2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-2343Cross-site scripting (XSS) vulnerability in people.php in Zoph before 0.7.0.6 allows remote attackers to inject arbitrar...
CVE-2009-2342Cross-site scripting (XSS) vulnerability in admin.php (aka the login page) in Content Management Made Easy (CMME) before...
CVE-2009-2341SQL injection vulnerability in albumdetail.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2009-2340SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2009-2339SQL injection vulnerability in index.php in Rentventory allows remote attackers to execute arbitrary SQL commands via th...
CVE-2009-2338Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is...
CVE-2009-2337SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when mag...
CVE-2009-2333Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execut...
CVE-2009-2332CMS Chainuk 1.2 and earlier allows remote attackers to obtain sensitive information via (1) a crafted id parameter to in...
CVE-2009-2331Multiple static code injection vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to inject arbitrary...
CVE-2009-2330Cross-site scripting (XSS) vulnerability in admin/admin_menu.php in CMS Chainuk 1.2 and earlier allows remote attackers ...
CVE-2009-2329KerviNet Forum 1.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) admin...
CVE-2009-2328admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remot...
CVE-2009-2327Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated...
CVE-2009-2326Multiple SQL injection vulnerabilities in KerviNet Forum 1.1 and earlier allow remote attackers to execute arbitrary SQL...
CVE-2009-2325Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a...
CVE-2009-2324Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitra...
CVE-2009-2323The web interface on the Axesstel MV 410R redirects users back to the referring page after execution of some CGI scripts...
CVE-2009-2322Cross-site scripting (XSS) vulnerability in cgi-bin/sysconf.cgi on the Axesstel MV 410R allows remote attackers to injec...
CVE-2009-2321cgi-bin/sysconf.cgi on the Axesstel MV 410R allows remote attackers to cause a denial of service (configuration reset) v...
CVE-2009-2320The web interface on the Axesstel MV 410R relies on client-side JavaScript code to validate input, which allows remote a...
CVE-2009-2319The default configuration of the Wi-Fi component on the Axesstel MV 410R does not use encryption, which makes it easier ...
CVE-2009-2318The Axesstel MV 410R allows remote attackers to cause a denial of service via a flood of SYN packets, a related issue to...
CVE-2009-2317The Axesstel MV 410R has a certain default administrator password, and does not force a password change, which makes it ...
CVE-2009-2316Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0 allow remote attackers to ...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now