SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

397,465 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 219 of 501

CVESummaryPriorityPublished
CVE-2008-7209Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows remote attackers to execute arbitrary code by uploading a file with an executable extension and using a safe content type such as…EXPLOIT ✓HIGH 7.5EPSS 6.01%11 September 2009
CVE-2008-7208Multiple SQL injection vulnerabilities in OneCMS 2.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) username parameter ($usernameb variable) to a_login.php or (2) user parameter to staff.php.EXPLOIT ✓MEDIUM 6.8EPSS 1.77%11 September 2009
CVE-2008-7203Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets.EXPLOIT ✓MEDIUM 5.0EPSS 2.61%11 September 2009
CVE-2009-3076Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operations, which makes it easier for remote attackers to trick a user into installing or removing an…EXPLOIT ✓HIGH 9.3EPSS 6.72%10 September 2009
CVE-2009-3162Cross-site scripting (XSS) vulnerability in Multi Website 1.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to the default URI.EXPLOIT ✓MEDIUM 4.3EPSS 1.27%10 September 2009
CVE-2009-3158admin/files.php in simplePHPWeb 0.2 does not require authentication, which allows remote attackers to perform unspecified administrative actions via unknown vectors.EXPLOIT ✓HIGH 7.5EPSS 2.66%10 September 2009
CVE-2009-3155Cross-site scripting (XSS) vulnerability in gmap.php in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%10 September 2009
CVE-2009-3154SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action to index.php, a different vector than…EXPLOIT ✓HIGH 7.5EPSS 0.93%10 September 2009
CVE-2009-3153Multiple cross-site scripting (XSS) vulnerabilities in x10 MP3 Search engine 1.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php, (2) category parameter to linkvideos_listing.php, id…EXPLOIT ×8 ✓MEDIUM 4.3EPSS 1.52%10 September 2009
CVE-2009-3152Multiple cross-site scripting (XSS) vulnerabilities in becommunity/community/index.php in NTSOFT BBS E-Market Professional allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) bt_code, and (3) b_no parameters in a board…EXPLOIT ✓MEDIUM 4.3EPSS 1.48%10 September 2009
CVE-2009-3151Directory traversal vulnerability in actions/downloadFile.php in Ultrize TimeSheet 1.2.2 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.73%10 September 2009
CVE-2009-3150SQL injection vulnerability in index.php in Multi Website 1.5 allows remote attackers to execute arbitrary SQL commands via the Browse parameter in a vote action.EXPLOIT ✓HIGH 7.5EPSS 1.00%10 September 2009
CVE-2009-3149Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 4.3EPSS 2.83%10 September 2009
CVE-2009-3148Multiple SQL injection vulnerabilities in PortalXP Teacher Edition 1.2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) calendar.php, (2) news.php, and (3) links.php; and the (4) assignment_id parameter to…EXPLOIT ✓HIGH 7.5EPSS 0.95%10 September 2009
CVE-2009-3124Directory traversal vulnerability in get_message.cgi in QuarkMail allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.99%9 September 2009
CVE-2009-3123Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.74%9 September 2009
CVE-2009-3119SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the view_id parameter.EXPLOITHIGH 7.5EPSS 0.99%9 September 2009
CVE-2009-3117SQL injection vulnerability in category.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%9 September 2009
CVE-2009-3116SQL injection vulnerability in index.php in Uiga Church Portal allows remote attackers to execute arbitrary SQL commands via the year parameter in a calendar action.EXPLOIT ✓HIGH 7.5EPSS 1.00%9 September 2009
CVE-2009-3115SolarWinds TFTP Server 9.2.0.111 and earlier allows remote attackers to cause a denial of service (service stop) via a crafted Option Acknowledgement (OACK) request.EXPLOIT ✓MEDIUM 5.0EPSS 10.7%9 September 2009
CVE-2008-7192Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.x versions, allows remote attackers to hijack the authentication of users for requests that delete private messages via the pmID…EXPLOIT ✓MEDIUM 6.8EPSS 0.82%9 September 2009
CVE-2009-3111The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes, as demonstrated by a certain module in VulnDisco Pack Professional 7.6 through 8.11.EXPLOIT ✓MEDIUM 5.0EPSS 11.2%9 September 2009
CVE-2008-7188ClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the profile of arbitrary users via a modified uid variable to siteadmin/useredit.php.EXPLOIT ✓HIGH 7.5EPSS 2.30%9 September 2009
CVE-2008-7185GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlist (.pls) file with a long Title field, possibly related to the g_hash_table_lookup function in b-playlist-manager.c.EXPLOIT ✓MEDIUM 4.3EPSS 3.06%8 September 2009
CVE-2008-7184Cross-site scripting (XSS) vulnerability in Diigo Toolbar and Diigolet allows remote attackers to inject arbitrary web script or HTML via a public comment.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%8 September 2009
CVE-2009-3103Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system…EXPLOIT ×6 ✓HIGH 10.0EPSS 92.3%8 September 2009
CVE-2009-3099Unspecified vulnerability in HP OpenView Operations Manager 8.1 on Windows Server 2003 SP2 allows remote attackers to have an unknown impact, related to a "Remote exploit," as demonstrated by a certain module in VulnDisco Pack Professional 8.11, a…EXPLOIT ✓HIGH 10.0EPSS 9.57%8 September 2009
CVE-2008-7182Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long first argument to the APPEND…EXPLOIT ✓MEDIUM 4.0EPSS 24.3%8 September 2009
CVE-2008-7181Butterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter to category-delete.php with the is_js_confirmed parameter set to 1, or (2) delete arbitrary accounts via the mytable parameter to…EXPLOIT ✓HIGH 7.5EPSS 2.29%8 September 2009
CVE-2008-7180del_query1.php in Telephone Directory 2008 allows remote attackers to delete arbitrary contacts via a direct request with a modified id variable.EXPLOIT ✓MEDIUM 5.0EPSS 1.62%8 September 2009
CVE-2008-7179OTManager CMS 2.4 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN_Hora, ADMIN_Logado, and ADMIN_Nome cookies to certain values, as reachable in Admin/index.php.EXPLOIT ✓HIGH 7.5EPSS 2.29%8 September 2009
CVE-2008-7178Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.17%8 September 2009
CVE-2008-7176Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a ..EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.97%8 September 2009
CVE-2008-7172Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote attackers to gain administrator privileges via direct requests to admin.php with the (1) potd_delete, (2) potd, (3) vote_update, (4)…EXPLOIT ✓HIGH 7.5EPSS 2.29%8 September 2009
CVE-2008-7171Multiple cross-site scripting (XSS) vulnerabilities in Lightweight news portal (LNP) 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) photo parameter to show_photo.php, (2) potd parameter to show_potd.php, or (3) the…EXPLOIT ✓MEDIUM 4.3EPSS 1.44%8 September 2009
CVE-2008-7170GSC build 2067 and earlier relies on the client to enforce administrator privileges, which allows remote attackers to execute arbitrary administrator commands via a crafted packet.EXPLOITHIGH 10.0EPSS 9.95%8 September 2009
CVE-2008-7169SQL injection vulnerability in Jabode horoscope extension (com_jabode) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.93%8 September 2009
CVE-2008-7168Insecure method vulnerability in the UUSee UUUpgrade ActiveX control (UUUpgrade.ocx 3.0.2.12) allows remote attackers to force the download and overwrite of arbitrary files via crafted arguments to the Update method, as exploited in the wild in June 2009.EXPLOIT ✓HIGH 9.3EPSS 5.65%8 September 2009
CVE-2008-7167Unrestricted file upload vulnerability in upload.php in Page Manager 2006-02-04 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified…EXPLOIT ✓HIGH 7.5EPSS 4.21%8 September 2009
CVE-2009-3082SQL injection vulnerability in wcategory.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.EXPLOIT ✓HIGH 7.5EPSS 0.89%4 September 2009
CVE-2009-3081SQL injection vulnerability in index.php in Uiga Church Portal allows remote attackers to execute arbitrary SQL commands via the month parameter in a calendar action.EXPLOIT ✓HIGH 7.5EPSS 0.96%4 September 2009
CVE-2009-3068Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute arbitrary code by uploading a Java Archive (.jsp) file during a PUBLISH action, then accessing it via a…EXPLOIT ×2 ✓HIGH 9.3EPSS 78.2%4 September 2009
CVE-2009-2521Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that…EXPLOIT ×2 ✓MEDIUM 5.0EPSS 82.3%4 September 2009
CVE-2008-7165Cross-site request forgery in cp06_wifi_m_nocifr.cgi in the administrator panel in TELECOM ITALIA Alice Gate2 Plus Wi-Fi allows remote attackers to hijack the authentication of administrators for requests that disable Wi-Fi encryption via certain values…EXPLOIT ✓MEDIUM 6.8EPSS 0.66%4 September 2009
CVE-2008-7163Directory traversal vulnerability in mods/Integrated/index.php in SineCMS 2.3.5 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the sine[config][index_main] parameter.EXPLOIT ✓MEDIUM 6.8EPSS 4.08%4 September 2009
CVE-2008-7162Buffer overflow in Hero Super Player 3000 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in a .M3U file.EXPLOIT ✓HIGH 9.3EPSS 5.52%4 September 2009
CVE-2008-7161Fortinet FortiGuard Fortinet FortiGate-1000 3.00 build 040075,070111 allows remote attackers to bypass URL filtering via fragmented GET or POST requests that use HTTP/1.0 without the Host header.EXPLOIT ✓HIGH 7.5EPSS 6.41%4 September 2009
CVE-2009-3066Multiple cross-site scripting (XSS) vulnerabilities in PropertyWatchScript.com Property Watch 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) videoid parameter to tools/email.php and (2) redirect parameter to tools/login.php.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.29%3 September 2009
CVE-2009-3065PHP remote file inclusion vulnerability in editor/edit_htmlarea.php in Ve-EDIT 0.1.4 allows remote attackers to execute arbitrary PHP code via a URL in the highlighter parameter.EXPLOIT ✓HIGH 7.5EPSS 2.19%3 September 2009
CVE-2009-3064Directory traversal vulnerability in debugger/debug_php.php in Ve-EDIT 0.1.4 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.40%3 September 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.