2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-2171 | — | — | 0.9% | Jun 23, 2009 | Mahara 1.1 before 1.1.5 does not apply permission checks when saving a view that contains artefacts, which allows remote... |
| CVE-2009-2170 | — | — | 0.9% | Jun 23, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0 before 1.0.12 and 1.1 before 1.1.5 allow remote attack... |
| CVE-2009-2169 | — | — | 4.5% | Jun 22, 2009 | Insecure method vulnerability in the PDFVIEWER.PDFViewerCtrl.1 ActiveX control (pdfviewer.ocx) in Edraw PDF Viewer Compo... |
| CVE-2009-2167 | — | — | 0.9% | Jun 22, 2009 | Multiple SQL injection vulnerabilities in cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier, when magic_quo... |
| CVE-2009-2166 | — | — | 3.2% | Jun 22, 2009 | Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to re... |
| CVE-2009-2165 | — | — | 1.4% | Jun 22, 2009 | SerendipityNZ (aka SimpleBoxes) Serene Bach 2.20R and earlier, and 3.00 beta023 and earlier 3.x versions, uses a predict... |
| CVE-2009-2164 | — | — | 1.0% | Jun 22, 2009 | Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote att... |
| CVE-2009-2163 | — | — | 3.0% | Jun 22, 2009 | Cross-site scripting (XSS) vulnerability in login/default.aspx in Sitecore CMS before 6.0.2 Update-1 090507 allows remot... |
| CVE-2009-2162 | — | — | 1.2% | Jun 22, 2009 | Cross-site scripting (XSS) vulnerability in the XOOPS MANIAC PukiWikiMod module 1.6.6.2 and earlier for XOOPS allows rem... |
| CVE-2009-2161 | — | — | 2.4% | Jun 22, 2009 | Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-inse... |
| CVE-2009-2160 | — | — | 3.2% | Jun 22, 2009 | TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpin... |
| CVE-2009-2159 | — | — | 2.7% | Jun 22, 2009 | backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote at... |
| CVE-2009-2157 | — | — | 1.7% | Jun 22, 2009 | Multiple SQL injection vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to execute arbitra... |
| CVE-2009-2156 | — | — | 1.5% | Jun 22, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to in... |
| CVE-2009-2155 | — | — | 1.9% | Jun 22, 2009 | Cross-site scripting (XSS) vulnerability in report/ReportViewAction.do in WebNMS Free Edition 5 allows remote attackers ... |
| CVE-2009-2154 | — | — | 0.9% | Jun 22, 2009 | SQL injection vulnerability in admin/login.php in Impleo Music Collection 2.0, when magic_quotes_gpc is disabled, allows... |
| CVE-2009-2153 | — | — | 1.3% | Jun 22, 2009 | Cross-site scripting (XSS) vulnerability in index.php in Impleo Music Collection 2.0 allows remote attackers to inject a... |
| CVE-2009-2152 | — | — | 0.9% | Jun 22, 2009 | SQL injection vulnerability in a_index.php in AdaptWeb 0.9.2 allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2009-2151 | — | — | 2.7% | Jun 22, 2009 | Directory traversal vulnerability in index.php in AdaptWeb 0.9.2 allows remote attackers to read arbitrary files via a .... |
| CVE-2009-2150 | — | — | 0.9% | Jun 22, 2009 | Multiple cross-site request forgery (CSRF) vulnerabilities in Campus Virtual-LMS allow (1) remote attackers to hijack th... |
| CVE-2009-2149 | — | — | 1.3% | Jun 22, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Campus Virtual-LMS allow remote attackers to inject arbitrary web... |
| CVE-2009-2148 | — | — | 1.0% | Jun 22, 2009 | SQL injection vulnerability in news/index.php in Campus Virtual-LMS allows remote attackers to execute arbitrary SQL com... |
| CVE-2009-2147 | — | — | 2.0% | Jun 22, 2009 | SQL injection vulnerability in fdown.php in phpWebThings 1.5.2 and earlier allows remote attackers to execute arbitrary ... |
| CVE-2009-2146 | — | — | 21.5% | Jun 22, 2009 | Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka... |
| CVE-2009-2145 | — | — | 1.6% | Jun 22, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in transLucid 1.75 allow remote attackers to inject arbitrary web sc... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now