2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-2262——PHP remote file inclusion vulnerability in install/di.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary...
CVE-2009-2261——PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .z...
CVE-2009-2260——stardict 3.0.1, when Enable Net Dict is configured, sends the contents of the clipboard to a dictionary server, which al...
CVE-2009-2259——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-2608. Reason: This candidate is a duplicate of...
CVE-2009-2258——Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmwar...
CVE-2009-2257——The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentic...
CVE-2009-2256——The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial o...
CVE-2009-2255——Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which a...
CVE-2009-2254——Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows ...
CVE-2009-2243——SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execu...
CVE-2009-2242——SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execu...
CVE-2009-2241——Cross-site scripting (XSS) vulnerability in search.asp in ASP Inline Corporate Calendar allows remote attackers to injec...
CVE-2009-2240——Cross-site scripting (XSS) vulnerability in AD2000 free-sw leger (aka Web Conference Room Free) 1.6.4 and earlier allows...
CVE-2009-2239——SQL injection vulnerability in the (1) casinobase (com_casinobase), (2) casino_blackjack (com_casino_blackjack), and (3)...
CVE-2009-2238——Unrestricted file upload vulnerability in includes/shared_scripts/wysiwyg_editor/assetmanager/assetmanager.asp in DMXRea...
CVE-2009-2237——Unspecified vulnerability in Views Bulk Operations 5.x-1.x before 5.x-1.4 and 6.x-1.x before 6.x-1.7, a module for Drupa...
CVE-2009-2236——SQL injection vulnerability in yad-admin/login.php in Your Article Directory allows remote attackers to execute arbitrar...
CVE-2009-2235——SQL injection vulnerability in page.php in Your Articles Directory allows remote attackers to execute arbitrary SQL comm...
CVE-2009-2234——Multiple SQL injection vulnerabilities in admin.php in VICIDIAL Call Center Suite 2.0.5-173 allow remote attackers to ex...
CVE-2009-2233——The admin interface in AWScripts.com Gallery Search Engine 1.5 allows remote attackers to bypass authentication and gain...
CVE-2009-2232——SQL injection vulnerability in image.php in Softbiz Banner Ad Management Script allows remote attackers to execute arbit...
CVE-2009-2231——MIDAS 1.43 allows remote attackers to bypass authentication and obtain administrative access via an admin account record...
CVE-2009-2230——SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authen...
CVE-2009-2229——Directory traversal vulnerability in engine.php in Kasseler CMS 1.3.5 lite allows remote attackers to read arbitrary fil...
CVE-2009-2228——Cross-site scripting (XSS) vulnerability in engine.php in Kasseler CMS allows remote attackers to inject arbitrary web s...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now