SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,020 CVEs1,725 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 245 of 501

CVESummaryPriorityPublished
CVE-2008-6490function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the target filename in the target_file parameter.EXPLOIT ✓HIGH 7.5EPSS 4.17%19 March 2009
CVE-2008-6489SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the album parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%19 March 2009
CVE-2008-6488SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the Admin field in a login action.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97%18 March 2009
CVE-2008-6487Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) admin and (2) password fields.EXPLOIT ✓HIGH 7.5EPSS 0.97%18 March 2009
CVE-2008-6485SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary SQL commands via the ctg parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97%18 March 2009
CVE-2008-6484SQL injection vulnerability in login.php in Mole Group Taxi Map Script (aka Taxi Calc Dist Script) allows remote attackers to execute arbitrary SQL commands via the user field.EXPLOIT ✓HIGH 7.5EPSS 1.00%18 March 2009
CVE-2008-6483PHP remote file inclusion vulnerability in admin.googlebase.php in the Ecom Solutions VirtueMart Google Base (aka com_googlebase or Froogle) component 1.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the…EXPLOIT ✓HIGH 7.5EPSS 25.7%18 March 2009
CVE-2008-6482PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the mosConfig_live_site parameter.EXPLOIT ✓MEDIUM 6.8EPSS 22.1%18 March 2009
CVE-2009-0932Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image…EXPLOIT ✓MEDIUM 6.4EPSS 45.8%17 March 2009
CVE-2008-6481SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%17 March 2009
CVE-2009-0922PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified…EXPLOIT ✓MEDIUM 4.0EPSS 10.2%17 March 2009
CVE-2008-6479Cross-site request forgery (CSRF) vulnerability in the "change password" feature in the VZPP web interface for Parallels Virtuozzo 25.4.swsoft (build 3.0.0-25.4.swsoft) allows remote attackers to modify the password via a link or IMG tag to vz/cp/pwd.EXPLOIT ✓MEDIUM 6.8EPSS 1.15%16 March 2009
CVE-2008-6478Cross-site request forgery (CSRF) vulnerability in the file manager in the VZPP web interface for Parallels Virtuozzo 365.6.swsoft (build 4.0.0-365.6.swsoft) and 25.4.swsoft (build 3.0.0-25.4.swsoft) allows remote attackers to create and delete…EXPLOIT ✓MEDIUM 6.8EPSS 1.30%16 March 2009
CVE-2008-6477SQL injection vulnerability in Mumbo Jumbo Media OP4 allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%16 March 2009
CVE-2008-6476Cross-site scripting (XSS) vulnerability in blog/search.aspx in BlogEngine.NET allows remote attackers to inject arbitrary web script or HTML via the q parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.47%16 March 2009
CVE-2008-6475SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earlier allows remote attackers to execute arbitrary SQL commands via the Via HTTP header (HTTP_VIA) to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.00%16 March 2009
CVE-2008-6473_blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary users via a modified "a" parameter with a "%" wildcard symbol in the b parameter.EXPLOIT ✓MEDIUM 6.4EPSS 2.31%16 March 2009
CVE-2009-0824Elaborate Bytes ElbyCDIO.sys 6.0.2.0 and earlier, as distributed in SlySoft AnyDVD before 6.5.2.6, Virtual CloneDrive 5.4.2.3 and earlier, CloneDVD 2.9.2.0 and earlier, and CloneCD 5.3.1.3 and earlier, uses the METHOD_NEITHER communication method for…EXPLOIT ✓MEDIUM 4.9EPSS 0.73%14 March 2009
CVE-2008-6471SQL injection vulnerability in detail.php in MountainGrafix easyLink 1.1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter in a show action.EXPLOIT ✓HIGH 7.5EPSS 1.00%13 March 2009
CVE-2008-6469SQL injection vulnerability in index.php in PlainCart 1.1.2 allows remote attackers to execute arbitrary SQL commands via the p parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%13 March 2009
CVE-2008-6468SQL injection vulnerability in index.php in Diesel Pay allows remote attackers to execute arbitrary SQL commands via the area parameter in a browse action.EXPLOIT ✓HIGH 7.5EPSS 0.93%13 March 2009
CVE-2008-6467SQL injection vulnerability in jobs/jobseekers/job-info.php in Diesel Job Site allows remote attackers to execute arbitrary SQL commands via the job_id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.93%13 March 2009
CVE-2008-6466SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e107 allows remote attackers to execute arbitrary SQL commands via the image parameter in an image-detail action.EXPLOIT ✓HIGH 7.5EPSS 0.97%13 March 2009
CVE-2008-6464SQL injection vulnerability in event.php in Mevin Productions Basic PHP Events Lister 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.05%13 March 2009
CVE-2008-6454SQL injection vulnerability in section.php in 6rbScript 3.3 allows remote attackers to execute arbitrary SQL commands via the singerid parameter in a singers action.EXPLOIT ✓HIGH 7.5EPSS 0.97%13 March 2009
CVE-2008-6453Directory traversal vulnerability in section.php in 6rbScript 3.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 4.3EPSS 2.29%13 March 2009
CVE-2008-6452SQL injection vulnerability in show_vote.php in Oceandir 2.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.93%13 March 2009
CVE-2008-6451SQL injection vulnerability in humor.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.93%13 March 2009
CVE-2009-0886Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 6.54%12 March 2009
CVE-2009-0885Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in a (1) M3U, (2) M3l, (3) TXT, and (4) LRC playlist file.EXPLOIT ×2 ✓HIGH 9.3EPSS 8.75%12 March 2009
CVE-2009-0883SQL injection vulnerability in Blue Eye CMS 1.0.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the BlueEyeCMS_login cookie parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.93%12 March 2009
CVE-2009-0882Multiple SQL injection vulnerabilities in nForum 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to showtheme.php and the (2) user parameter to userinfo.php.EXPLOIT ✓HIGH 7.5EPSS 0.91%12 March 2009
CVE-2009-0881SQL injection vulnerability in ejemplo/paises.php in isiAJAX 1 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.95%12 March 2009
CVE-2009-0880Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a ..EXPLOIT ×3 ✓MEDIUM 6.8EPSS 31.6%12 March 2009
CVE-2009-0879The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of service (daemon crash) via a long consumer name, as demonstrated by an M-POST request to a long /CIMListener/ URI.EXPLOIT ✓MEDIUM 5.0EPSS 8.22%12 March 2009
CVE-2009-0876Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain privileges via a hardlink attack, which preserves setuid/setgid bits on Linux, related to DT_RPATH:$ORIGIN.EXPLOIT ✓MEDIUM 6.9EPSS 0.78%12 March 2009
CVE-2009-0837Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to execute arbitrary code via a long (1) relative path or (2) absolute path in the filename argument in an action, as demonstrated by the…EXPLOIT ×2 ✓HIGH 10.0EPSS 75.8%10 March 2009
CVE-2009-0866pHNews Alpha 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for extra/genbackup.php.EXPLOIT ✓MEDIUM 5.0EPSS 2.51%10 March 2009
CVE-2009-0865Directory traversal vulnerability in the SnapShotToFile method in the GeoVision LiveX (aka LiveX_v8200) ActiveX control 8.1.2 and 8.2.0 in LIVEX_~1.OCX allows remote attackers to create or overwrite arbitrary files via a ..EXPLOIT ✓HIGH 8.8EPSS 5.54%10 March 2009
CVE-2009-0864S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for the login cookie.EXPLOIT ✓HIGH 7.5EPSS 2.77%10 March 2009
CVE-2009-0863SQL injection vulnerability in admin/delete_page.php in S-Cms 1.1 Stable allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.13%10 March 2009
CVE-2009-0858Bernstein djbdns 1.05 and earlier does not constrain offsets in the required manner, which allows remote attackers, with control over a third-party subdomain served by tinydns and axfrdns, to trigger DNS responses containing arbitrary records via…EXPLOIT ✓MEDIUM 5.8EPSS 6.28%9 March 2009
CVE-2009-0855Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.EXPLOIT ✓MEDIUM 4.3EPSS 5.98%9 March 2009
CVE-2009-0825SQL injection vulnerability in system/rss.php in TinX/cms 3.x before 3.5.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.26%9 March 2009
CVE-2009-0537Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to cause a denial of service (application crash) via a deep directory tree,…EXPLOIT ✓MEDIUM 4.9EPSS 3.59%9 March 2009
CVE-2009-0853login.php in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allows remote attackers to bypass authentication and obtain administrative access via special characters in the Username parameter, as demonstrated by an admin'# parameter value.EXPLOIT ✓MEDIUM 6.8EPSS 2.36%9 March 2009
CVE-2009-0852showme.php in CelerBB 0.0.2 allows remote attackers to obtain "reserved information" via the user parameter.EXPLOIT ✓MEDIUM 5.0EPSS 2.68%9 March 2009
CVE-2009-0851Multiple SQL injection vulnerabilities in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewforum.php and (2) viewtopic.php.EXPLOIT ✓MEDIUM 6.8EPSS 1.07%9 March 2009
CVE-2009-0849Stack-based buffer overflow in the DtbClsLogin function in NovaStor NovaNET 12 allows remote attackers to (1) execute arbitrary code on Linux platforms via a long username field during backup domain authentication, related to libnnlindtb.so; or (2)…EXPLOIT ✓HIGH 7.5EPSS 16.5%9 March 2009
CVE-2008-6447Buffer overflow in emmailstore.dll 6.5.0.3 in the QuikSoft EasyMail MailStore ActiveX control allows remote attackers to execute arbitrary code via a long first argument to the CreateStore method.EXPLOIT ×2 ✓HIGH 9.3EPSS 5.82%9 March 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.