SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

397,465 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 221 of 501

CVESummaryPriorityPublished
CVE-2008-7099Unspecified vulnerability in the Manage Templates feature in Qsoft K-Rate Premium allows remote attackers to execute arbitrary PHP code via unknown vectors.EXPLOIT ✓MEDIUM 6.8EPSS 2.02%27 August 2009
CVE-2008-7098Multiple cross-site scripting (XSS) vulnerabilities in Qsoft K-Rate Premium allow remote attackers to inject arbitrary web script or HTML via the blog, possibly the (1) Title and (2) Text fields; (3) the gallery, possibly the Description field in Your…EXPLOIT ✓MEDIUM 4.3EPSS 2.00%27 August 2009
CVE-2008-7097Multiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands via (1) the $id variable in admin/includes/dele_cpac.php, (2) $ord[order_id] variable in payments/payment_received.php, (3) $id…EXPLOIT ✓HIGH 7.5EPSS 2.08%27 August 2009
CVE-2009-2698The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors…EXPLOIT ×3 ✓HIGH 7.8EPSS 7.12%27 August 2009
CVE-2008-7091Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to vote.php, which is not properly handled in libs/link.php; (2) id parameter to trackback.php; (3) an…EXPLOIT ×2 ✓HIGH 7.5EPSS 2.10%26 August 2009
CVE-2008-7090Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existence of arbitrary files via a ..EXPLOIT ✓HIGH 7.8EPSS 8.30%26 August 2009
CVE-2008-7089Cross-site scripting (XSS) vulnerability in Pligg 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action to user.php and other unspecified vectors.EXPLOIT ✓MEDIUM 4.3EPSS 1.71%26 August 2009
CVE-2008-7088Unrestricted file upload vulnerability in upload.php in PhotoPost vBGallery 2.4.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct…EXPLOIT ✓MEDIUM 6.5EPSS 3.25%26 August 2009
CVE-2008-7087PHP remote file inclusion vulnerability in search_wA.php in OpenPro 1.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the LIBPATH parameter.EXPLOIT ✓HIGH 7.5EPSS 2.30%26 August 2009
CVE-2008-7086Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie cookie to admin.EXPLOIT ✓HIGH 7.5EPSS 6.64%26 August 2009
CVE-2008-7085Multiple SQL injection vulnerabilities in TheHockeyStop HockeySTATS Online 2.0 Basic and Advanced allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the viewpage action to the default URI, probably index.php, or (2)…EXPLOIT ✓HIGH 7.5EPSS 1.99%26 August 2009
CVE-2008-7084Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.76%26 August 2009
CVE-2009-2966avp.exe in Kaspersky Internet Security 9.0.0.459 and Anti-Virus 9.0.0.463 allows remote attackers to cause a denial of service (CPU consumption and network connectivity loss) via an HTTP URL request that contains a large number of dot "." characters.EXPLOIT ✓MEDIUM 4.3EPSS 6.40%25 August 2009
CVE-2009-2965Cross-site scripting (XSS) vulnerability in entry/index.jsp in Radvision Scopia 5.7, and possibly other versions before SD 7.0.100, allows remote attackers to inject arbitrary web script or HTML via the page parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.20%25 August 2009
CVE-2009-2961Stack-based buffer overflow in Thaddy de Konng KOL Player 1.0 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a .MP3 playlist file.EXPLOIT ✓HIGH 9.3EPSS 4.81%25 August 2009
CVE-2009-2960CuteFlow 2.10.3 and 2.11.0_c does not properly restrict access to pages/edituser.php, which allows remote attackers to modify usernames and passwords via a direct request.EXPLOIT ✓HIGH 7.5EPSS 2.33%25 August 2009
CVE-2008-7083Multiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.EXPLOIT ✓HIGH 7.5EPSS 0.97%25 August 2009
CVE-2008-7080Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql.EXPLOIT ✓MEDIUM 5.0EPSS 7.59%25 August 2009
CVE-2008-7079Buffer overflow in Nero ShowTime 5.0.15.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long entry in a .M3U playlist file.EXPLOIT ✓HIGH 9.3EPSS 5.76%25 August 2009
CVE-2008-7078Multiple buffer overflows in Rumpus before 6.0.1 allow remote attackers to (1) cause a denial of service (segmentation fault) via a long HTTP verb in the HTTP component; and allow remote authenticated users to execute arbitrary code via a long argument…EXPLOIT ✓HIGH 9.0EPSS 7.14%25 August 2009
CVE-2008-7077Multiple SQL injection vulnerabilities in SailPlanner 0.3a allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.EXPLOIT ✓HIGH 7.5EPSS 0.97%25 August 2009
CVE-2008-7076Unrestricted file upload vulnerability in user.modify.profile.php in Kalptaru Infotech Ltd.EXPLOIT ✓MEDIUM 6.5EPSS 3.39%25 August 2009
CVE-2008-7075Multiple SQL injection vulnerabilities in Kalptaru Infotech Ltd.EXPLOIT ×2 ✓HIGH 7.5EPSS 2.03%25 August 2009
CVE-2008-7074Format string vulnerability in MemeCode Software i.Scribe 1.88 through 2.00 before Beta9 allows remote SMTP servers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a server response, which is not…EXPLOIT ✓HIGH 9.3EPSS 4.89%25 August 2009
CVE-2008-7073PHP remote file inclusion vulnerability in lib/action/rss.php in RSS module 0.1 for Pie Web M{a,e}sher, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the lib parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.81%25 August 2009
CVE-2008-7072Cross-site scripting (XSS) vulnerability in index.php in Chipmunk Topsites allows remote attackers to inject arbitrary web script or HTML via the start parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%25 August 2009
CVE-2008-7071SQL injection vulnerability in authenticate.php in Chipmunk Topsites allows remote attackers to execute arbitrary SQL commands via the username parameter, related to login.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%25 August 2009
CVE-2008-7070Argument injection vulnerability in the URI handler in KVIrc 3.4.2 Shiny allows remote attackers to execute arbitrary commands via a " (quote) followed by command line switches in a (1) irc:///, (2) irc6:///, (3) ircs:///, or (4) and ircs6:/// URI.EXPLOIT ✓HIGH 9.3EPSS 5.05%25 August 2009
CVE-2008-7069All Club CMS (ACCMS) 0.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database configuration information, including credentials, via a direct request to accms.dat.EXPLOIT ✓HIGH 7.5EPSS 2.53%25 August 2009
CVE-2008-7067PHP remote file inclusion vulnerability in admin/plugins/Online_Users/main.php in PageTree CMS 0.0.2 BETA 0001 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[PT_Config][dir][data] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.29%25 August 2009
CVE-2008-7066OpenForum 0.66 Beta allows remote attackers to bypass authentication and reset passwords of other users via a direct request with the update parameter set to 1 and modified user and password parameters.EXPLOIT ✓HIGH 7.5EPSS 2.50%25 August 2009
CVE-2008-7065Siemens C450 IP and C475 IP VoIP devices allow remote attackers to cause a denial of service (disconnected calls and device reboot) via a crafted SIP packet to UDP port 5060.EXPLOIT ✓HIGH 7.8EPSS 3.73%25 August 2009
CVE-2008-7064Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5, when running on Windows, allows remote attackers to include and execute arbitrary local files via a "\"…EXPLOIT ✓HIGH 7.5EPSS 3.19%25 August 2009
CVE-2008-7063Ocean12 FAQ Manager Pro stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for admin/o12faq.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.23%25 August 2009
CVE-2008-7062Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request…EXPLOIT ✓MEDIUM 6.8EPSS 6.72%25 August 2009
CVE-2008-7061The tooltip manager (chrome/views/tooltip_manager.cc) in Google Chrome 0.2.149.29 Build 1798 and possibly other versions before 0.2.149.30 allows remote attackers to cause a denial of service (CPU consumption or crash) via a tag with a long title…EXPLOIT ✓MEDIUM 4.3EPSS 4.26%24 August 2009
CVE-2008-7059SQL injection vulnerability in index.php in One-News Beta 2 allows remote attackers to execute arbitrary SQL commands via the q parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97%24 August 2009
CVE-2008-7058Cross-site request forgery (CSRF) vulnerability in BandSite CMS 1.1.4 allows remote attackers to hijack the authentication of administrators and force a logout via adminpanel/logout.php.EXPLOIT ✓MEDIUM 6.8EPSS 0.94%24 August 2009
CVE-2008-7057Cross-site scripting (XSS) vulnerability in merchandise.php in BandSite CMS 1.1.4 allows remote attackers to inject arbitrary HTML or web script via the type parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%24 August 2009
CVE-2008-7056BandSite CMS 1.1.4 does not perform access control for adminpanel/phpmydump.php, which allows remote attackers to obtain copies of the database via a direct request.EXPLOIT ✓MEDIUM 5.0EPSS 2.46%24 August 2009
CVE-2008-7055module.php in ezContents 2.0.3 allows remote attackers to bypass the directory traversal protection mechanism to include and execute arbitrary local files via "....//" (doubled dot dot slash) sequences in the link parameter, which is not properly…EXPLOIT ✓MEDIUM 5.1EPSS 2.00%24 August 2009
CVE-2008-7054Multiple directory traversal vulnerabilities in ezContents 2.0.3 allow remote attackers to include and execute arbitrary local files via the (1) gsLanguage and (2) language_home parameters to modules/diary/showdiary.php; (3) admin_home, (4) gsLanguage,…EXPLOIT ✓MEDIUM 5.1EPSS 7.04%24 August 2009
CVE-2008-7053LogMeIn Remote Access Utility ActiveX control (RACtrl.dll) allows remote attackers to cause a denial of service (crash) by setting the fgcolor and bgcolor properties to certain long values that trigger memory corruption.EXPLOIT ✓HIGH 9.3EPSS 6.54%24 August 2009
CVE-2009-2953Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of service (CPU consumption) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.EXPLOIT ✓MEDIUM 5.0EPSS 4.63%24 August 2009
CVE-2008-7052Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct…EXPLOIT ✓MEDIUM 6.5EPSS 3.29%24 August 2009
CVE-2008-7051AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2) articles.php, (3) articlesuspend.php, (4) site.php, (5) statistics.php, (6) mail.php, (7)…EXPLOIT ✓HIGH 7.5EPSS 2.51%24 August 2009
CVE-2008-7049Multiple SQL injection vulnerabilities in login.asp in NatterChat 1.1 and 1.12 allow remote attackers to execute arbitrary SQL commands via the (1) txtUsername parameter (aka Username) and (2) txtPassword parameter (aka Password) in a form generated by…EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97%24 August 2009
CVE-2008-7047NatterChat 1.1 allows remote attackers to bypass authentication and gain administrator privileges to read or delete rooms and messages via a direct request to admin/home.asp.EXPLOIT ✓HIGH 7.5EPSS 3.13%24 August 2009
CVE-2008-7046AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/include/newpoll.php, a different vector than CVE-2008-7045.EXPLOIT ✓MEDIUM 6.4EPSS 2.16%24 August 2009
CVE-2008-7045AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct request to admin/resetvote.php.EXPLOIT ✓MEDIUM 6.4EPSS 2.60%24 August 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.