Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
397,948 CVEs1,725 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 241 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-6668 | Multiple directory traversal vulnerabilities in nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 15.3% | 8 April 2009 |
| CVE-2008-6667 | A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser and mobspass cookies to 1. | EXPLOIT ✓HIGH 7.5EPSS 2.56% | 8 April 2009 |
| CVE-2008-6665 | change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges via a crafted email parameter, possibly related to code injection. | EXPLOIT ✓MEDIUM 6.8EPSS 1.83% | 8 April 2009 |
| CVE-2008-6664 | action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values. | EXPLOIT ✓HIGH 7.5EPSS 2.51% | 8 April 2009 |
| CVE-2008-6663 | SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the auction_id parameter, a different vector than CVE-2009-0106. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 8 April 2009 |
| CVE-2009-0795 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ✓UnscoredEPSS — | 8 April 2009 |
| CVE-2009-1263 | SQL injection vulnerability in sub_commententry.php in the BookJoomlas (com_bookjoomlas) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a comment action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 7 April 2009 |
| CVE-2009-1260 | Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted (1) CCD or (2) IMG file. | EXPLOIT ×2 ✓HIGH 9.3EPSS 42.7% | 7 April 2009 |
| CVE-2009-1259 | SQL injection vulnerability in inc/bb/topic.php in Insane Visions AdaptBB 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the topic_id parameter in a topic action to index.php. | EXPLOIT ✓MEDIUM 6.8EPSS 0.93% | 7 April 2009 |
| CVE-2009-1257 | Heap-based buffer overflow in Magic ISO Maker 5.5 build 0274 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted CCD file. | EXPLOIT ×2 ✓HIGH 9.0EPSS 13.9% | 7 April 2009 |
| CVE-2009-1256 | SQL injection vulnerability in FlexCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the ItemId parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.00% | 7 April 2009 |
| CVE-2009-0796 | Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI. | EXPLOIT ✓LOW 2.6EPSS 29.6% | 7 April 2009 |
| CVE-2008-6660 | Unrestricted file upload vulnerability in bigdump.php in Alexey Ozerov BigDump 0.29b allows remote attackers to execute arbitrary code by uploading a file with an executable extension followed by a .sql extension, then accessing this file via a direct… | EXPLOIT ✓MEDIUM 6.8EPSS 2.98% | 7 April 2009 |
| CVE-2008-6659 | Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated users to configure arbitrary local files for execution via directory traversal sequences in the value of the… | EXPLOIT ✓MEDIUM 5.5EPSS 3.30% | 7 April 2009 |
| CVE-2008-6658 | Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated administrators to install packages from arbitrary directories via a .. | EXPLOIT ✓MEDIUM 4.0EPSS 1.98% | 7 April 2009 |
| CVE-2008-6657 | Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attackers to hijack the authentication of admins for requests that install packages via the package… | EXPLOIT ✓MEDIUM 6.8EPSS 1.14% | 7 April 2009 |
| CVE-2008-6656 | Multiple SQL injection vulnerabilities in Open Auto Classifieds 1.4.3b allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to listings.php and (2) the username field to login.php. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 7 April 2009 |
| CVE-2008-6655 | Multiple cross-site scripting (XSS) vulnerabilities in GEDCOM_TO_MYSQL 2 allow remote attackers to inject arbitrary web script or HTML via the (1) nom_branche and (2) nom parameters to php/prenom.php; the (3) nom_branche parameter to php/index.php; and… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.48% | 7 April 2009 |
| CVE-2008-6653 | SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.00% | 7 April 2009 |
| CVE-2008-6652 | SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the sitename parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 7 April 2009 |
| CVE-2008-6651 | Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbitrary PHP code into oxyhistory.php via the oxymsg parameter. | EXPLOIT ✓HIGH 10.0EPSS 3.50% | 7 April 2009 |
| CVE-2008-6650 | del.php in miniBloggie 1.0 allows remote attackers to delete arbitrary posts via a direct request with a modified post_id parameter, a different vulnerability than CVE-2008-4628. | EXPLOIT ✓MEDIUM 5.0EPSS 1.96% | 7 April 2009 |
| CVE-2008-6649 | SQL injection vulnerability in manager/image_details_editor.php in Ktools PhotoStore 2.5, 2.9.8, 3.1.0, and other versions through 3.5.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.02% | 7 April 2009 |
| CVE-2008-6648 | SQL injection vulnerability in crumbs.php in Ktools PhotoStore 3.4.3 and 3.5.2 allows remote attackers to execute arbitrary SQL commands via the gid parameter to about_us.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.01% | 7 April 2009 |
| CVE-2008-6647 | SQL injection vulnerability in gallery.php in Ktools PhotoStore 3.4.3 allows remote attackers to execute arbitrary SQL commands via the gid parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.01% | 7 April 2009 |
| CVE-2008-6644 | Cross-site scripting (XSS) vulnerability in Default.aspx in DotNetNuke 4.8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 7 April 2009 |
| CVE-2008-6643 | LokiCMS 0.3.4 and possibly earlier versions does not properly restrict access to administrative functions, which allows remote attackers to bypass intended restrictions and modify configuration settings via the LokiACTION parameter in a direct request… | EXPLOIT ✓MEDIUM 5.0EPSS 2.41% | 7 April 2009 |
| CVE-2008-6642 | SQL injection vulnerability in view.php in DotContent FluentCMS 4.x allows remote attackers to execute arbitrary SQL commands via the sid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 7 April 2009 |
| CVE-2008-6641 | Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to execute arbitrary SQL commands via the sid parameter to (1) kanal.asp, (2) google.asp, and (3) hakk.asp in yonet/; and allow remote attackers to… | EXPLOIT ✓MEDIUM 6.5EPSS 0.85% | 7 April 2009 |
| CVE-2008-6640 | Multiple SQL injection vulnerabilities in BatmanPorTaL allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) uyeadmin.asp and (2) profil.asp. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97% | 7 April 2009 |
| CVE-2008-6637 | Multiple cross-site scripting (XSS) vulnerabilities in forgotPW.php in Library Video Company SAFARI Montage 3.1.x allow remote attackers to inject arbitrary web script or HTML via the (1) school and (2) email parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.72% | 7 April 2009 |
| CVE-2008-6636 | PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the dir_edge_skins parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.89% | 7 April 2009 |
| CVE-2008-6635 | PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the dir_inc parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.03% | 7 April 2009 |
| CVE-2008-6634 | SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idroom parameter to weekview.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 7 April 2009 |
| CVE-2008-6633 | SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idresa parameter to resaopen.php. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 7 April 2009 |
| CVE-2008-6632 | SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header ($_SERVER['HTTP_USER_AGENT']). | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 7 April 2009 |
| CVE-2008-6631 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in BlogPHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) user parameter in a sendmessage action and the (2) username parameter when registering a new user,… | EXPLOIT ✓MEDIUM 4.3EPSS 1.72% | 7 April 2009 |
| CVE-2008-6629 | Cross-site scripting (XSS) vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script or HTML via the name parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.52% | 6 April 2009 |
| CVE-2008-6628 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ✓UnscoredEPSS — | 6 April 2009 |
| CVE-2008-6627 | SQL injection vulnerability in getin.php in WEBBDOMAIN WebShop 1.2, 1.1, 1.02, and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 6 April 2009 |
| CVE-2008-6626 | SQL injection vulnerability in getin.php in WEBBDOMAIN Quiz 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 6 April 2009 |
| CVE-2008-6625 | SQL injection vulnerability in getin.php in WEBBDOMAIN Polls (aka Poll) 1.0 and 1.01 allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 6 April 2009 |
| CVE-2008-6624 | SQL injection vulnerability in getin.php in WEBBDOMAIN Petition 1.02, 2.0, and 3.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 6 April 2009 |
| CVE-2008-6623 | SQL injection vulnerability in getin.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 6 April 2009 |
| CVE-2008-6622 | SQL injection vulnerability in choosecard.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02, 1.01, and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 6 April 2009 |
| CVE-2008-6620 | Multiple cross-site scripting (XSS) vulnerabilities in javascript/editor/editor/filemanager/browser/mcpuk/connectors/php/connector.php in GraFX miniCWB 2.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1)… | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 6 April 2009 |
| CVE-2008-6619 | Unrestricted file upload vulnerability in class/ApplyDB.php in ClassSystem 2.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in class/UploadHomepage/. | EXPLOIT ✓MEDIUM 6.8EPSS 4.06% | 6 April 2009 |
| CVE-2008-6618 | Multiple SQL injection vulnerabilities in ClassSystem 2.3 allow remote attackers to execute arbitrary SQL commands via the teacher_id parameter in (1) class/HomepageMain.php and (2) class/HomepageTop.php, and (3) the message_id parameter in… | EXPLOIT ×3 ✓HIGH 7.5EPSS 1.91% | 6 April 2009 |
| CVE-2008-6617 | Unrestricted file upload vulnerability in adm/visual/upload.php in SiteXS CMS 0.1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/. | EXPLOIT ✓MEDIUM 6.8EPSS 3.33% | 6 April 2009 |
| CVE-2008-6616 | Cross-site scripting (XSS) vulnerability in index.php in Zen Software Zen Cart 2008 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in the advanced_search_result page. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 6 April 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.