SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

397,465 CVEs1,723 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 222 of 501

CVESummaryPriorityPublished
CVE-2008-7044SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to execute arbitrary SQL commands via the ques parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%24 August 2009
CVE-2008-7043Cross-site scripting (XSS) vulnerability in register.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to inject arbitrary web script or HTML via the Email parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.72%24 August 2009
CVE-2008-7042PHP remote file inclusion vulnerability in url.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the tmp_sid parameter.EXPLOIT ✓HIGH 7.5EPSS 2.31%24 August 2009
CVE-2008-7041AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.EXPLOIT ✓HIGH 7.5EPSS 2.77%24 August 2009
CVE-2008-7040SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remote attackers to execute arbitrary SQL commands via the u parameter.EXPLOIT ✓HIGH 7.5EPSS 2.80%24 August 2009
CVE-2008-7038SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parameter in a showgall action to modules.php.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.15%24 August 2009
CVE-2008-7036Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for E-XooPS 1.0.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1)…EXPLOIT ✓MEDIUM 4.3EPSS 1.50%24 August 2009
CVE-2008-7033SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than…EXPLOIT ✓HIGH 7.5EPSS 0.97%24 August 2009
CVE-2008-7032Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote attackers to hijack the authentication of administrators for requests that create new administrators and execute shell…EXPLOIT ✓MEDIUM 6.8EPSS 2.42%24 August 2009
CVE-2008-7031Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SSH packets, a different vulnerability than CVE-2008-0151.EXPLOIT ✓HIGH 10.0EPSS 8.25%24 August 2009
CVE-2008-7030Multiple SQL injection vulnerabilities in Site2Nite Real Estate Web allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field to an unspecified component, possibly agentlist.asp.EXPLOIT ✓HIGH 7.5EPSS 0.97%24 August 2009
CVE-2009-2934Multiple stack-based buffer overflows in xaudio.dll in Programmed Integration PIPL 2.5.0 and 2.5.0D allow remote attackers to execute arbitrary code via a long string in a (1) .pls or (2) .pl playlist file.EXPLOIT ×2 ✓HIGH 9.3EPSS 10.2%21 August 2009
CVE-2009-2930Cross-site scripting (XSS) vulnerability in the Search feature in elka CMS (aka Elkapax) allows remote attackers to inject arbitrary web script or HTML via the q parameter to the default URI.EXPLOIT ✓MEDIUM 4.3EPSS 1.20%21 August 2009
CVE-2009-2929Multiple SQL injection vulnerabilities in TGS Content Management 0.x allow remote attackers to execute arbitrary SQL commands via the (1) tgs_language_id, (2) tpl_dir, (3) referer, (4) user-agent, (5) site, (6) option, (7) db_optimization, (8) owner,…EXPLOIT ✓HIGH 7.5EPSS 0.95%21 August 2009
CVE-2009-2928Cross-site scripting (XSS) vulnerability in login.php in TGS Content Management 0.x allows remote attackers to inject arbitrary web script or HTML via the previous_page parameter, a different vector than CVE-2008-6839.EXPLOIT ✓MEDIUM 4.3EPSS 1.22%21 August 2009
CVE-2009-2927SQL injection vulnerability in DetailFile.php in DigitalSpinners DS CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the nFileId parameter.EXPLOIT ✓HIGH 7.5EPSS 0.93%21 August 2009
CVE-2009-2926Multiple SQL injection vulnerabilities in PHP Competition System BETA 0.84 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) day parameter to show_matchs.php and (2) pageno parameter to persons.php.EXPLOIT ✓HIGH 7.5EPSS 0.93%21 August 2009
CVE-2009-2473neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number…EXPLOIT ✓MEDIUM 4.3EPSS 8.44%21 August 2009
CVE-2009-1879Cross-site scripting (XSS) vulnerability in index.template.html in the express-install templates in the SDK in Adobe Flex before 3.4, when the installed Flash version is older than a specified requiredMajorVersion value, allows remote attackers to…EXPLOIT ✓LOW 2.6EPSS 8.25%21 August 2009
CVE-2008-7028RPG.Board 0.8 Beta2 and earlier allows remote attackers to bypass authentication and gain privileges by setting the keep4u cookie to a certain value.EXPLOIT ✓HIGH 7.5EPSS 2.56%21 August 2009
CVE-2008-7027Libra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user and pass cookies to 1.EXPLOIT ✓HIGH 7.5EPSS 2.29%21 August 2009
CVE-2008-7026Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct…EXPLOIT ✓MEDIUM 6.8EPSS 4.70%21 August 2009
CVE-2008-7025TrueVector in Check Point ZoneAlarm 8.0.020.000, with vsmon.exe running, allows remote HTTP proxies to cause a denial of service (crash) and disable the HIDS module via a crafted response.EXPLOIT ✓MEDIUM 4.3EPSS 2.02%21 August 2009
CVE-2008-7024admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator privileges by setting the user cookie to "admin" and setting the name parameter to "users."EXPLOIT ✓MEDIUM 6.8EPSS 2.53%21 August 2009
CVE-2008-7022Insecure method vulnerability in ChilkatMail_v7_9.dll in the Chilkat Software IMAP ActiveX control (ChilkatMail2.ChilkatMailMan2.1) allows remote attackers to execute arbitrary programs via the LoadXmlEmail method.EXPLOIT ✓HIGH 9.3EPSS 4.82%21 August 2009
CVE-2008-7021Unrestricted file upload vulnerability in editlogo.php in AvailScript Jobs Portal Script allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as an image or logo, then accessing it via a direct…EXPLOIT ✓MEDIUM 6.0EPSS 2.73%21 August 2009
CVE-2008-7019Esqlanelapse 2.6.1 and 2.6.2 allows remote attackers to bypass authentication and gain privileges via modified (1) enombre and (2) euri cookies.EXPLOIT ✓HIGH 7.5EPSS 2.56%21 August 2009
CVE-2008-7017Cross-site scripting (XSS) vulnerability in analyse.php in CAcert 20080921, and possibly other versions before 20080928, allows remote attackers to inject arbitrary web script or HTML via the CN (CommonName) field in the subject of an X.509 certificate.EXPLOIT ✓MEDIUM 4.3EPSS 0.90%21 August 2009
CVE-2009-2925Directory traversal vulnerability in DJcalendar.cgi in DJCalendar allows remote attackers to read arbitrary files via a ..EXPLOIT ✓HIGH 7.8EPSS 3.47%21 August 2009
CVE-2009-2924Multiple SQL injection vulnerabilities in Videos Broadcast Yourself 2 allow remote attackers to execute arbitrary SQL commands via the (1) UploadID parameter to videoint.php, and possibly the (2) cat_id parameter to catvideo.php and (3) uid parameter to…EXPLOIT ✓HIGH 7.5EPSS 0.92%21 August 2009
CVE-2009-2923Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.99%21 August 2009
CVE-2009-2922Absolute path traversal vulnerability in pixaria.image.php in Pixaria Gallery 2.0.0 through 2.3.5 allows remote attackers to read arbitrary files via a base64-encoded file parameter.EXPLOIT ✓HIGH 7.8EPSS 2.59%21 August 2009
CVE-2009-2921Multiple SQL injection vulnerabilities in login.php in MOC Designs PHP News 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) newsuser parameter (User field) and (2) newspassword parameter (Password field).EXPLOIT ✓HIGH 7.5EPSS 1.15%21 August 2009
CVE-2009-2920Multiple cross-site scripting (XSS) vulnerabilities in Elvin 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) component and (2) priority parameters to buglist.php; and the (3) Username (4) E-mail, (5) Pass, and (6) Confirm…EXPLOIT ✓MEDIUM 4.3EPSS 1.22%21 August 2009
CVE-2009-2918The tgbvpn.sys driver in TheGreenBow IPSec VPN Client 4.61.003 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted request to the 0x80000034 IOCTL, probably involving an input or output buffer size…EXPLOIT ✓LOW 2.1EPSS 0.85%21 August 2009
CVE-2009-2917Stack-based buffer overflow in ImTOO MPEG Encoder 3.1.53 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted string in a (1) .cue or (2) .m3u playlist file.EXPLOIT ✓MEDIUM 4.3EPSS 3.39%21 August 2009
CVE-2009-2915SQL injection vulnerability in 2fly_gift.php in 2FLY Gift Delivery System 6.0 allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a content action.EXPLOIT ✓HIGH 7.5EPSS 0.97%21 August 2009
CVE-2009-2732The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an Authorization HTTP header that lacks a : (colon) character in the base64-decoded…EXPLOIT ✓MEDIUM 5.0EPSS 7.27%21 August 2009
CVE-2009-2694The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory…EXPLOIT ✓HIGH 10.0EPSS 20.3%21 August 2009
CVE-2009-2896Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file.EXPLOIT ✓HIGH 9.3EPSS 5.59%20 August 2009
CVE-2009-2895SQL injection vulnerability in rss.php in Ultimate Regnow Affiliate (URA) 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter.EXPLOIT ✓HIGH 7.5EPSS 0.92%20 August 2009
CVE-2009-2894Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to product_desc.php, and the cid parameter to (2) showcategory.php and (3) gallery.php.EXPLOIT ✓HIGH 7.5EPSS 1.18%20 August 2009
CVE-2009-2893Multiple cross-site scripting (XSS) vulnerabilities in index.php in XZero Community Classifieds 4.97.8 allow remote attackers to inject arbitrary web script or HTML via (1) the postevent parameter in a post action or (2) the _xzcal_y parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.48%20 August 2009
CVE-2009-2892Multiple SQL injection vulnerabilities in header.php in Scripteen Free Image Hosting Script 2.3 allow remote attackers to execute arbitrary SQL commands via a (1) cookid or (2) cookgid cookie.EXPLOIT ✓HIGH 7.5EPSS 1.08%20 August 2009
CVE-2009-2891SQL injection vulnerability in list.php in PHP Scripts Now Riddles allows remote attackers to execute arbitrary SQL commands via the catid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%20 August 2009
CVE-2009-2890Cross-site scripting (XSS) vulnerability in results.php in PHP Scripts Now Riddles allows remote attackers to inject arbitrary web script or HTML via the searchquery parameter.EXPLOIT ✓MEDIUM 4.3EPSS 3.06%20 August 2009
CVE-2009-2889Cross-site scripting (XSS) vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to inject arbitrary web script or HTML via the letters parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%20 August 2009
CVE-2009-2888SQL injection vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to execute arbitrary SQL commands via the n parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%20 August 2009
CVE-2009-2885SQL injection vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote attackers to execute arbitrary SQL commands via the rank parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%20 August 2009
CVE-2009-2884Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote attackers to inject arbitrary web script or HTML via the rank parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%20 August 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.