2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-2262 | — | — | 1.2% | Jun 30, 2009 | PHP remote file inclusion vulnerability in install/di.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary... |
| CVE-2009-2261 | — | — | 41.4% | Jun 30, 2009 | PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .z... |
| CVE-2009-2260 | — | — | 2.1% | Jun 30, 2009 | stardict 3.0.1, when Enable Net Dict is configured, sends the contents of the clipboard to a dictionary server, which al... |
| CVE-2009-2259 | — | — | — | Jun 30, 2009 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-2608. Reason: This candidate is a duplicate of... |
| CVE-2009-2258 | — | — | 6.7% | Jun 30, 2009 | Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmwar... |
| CVE-2009-2257 | — | — | 7.2% | Jun 30, 2009 | The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentic... |
| CVE-2009-2256 | — | — | 7.4% | Jun 30, 2009 | The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial o... |
| CVE-2009-2255 | — | — | 31.0% | Jun 30, 2009 | Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which a... |
| CVE-2009-2254 | — | — | 10.9% | Jun 30, 2009 | Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows ... |
| CVE-2009-2243 | — | — | 0.9% | Jun 27, 2009 | SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execu... |
| CVE-2009-2242 | — | — | 0.9% | Jun 27, 2009 | SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execu... |
| CVE-2009-2241 | — | — | 1.5% | Jun 27, 2009 | Cross-site scripting (XSS) vulnerability in search.asp in ASP Inline Corporate Calendar allows remote attackers to injec... |
| CVE-2009-2240 | — | — | 1.1% | Jun 27, 2009 | Cross-site scripting (XSS) vulnerability in AD2000 free-sw leger (aka Web Conference Room Free) 1.6.4 and earlier allows... |
| CVE-2009-2239 | — | — | 1.0% | Jun 27, 2009 | SQL injection vulnerability in the (1) casinobase (com_casinobase), (2) casino_blackjack (com_casino_blackjack), and (3)... |
| CVE-2009-2238 | — | — | 3.5% | Jun 27, 2009 | Unrestricted file upload vulnerability in includes/shared_scripts/wysiwyg_editor/assetmanager/assetmanager.asp in DMXRea... |
| CVE-2009-2237 | — | — | 2.2% | Jun 27, 2009 | Unspecified vulnerability in Views Bulk Operations 5.x-1.x before 5.x-1.4 and 6.x-1.x before 6.x-1.7, a module for Drupa... |
| CVE-2009-2236 | — | — | 1.0% | Jun 27, 2009 | SQL injection vulnerability in yad-admin/login.php in Your Article Directory allows remote attackers to execute arbitrar... |
| CVE-2009-2235 | — | — | 1.0% | Jun 27, 2009 | SQL injection vulnerability in page.php in Your Articles Directory allows remote attackers to execute arbitrary SQL comm... |
| CVE-2009-2234 | — | — | 1.0% | Jun 27, 2009 | Multiple SQL injection vulnerabilities in admin.php in VICIDIAL Call Center Suite 2.0.5-173 allow remote attackers to ex... |
| CVE-2009-2233 | — | — | 2.6% | Jun 26, 2009 | The admin interface in AWScripts.com Gallery Search Engine 1.5 allows remote attackers to bypass authentication and gain... |
| CVE-2009-2232 | — | — | 1.1% | Jun 26, 2009 | SQL injection vulnerability in image.php in Softbiz Banner Ad Management Script allows remote attackers to execute arbit... |
| CVE-2009-2231 | — | — | 2.6% | Jun 26, 2009 | MIDAS 1.43 allows remote attackers to bypass authentication and obtain administrative access via an admin account record... |
| CVE-2009-2230 | — | — | 1.2% | Jun 26, 2009 | SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authen... |
| CVE-2009-2229 | — | — | 3.5% | Jun 26, 2009 | Directory traversal vulnerability in engine.php in Kasseler CMS 1.3.5 lite allows remote attackers to read arbitrary fil... |
| CVE-2009-2228 | — | — | 1.4% | Jun 26, 2009 | Cross-site scripting (XSS) vulnerability in engine.php in Kasseler CMS allows remote attackers to inject arbitrary web s... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now