SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,401 CVEs1,726 in CISA KEV17,261 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 259 of 501

CVESummaryPriorityPublished
CVE-2009-0134Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers to create and overwrite arbitrary files via the (1) DoSaveFile or (2) DoSaveHtmlFile method.EXPLOIT ✓HIGH 9.3EPSS 8.86%16 January 2009
CVE-2009-0133Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564.EXPLOIT ×7 ✓HIGH 10.0EPSS 67.0%15 January 2009
CVE-2008-5904The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading to a buffer overflow.EXPLOIT ✓HIGH 7.5EPSS 7.35%15 January 2009
CVE-2009-0121SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 allows remote attackers to execute arbitrary SQL commands via the password parameter.EXPLOIT ✓HIGH 7.5EPSS 0.89%15 January 2009
CVE-2009-0120The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by sending data over an established SSL connection, as demonstrated by the abc\r\n\r\n string data.EXPLOIT ✓HIGH 7.8EPSS 3.55%15 January 2009
CVE-2003-1566Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection.EXPLOIT ✓MEDIUM 5.0EPSS 28.1%15 January 2009
CVE-2009-0119Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .chm file.EXPLOIT ✓HIGH 10.0EPSS 36.7%14 January 2009
CVE-2008-5457Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity,…EXPLOIT ×2 ✓HIGH 10.0EPSS 61.3%14 January 2009
CVE-2008-5444Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2008-5448 and…EXPLOIT ✓HIGH 10.0EPSS 60.6%14 January 2009
CVE-2008-3979Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.EXPLOIT ✓MEDIUM 5.5EPSS 32.4%14 January 2009
CVE-2008-5517The web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related to (1) git_snapshot and (2) git_object.EXPLOITHIGH 7.5EPSS 11.9%13 January 2009
CVE-2008-5901iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a direct request for db/iyziforum.mdb.EXPLOIT ✓HIGH 7.5EPSS 2.42%12 January 2009
CVE-2008-5900CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CAArticles.mdb.EXPLOIT ✓HIGH 7.5EPSS 6.36%12 January 2009
CVE-2008-5899CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CAFFAPage.mdb.EXPLOIT ✓HIGH 7.5EPSS 6.36%12 January 2009
CVE-2008-5898CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CADirectory.mdb.EXPLOIT ✓HIGH 7.5EPSS 6.36%12 January 2009
CVE-2008-5897CodeAvalanche FreeWallpaper stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for…EXPLOIT ✓HIGH 7.5EPSS 6.36%12 January 2009
CVE-2008-5896CodeAvalanche RateMySite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for…EXPLOIT ✓HIGH 7.5EPSS 2.44%12 January 2009
CVE-2008-5895SQL injection vulnerability in connection.php in Mediatheka 4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%12 January 2009
CVE-2008-5894Directory traversal vulnerability in index.php in Mediatheka 4.2 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.92%12 January 2009
CVE-2008-5893Cross-site scripting (XSS) vulnerability in admin_dblayers.asp in ClickAndEmail allows remote attackers to inject arbitrary web script or HTML via the tablename parameter in an update action.EXPLOIT ✓LOW 2.6EPSS 1.58%12 January 2009
CVE-2008-5892Multiple SQL injection vulnerabilities in ClickAndEmail allow remote attackers to execute arbitrary SQL commands via (1) the ID parameter to admin_dblayers.asp in an update action, (2) the adminid parameter to admin_loginCheck.asp (aka the USERNAME…EXPLOIT ✓HIGH 7.5EPSS 0.97%12 January 2009
CVE-2008-5891Cross-site scripting (XSS) vulnerability in the profile editing functionality in Injader before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%12 January 2009
CVE-2008-5890SQL injection vulnerability in feeds.php in Injader before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.03%12 January 2009
CVE-2008-5889Cross-site scripting (XSS) vulnerability in user.asp in Click&Rank allows remote attackers to inject arbitrary web script or HTML via the action parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.22%12 January 2009
CVE-2008-5888Multiple SQL injection vulnerabilities in Click&Rank allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) hitcounter.asp, (2) user_delete.asp, and (3) user_update.asp; (4) the userid parameter to admin_login.asp (aka the…EXPLOIT ✓HIGH 7.5EPSS 0.97%12 January 2009
CVE-2008-5886TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a direct request for _private/discussion.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.59%12 January 2009
CVE-2008-5885The Net Guys ASPired2Quote stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for admin/quote.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 6.28%12 January 2009
CVE-2008-5884AyeView 2.20 allows user-assisted attackers to cause a denial of service (application crash) via a GIF file with a malformed header.EXPLOIT ✓MEDIUM 4.3EPSS 2.12%12 January 2009
CVE-2008-5883Absolute path traversal vulnerability in front-end/dir.php in mini-pub 0.3 and earlier allows remote attackers to list arbitrary directories via a full pathname in the sDir parameter.EXPLOIT ✓HIGH 7.8EPSS 2.58%12 January 2009
CVE-2009-0113Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla!EXPLOIT ✓MEDIUM 5.0EPSS 6.58%9 January 2009
CVE-2009-0111SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%9 January 2009
CVE-2009-0110SQL injection vulnerability in read.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%9 January 2009
CVE-2009-0109SQL injection vulnerability in index.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%9 January 2009
CVE-2009-0108PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via modified (1) PHPAUCTION_RM_ID, (2) PHPAUCTION_RM_NAME, (3) PHPAUCTION_RM_USERNAME, and (4) PHPAUCTION_RM_EMAIL cookies.EXPLOIT ✓HIGH 7.5EPSS 2.55%9 January 2009
CVE-2009-0107Cross-site scripting (XSS) vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.48%9 January 2009
CVE-2009-0106SQL injection vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the user_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.02%9 January 2009
CVE-2009-0105Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web script or HTML via the mdfd parameter in a prog action.EXPLOIT ✓MEDIUM 4.3EPSS 1.47%9 January 2009
CVE-2009-0104SQL injection vulnerability in index.php in EZpack 4.2b2 allows remote attackers to execute arbitrary SQL commands via the qType parameter in a webboard prog action.EXPLOIT ✓HIGH 7.5EPSS 0.99%9 January 2009
CVE-2009-0103Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) apps_path[plug] parameter to plugin/gateway/gnokii/init.php, the (2) apps_path[themes] parameter to…EXPLOIT ✓HIGH 7.5EPSS 10.1%9 January 2009
CVE-2008-5881Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) gateway_module parameter to plugin/gateway/gnokii/init.php and the (2)…EXPLOIT ✓HIGH 7.5EPSS 7.27%9 January 2009
CVE-2009-0071Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a (1)…EXPLOIT ✓LOW 2.6EPSS 6.59%8 January 2009
CVE-2009-0070Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (application crash), and probably have unspecified other impact via the array index of the arguments array in…EXPLOIT ✓HIGH 9.3EPSS 2.86%8 January 2009
CVE-2009-0043The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, which allows remote attackers to execute arbitrary commands via unspecified vectors.EXPLOIT ✓HIGH 10.0EPSS 53.3%8 January 2009
CVE-2008-5880admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "ok".EXPLOIT ✓HIGH 7.5EPSS 2.51%8 January 2009
CVE-2008-5879Cross-site scripting (XSS) vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, allows remote attackers to inject arbitrary web script or HTML via the page parameter and other unspecified vectors.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%8 January 2009
CVE-2008-5878Multiple directory traversal vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to include and execute arbitrary files via a ..EXPLOIT ✓MEDIUM 5.1EPSS 1.92%8 January 2009
CVE-2008-5877Multiple SQL injection vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) form_id parameter…EXPLOIT ✓MEDIUM 6.8EPSS 0.91%8 January 2009
CVE-2008-5875SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php.EXPLOIT ×3 ✓HIGH 7.5EPSS 0.97%8 January 2009
CVE-2008-5874Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php in the (1) com_allhotels or (2)…EXPLOIT ×3 ✓HIGH 7.5EPSS 0.97%8 January 2009
CVE-2008-0067Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) long string parameters to the OpenView5.exe CGI program; (2) a long string parameter to the…EXPLOIT ✓HIGH 10.0EPSS 63.4%8 January 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.