
| CVE-2009-0108 | PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via modified (1) PHPAUCTION_RM_ID, (2) PHPAUCTION_RM_NAME, (3) PHPAUCTION_RM_USERNAME, and (4) PHPAUCTION_RM_EMAIL cookies. | EXPLOIT ✓HIGH 7.5EPSS 2.55% | 9 January 2009 |
| CVE-2009-0107 | Cross-site scripting (XSS) vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to inject arbitrary web script or HTML via the user_id parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 9 January 2009 |
| CVE-2009-0106 | SQL injection vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the user_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 9 January 2009 |
| CVE-2009-0105 | Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web script or HTML via the mdfd parameter in a prog action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 9 January 2009 |
| CVE-2009-0104 | SQL injection vulnerability in index.php in EZpack 4.2b2 allows remote attackers to execute arbitrary SQL commands via the qType parameter in a webboard prog action. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 9 January 2009 |
| CVE-2009-0103 | Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) apps_path[plug] parameter to plugin/gateway/gnokii/init.php, the (2) apps_path[themes] parameter to… | EXPLOIT ✓HIGH 7.5EPSS 10.1% | 9 January 2009 |
| CVE-2008-5881 | Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) gateway_module parameter to plugin/gateway/gnokii/init.php and the (2)… | EXPLOIT ✓HIGH 7.5EPSS 7.27% | 9 January 2009 |
| CVE-2009-0071 | Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a (1)… | EXPLOIT ✓LOW 2.6EPSS 6.59% | 8 January 2009 |
| CVE-2009-0070 | Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (application crash), and probably have unspecified other impact via the array index of the arguments array in… | EXPLOIT ✓HIGH 9.3EPSS 2.86% | 8 January 2009 |
| CVE-2009-0043 | The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, which allows remote attackers to execute arbitrary commands via unspecified vectors. | EXPLOIT ✓HIGH 10.0EPSS 53.3% | 8 January 2009 |
| CVE-2008-5880 | admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "ok". | EXPLOIT ✓HIGH 7.5EPSS 2.51% | 8 January 2009 |
| CVE-2008-5879 | Cross-site scripting (XSS) vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, allows remote attackers to inject arbitrary web script or HTML via the page parameter and other unspecified vectors. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 8 January 2009 |
| CVE-2008-5878 | Multiple directory traversal vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to include and execute arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.1EPSS 1.92% | 8 January 2009 |
| CVE-2008-5877 | Multiple SQL injection vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) form_id parameter… | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 8 January 2009 |
| CVE-2008-5875 | SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php. | EXPLOIT ×3 ✓HIGH 7.5EPSS 0.97% | 8 January 2009 |
| CVE-2008-5874 | Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php in the (1) com_allhotels or (2)… | EXPLOIT ×3 ✓HIGH 7.5EPSS 0.97% | 8 January 2009 |
| CVE-2008-0067 | Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) long string parameters to the OpenView5.exe CGI program; (2) a long string parameter to the… | EXPLOIT ✓HIGH 10.0EPSS 63.4% | 8 January 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.