SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,020 CVEs1,725 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 246 of 501

CVESummaryPriorityPublished
CVE-2008-6446Static code injection vulnerability in the Guestbook component in CMS MAXSITE allows remote attackers to inject arbitrary PHP code into the guestbook via the message parameter.EXPLOIT ✓HIGH 7.5EPSS 2.27%9 March 2009
CVE-2008-6443SQL injection vulnerability in forum_duzen.php in phpKF allows remote attackers to execute arbitrary SQL commands via the fno parameter.EXPLOIT ✓HIGH 7.5EPSS 0.96%9 March 2009
CVE-2008-6442Insecure method vulnerability in Sina Inc.EXPLOIT ✓MEDIUM 5.8EPSS 1.82%9 March 2009
CVE-2008-6439Cross-site scripting (XSS) vulnerability in search_results.php in ABK-Soft AbleDating 2.4 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.47%6 March 2009
CVE-2008-6438SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the uid parameter, a different vector than CVE-2008-2455.EXPLOIT ×4 ✓HIGH 7.5EPSS 3.40%6 March 2009
CVE-2008-6437Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeForum 1.0 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to error.php, and the (2) nickname and (3) randomid parameters to…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.76%6 March 2009
CVE-2008-6435Multiple cross-site scripting (XSS) vulnerabilities in phpSQLiteCMS 1 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) lang[home], (2) lang[admin_menu], and (3) lang[admin_menu_page_overview] parameters to…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.48%6 March 2009
CVE-2008-6431Multiple cross-site scripting (XSS) vulnerabilities in BMForum 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) outpused parameter to index.php, the (2) footer_copyright and (3) verandproname parameters to…EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.82%6 March 2009
CVE-2008-6430SQL injection vulnerability in the MyContent (com_mycontent) component 1.1.13 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.04%6 March 2009
CVE-2008-6429SQL injection vulnerability in the PrayerCenter (com_prayercenter) component 1.4.9 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_request action to index2.php.EXPLOIT ✓HIGH 7.5EPSS 1.39%6 March 2009
CVE-2008-6427SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cid parameter.EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.65%6 March 2009
CVE-2008-6425SQL injection vulnerability in news.php in ComicShout 2.8 allows remote attackers to execute arbitrary SQL commands via the news_id parameter, a different vector than CVE-2008-2456.EXPLOIT ✓HIGH 7.5EPSS 1.20%6 March 2009
CVE-2008-6423Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and earlier allows remote attackers to read arbitrary local files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 6.80%6 March 2009
CVE-2008-6422Multiple SQL injection vulnerabilities in PsychoStats 2.3, 2.3.1, and 2.3.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) weapon.php and (2) map.php.EXPLOIT ✓HIGH 7.5EPSS 1.15%6 March 2009
CVE-2008-6421PHP remote file inclusion vulnerability in social_game_play.php in Social Site Generator (SSG) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 2.90%6 March 2009
CVE-2008-6420Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.php, (2) webadmin/download.php, and (3) webadmin/download_file.php.EXPLOIT ×2 ✓MEDIUM 5.0EPSS 3.56%6 March 2009
CVE-2008-6419Multiple SQL injection vulnerabilities in Social Site Generator (SSG) 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) sgc_id parameter to display_blog.php, (2) scm_mem_id parameter to social_my_profile_download.php, and the (3)…EXPLOIT ✓HIGH 7.5EPSS 1.23%6 March 2009
CVE-2008-6418SQL injection vulnerability in scrape.php in TorrentTrader before 2008-05-13 allows remote attackers to execute arbitrary SQL commands via the info_hash parameter.EXPLOIT ✓HIGH 7.5EPSS 1.22%6 March 2009
CVE-2009-0835The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform, when CONFIG_SECCOMP is enabled, does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a…EXPLOIT ✓LOW 3.6EPSS 0.93%6 March 2009
CVE-2008-6414SQL injection vulnerability in detail.php in AJ Auction Pro Platinum Skin 2 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%6 March 2009
CVE-2008-6411Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the login cookie to 1.EXPLOIT ✓HIGH 7.5EPSS 2.56%6 March 2009
CVE-2008-6410Directory traversal vulnerability in show.php in ol'bookmarks manager 0.7.5 and earlier allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.29%6 March 2009
CVE-2008-6409SQL injection vulnerability in index.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary SQL commands via the id parameter in a brain action.EXPLOIT ×3 ✓HIGH 7.5EPSS 0.94%6 March 2009
CVE-2008-6408PHP remote file inclusion vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary PHP code via a URL in the framefile parameter.EXPLOIT ✓HIGH 7.5EPSS 2.29%6 March 2009
CVE-2008-6407Directory traversal vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.29%6 March 2009
CVE-2008-6406Cross-site scripting (XSS) vulnerability in admin.php in DataLife Engine (DLE) 7.2 allows remote attackers to inject arbitrary web script or HTML via the query string.EXPLOIT ✓MEDIUM 4.3EPSS 1.47%6 March 2009
CVE-2008-6405SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL commands via the cid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%6 March 2009
CVE-2008-6404Cross-site scripting (XSS) vulnerability in add_calendars.php in eXtrovert Software Thyme 1.3 allows remote attackers to inject arbitrary web script or HTML via the callback parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%6 March 2009
CVE-2008-6403PHP remote file inclusion vulnerability in themes/default/include/html/insert.inc.php in OpenRat 0.8-beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tpl_dir parameter.EXPLOIT ✓HIGH 7.5EPSS 2.29%6 March 2009
CVE-2008-6402PHP remote file inclusion vulnerability in hu/modules/reg-new/modstart.php in Sofi WebGui 0.6.3 PRE and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mod_dir parameter.EXPLOIT ✓HIGH 7.5EPSS 2.29%6 March 2009
CVE-2008-6401SQL injection vulnerability in sayfa.php in JETIK-WEB allows remote attackers to execute arbitrary SQL commands via the kat parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%6 March 2009
CVE-2009-0769QIP 2005 build 8082 allows remote attackers to cause a denial of service (CPU consumption and application hang) via a crafted Rich Text Format (RTF) ICQ message, as demonstrated by an {\rtf\pict\&&} message.EXPLOIT ✓MEDIUM 4.3EPSS 2.43%6 March 2009
CVE-2009-0768SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the forumID parameter in a next action.EXPLOIT ✓HIGH 7.5EPSS 0.95%6 March 2009
CVE-2009-0767Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing credentials via a direct request for job/config.data.EXPLOIT ✓MEDIUM 5.0EPSS 2.33%6 March 2009
CVE-2009-0766Directory traversal vulnerability in default.php in Kipper 2.01 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the configfile parameter.EXPLOIT ✓HIGH 7.5EPSS 2.36%6 March 2009
CVE-2009-0765Directory traversal vulnerability in index.php in Kipper 2.01 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.35%6 March 2009
CVE-2009-0764Multiple cross-site scripting (XSS) vulnerabilities in Kipper 2.01 allow remote attackers to inject arbitrary web script or HTML via the charm parameter to (1) index.php and (2) kipper.php.EXPLOIT ✓MEDIUM 4.3EPSS 1.20%6 March 2009
CVE-2009-0763Cross-site scripting (XSS) vulnerability in default.php in Kipper 2.01 allows remote attackers to inject arbitrary web script or HTML via the charm parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.48%6 March 2009
CVE-2009-0761Cross-site scripting (XSS) vulnerability in online.asp in Team Board 1.x allows remote attackers to inject arbitrary web script or HTML via the lookname parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.23%6 March 2009
CVE-2009-0760Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for data/team.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.46%6 March 2009
CVE-2009-0833Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute arbitrary code via a playlist (.pls) file with a long URL in the File1 field.EXPLOIT ✓HIGH 9.3EPSS 9.30%5 March 2009
CVE-2009-0832SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the CA parameter.EXPLOIT ✓HIGH 7.5EPSS 1.13%5 March 2009
CVE-2009-0831SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the sortby parameter.EXPLOIT ✓MEDIUM 6.0EPSS 0.94%5 March 2009
CVE-2009-0829Multiple SQL injection vulnerabilities in QuoteBook allow remote attackers to execute arbitrary SQL commands via the (1) MyBox and (2) selectFavorites parameters to (a) quotes.php and the (3) QuoteName and (4) QuoteText parameters to (b) quotesadd.php.EXPLOIT ✓HIGH 7.5EPSS 0.91%5 March 2009
CVE-2009-0828QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information, including user credentials, via a direct request.EXPLOIT ✓MEDIUM 5.0EPSS 2.87%5 March 2009
CVE-2009-0827PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request.EXPLOIT ✓MEDIUM 5.0EPSS 2.51%5 March 2009
CVE-2009-0826BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request.EXPLOIT ✓MEDIUM 5.0EPSS 2.62%5 March 2009
CVE-2009-0821Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print function, as demonstrated by a window.print(window.print()) in the onclick attribute of an INPUT element.EXPLOIT ✓MEDIUM 5.0EPSS 5.29%5 March 2009
CVE-2009-0820Multiple eval injection vulnerabilities in phpScheduleIt before 1.2.11 allow remote attackers to execute arbitrary code via (1) the end_date parameter to reserve.php and (2) the start_date and end_date parameters to check.php.EXPLOIT ✓HIGH 7.5EPSS 4.95%5 March 2009
CVE-2009-0819sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML()," which…EXPLOIT ✓MEDIUM 4.0EPSS 10.2%5 March 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.