2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-2262PHP remote file inclusion vulnerability in install/di.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary...
CVE-2009-2261PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .z...
CVE-2009-2260stardict 3.0.1, when Enable Net Dict is configured, sends the contents of the clipboard to a dictionary server, which al...
CVE-2009-2259Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-2608. Reason: This candidate is a duplicate of...
CVE-2009-2258Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmwar...
CVE-2009-2257The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentic...
CVE-2009-2256The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial o...
CVE-2009-2255Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which a...
CVE-2009-2254Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows ...
CVE-2009-2243SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execu...
CVE-2009-2242SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execu...
CVE-2009-2241Cross-site scripting (XSS) vulnerability in search.asp in ASP Inline Corporate Calendar allows remote attackers to injec...
CVE-2009-2240Cross-site scripting (XSS) vulnerability in AD2000 free-sw leger (aka Web Conference Room Free) 1.6.4 and earlier allows...
CVE-2009-2239SQL injection vulnerability in the (1) casinobase (com_casinobase), (2) casino_blackjack (com_casino_blackjack), and (3)...
CVE-2009-2238Unrestricted file upload vulnerability in includes/shared_scripts/wysiwyg_editor/assetmanager/assetmanager.asp in DMXRea...
CVE-2009-2237Unspecified vulnerability in Views Bulk Operations 5.x-1.x before 5.x-1.4 and 6.x-1.x before 6.x-1.7, a module for Drupa...
CVE-2009-2236SQL injection vulnerability in yad-admin/login.php in Your Article Directory allows remote attackers to execute arbitrar...
CVE-2009-2235SQL injection vulnerability in page.php in Your Articles Directory allows remote attackers to execute arbitrary SQL comm...
CVE-2009-2234Multiple SQL injection vulnerabilities in admin.php in VICIDIAL Call Center Suite 2.0.5-173 allow remote attackers to ex...
CVE-2009-2233The admin interface in AWScripts.com Gallery Search Engine 1.5 allows remote attackers to bypass authentication and gain...
CVE-2009-2232SQL injection vulnerability in image.php in Softbiz Banner Ad Management Script allows remote attackers to execute arbit...
CVE-2009-2231MIDAS 1.43 allows remote attackers to bypass authentication and obtain administrative access via an admin account record...
CVE-2009-2230SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authen...
CVE-2009-2229Directory traversal vulnerability in engine.php in Kasseler CMS 1.3.5 lite allows remote attackers to read arbitrary fil...
CVE-2009-2228Cross-site scripting (XSS) vulnerability in engine.php in Kasseler CMS allows remote attackers to inject arbitrary web s...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now