2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-4592Unspecified vulnerability in base_local_rules.php in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remot...
CVE-2009-4591SQL injection vulnerability in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attackers to execute...
CVE-2009-4590Cross-site scripting (XSS) vulnerability in base_local_rules.php in Basic Analysis and Security Engine (BASE) before 1.4...
CVE-2009-4589Cross-site scripting (XSS) vulnerability in the Special:Block implementation in the getContribsLink function in SpecialB...
CVE-2009-4588Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlie...
CVE-2009-4587Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved wor...
CVE-2009-4586Multiple cross-site scripting (XSS) vulnerabilities in index.html in Wowd client before 1.3.1 allow remote attackers to ...
CVE-2009-4585UranyumSoft Listing Service stores sensitive information under the web root with insufficient access control, which allo...
CVE-2009-4584admin.php in dB Masters Multimedia Links Directory 3.1.3 allows remote attackers to bypass authentication and gain admin...
CVE-2009-4583SQL injection vulnerability in the DhForum (com_dhforum) component for Joomla! allows remote attackers to execute arbitr...
CVE-2009-4582SQL injection vulnerability in detail.php in the Dictionary module for XOOPS 2.0.18 allows remote attackers to execute a...
CVE-2009-4581CRITICAL9.8Directory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is dis...
CVE-2009-4580Multiple cross-site scripting (XSS) vulnerabilities in Hasta Blog 2.3 allow remote attackers to inject arbitrary web scr...
CVE-2009-4579Cross-site scripting (XSS) vulnerability in the Artist avenue (com_artistavenue) component for Joomla! and Mambo allows ...
CVE-2009-4578Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows rem...
CVE-2009-4577SQL injection vulnerability in the MDForum module 2.x through 2.07 for MAXdev MDPro allows remote attackers to execute a...
CVE-2009-4576SQL injection vulnerability in the BeeHeard (com_beeheard) component 1.x for Joomla! allows remote attackers to execute ...
CVE-2009-4575Cross-site scripting (XSS) vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 RC2 for Joomla! allows remote...
CVE-2009-4574SQL injection vulnerability in country_escorts.php in I-Escorts Directory Script allows remote attackers to execute arbi...
CVE-2009-4573Multiple cross-site scripting (XSS) vulnerabilities in the Joomulus (mod_joomulus) module 2.0 for Joomla! allow remote a...
CVE-2009-4572Cross-site request forgery (CSRF) vulnerability in PhpShop 0.8.1 allows remote attackers to hijack the authentication of...
CVE-2009-4571Multiple SQL injection vulnerabilities in index.php in PhpShop 0.8.1 allow remote attackers to execute arbitrary SQL com...
CVE-2009-4570Cross-site scripting (XSS) vulnerability in PhpShop 0.8.1 allows remote attackers to inject arbitrary web script or HTML...
CVE-2009-4569SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the...
CVE-2009-4568Cross-site scripting (XSS) vulnerability in Webmin before 1.500 and Usermin before 1.430 allows remote attackers to inje...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now