SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

397,948 CVEs1,725 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 241 of 501

CVESummaryPriorityPublished
CVE-2008-6668Multiple directory traversal vulnerabilities in nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 15.3%8 April 2009
CVE-2008-6667A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser and mobspass cookies to 1.EXPLOIT ✓HIGH 7.5EPSS 2.56%8 April 2009
CVE-2008-6665change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges via a crafted email parameter, possibly related to code injection.EXPLOIT ✓MEDIUM 6.8EPSS 1.83%8 April 2009
CVE-2008-6664action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values.EXPLOIT ✓HIGH 7.5EPSS 2.51%8 April 2009
CVE-2008-6663SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the auction_id parameter, a different vector than CVE-2009-0106.EXPLOIT ✓HIGH 7.5EPSS 0.97%8 April 2009
CVE-2009-0795Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOIT ✓UnscoredEPSS —8 April 2009
CVE-2009-1263SQL injection vulnerability in sub_commententry.php in the BookJoomlas (com_bookjoomlas) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a comment action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.02%7 April 2009
CVE-2009-1260Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted (1) CCD or (2) IMG file.EXPLOIT ×2 ✓HIGH 9.3EPSS 42.7%7 April 2009
CVE-2009-1259SQL injection vulnerability in inc/bb/topic.php in Insane Visions AdaptBB 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the topic_id parameter in a topic action to index.php.EXPLOIT ✓MEDIUM 6.8EPSS 0.93%7 April 2009
CVE-2009-1257Heap-based buffer overflow in Magic ISO Maker 5.5 build 0274 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted CCD file.EXPLOIT ×2 ✓HIGH 9.0EPSS 13.9%7 April 2009
CVE-2009-1256SQL injection vulnerability in FlexCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the ItemId parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.00%7 April 2009
CVE-2009-0796Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.EXPLOIT ✓LOW 2.6EPSS 29.6%7 April 2009
CVE-2008-6660Unrestricted file upload vulnerability in bigdump.php in Alexey Ozerov BigDump 0.29b allows remote attackers to execute arbitrary code by uploading a file with an executable extension followed by a .sql extension, then accessing this file via a direct…EXPLOIT ✓MEDIUM 6.8EPSS 2.98%7 April 2009
CVE-2008-6659Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated users to configure arbitrary local files for execution via directory traversal sequences in the value of the…EXPLOIT ✓MEDIUM 5.5EPSS 3.30%7 April 2009
CVE-2008-6658Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated administrators to install packages from arbitrary directories via a ..EXPLOIT ✓MEDIUM 4.0EPSS 1.98%7 April 2009
CVE-2008-6657Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attackers to hijack the authentication of admins for requests that install packages via the package…EXPLOIT ✓MEDIUM 6.8EPSS 1.14%7 April 2009
CVE-2008-6656Multiple SQL injection vulnerabilities in Open Auto Classifieds 1.4.3b allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to listings.php and (2) the username field to login.php.EXPLOIT ✓HIGH 7.5EPSS 1.15%7 April 2009
CVE-2008-6655Multiple cross-site scripting (XSS) vulnerabilities in GEDCOM_TO_MYSQL 2 allow remote attackers to inject arbitrary web script or HTML via the (1) nom_branche and (2) nom parameters to php/prenom.php; the (3) nom_branche parameter to php/index.php; and…EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.48%7 April 2009
CVE-2008-6653SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 2.00%7 April 2009
CVE-2008-6652SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the sitename parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%7 April 2009
CVE-2008-6651Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbitrary PHP code into oxyhistory.php via the oxymsg parameter.EXPLOIT ✓HIGH 10.0EPSS 3.50%7 April 2009
CVE-2008-6650del.php in miniBloggie 1.0 allows remote attackers to delete arbitrary posts via a direct request with a modified post_id parameter, a different vulnerability than CVE-2008-4628.EXPLOIT ✓MEDIUM 5.0EPSS 1.96%7 April 2009
CVE-2008-6649SQL injection vulnerability in manager/image_details_editor.php in Ktools PhotoStore 2.5, 2.9.8, 3.1.0, and other versions through 3.5.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 2.02%7 April 2009
CVE-2008-6648SQL injection vulnerability in crumbs.php in Ktools PhotoStore 3.4.3 and 3.5.2 allows remote attackers to execute arbitrary SQL commands via the gid parameter to about_us.php.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.01%7 April 2009
CVE-2008-6647SQL injection vulnerability in gallery.php in Ktools PhotoStore 3.4.3 allows remote attackers to execute arbitrary SQL commands via the gid parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.01%7 April 2009
CVE-2008-6644Cross-site scripting (XSS) vulnerability in Default.aspx in DotNetNuke 4.8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.EXPLOIT ✓MEDIUM 4.3EPSS 1.51%7 April 2009
CVE-2008-6643LokiCMS 0.3.4 and possibly earlier versions does not properly restrict access to administrative functions, which allows remote attackers to bypass intended restrictions and modify configuration settings via the LokiACTION parameter in a direct request…EXPLOIT ✓MEDIUM 5.0EPSS 2.41%7 April 2009
CVE-2008-6642SQL injection vulnerability in view.php in DotContent FluentCMS 4.x allows remote attackers to execute arbitrary SQL commands via the sid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%7 April 2009
CVE-2008-6641Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to execute arbitrary SQL commands via the sid parameter to (1) kanal.asp, (2) google.asp, and (3) hakk.asp in yonet/; and allow remote attackers to…EXPLOIT ✓MEDIUM 6.5EPSS 0.85%7 April 2009
CVE-2008-6640Multiple SQL injection vulnerabilities in BatmanPorTaL allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) uyeadmin.asp and (2) profil.asp.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97%7 April 2009
CVE-2008-6637Multiple cross-site scripting (XSS) vulnerabilities in forgotPW.php in Library Video Company SAFARI Montage 3.1.x allow remote attackers to inject arbitrary web script or HTML via the (1) school and (2) email parameters.EXPLOIT ✓MEDIUM 4.3EPSS 1.72%7 April 2009
CVE-2008-6636PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the dir_edge_skins parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.89%7 April 2009
CVE-2008-6635PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the dir_inc parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.03%7 April 2009
CVE-2008-6634SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idroom parameter to weekview.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%7 April 2009
CVE-2008-6633SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idresa parameter to resaopen.php.EXPLOIT ✓HIGH 7.5EPSS 1.15%7 April 2009
CVE-2008-6632SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header ($_SERVER['HTTP_USER_AGENT']).EXPLOIT ✓HIGH 7.5EPSS 0.97%7 April 2009
CVE-2008-6631Multiple cross-site scripting (XSS) vulnerabilities in index.php in BlogPHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) user parameter in a sendmessage action and the (2) username parameter when registering a new user,…EXPLOIT ✓MEDIUM 4.3EPSS 1.72%7 April 2009
CVE-2008-6629Cross-site scripting (XSS) vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script or HTML via the name parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.52%6 April 2009
CVE-2008-6628Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOIT ✓UnscoredEPSS —6 April 2009
CVE-2008-6627SQL injection vulnerability in getin.php in WEBBDOMAIN WebShop 1.2, 1.1, 1.02, and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%6 April 2009
CVE-2008-6626SQL injection vulnerability in getin.php in WEBBDOMAIN Quiz 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%6 April 2009
CVE-2008-6625SQL injection vulnerability in getin.php in WEBBDOMAIN Polls (aka Poll) 1.0 and 1.01 allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%6 April 2009
CVE-2008-6624SQL injection vulnerability in getin.php in WEBBDOMAIN Petition 1.02, 2.0, and 3.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%6 April 2009
CVE-2008-6623SQL injection vulnerability in getin.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%6 April 2009
CVE-2008-6622SQL injection vulnerability in choosecard.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02, 1.01, and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%6 April 2009
CVE-2008-6620Multiple cross-site scripting (XSS) vulnerabilities in javascript/editor/editor/filemanager/browser/mcpuk/connectors/php/connector.php in GraFX miniCWB 2.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1)…EXPLOIT ✓MEDIUM 4.3EPSS 1.50%6 April 2009
CVE-2008-6619Unrestricted file upload vulnerability in class/ApplyDB.php in ClassSystem 2.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in class/UploadHomepage/.EXPLOIT ✓MEDIUM 6.8EPSS 4.06%6 April 2009
CVE-2008-6618Multiple SQL injection vulnerabilities in ClassSystem 2.3 allow remote attackers to execute arbitrary SQL commands via the teacher_id parameter in (1) class/HomepageMain.php and (2) class/HomepageTop.php, and (3) the message_id parameter in…EXPLOIT ×3 ✓HIGH 7.5EPSS 1.91%6 April 2009
CVE-2008-6617Unrestricted file upload vulnerability in adm/visual/upload.php in SiteXS CMS 0.1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/.EXPLOIT ✓MEDIUM 6.8EPSS 3.33%6 April 2009
CVE-2008-6616Cross-site scripting (XSS) vulnerability in index.php in Zen Software Zen Cart 2008 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in the advanced_search_result page.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%6 April 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.