Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,020 CVEs1,726 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 248 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-6354 | The Net Guys ASPired2poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to ASPired2poll.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.33% | 2 March 2009 |
| CVE-2008-6353 | SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the cha parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 2 March 2009 |
| CVE-2008-6352 | SQL injection vulnerability in home.html in Xpoze Pro 4.10 allows remote attackers to execute arbitrary SQL commands via the menu parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 2 March 2009 |
| CVE-2008-6351 | Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to inject arbitrary web script or HTML via the r parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 2 March 2009 |
| CVE-2008-6350 | SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitrary SQL commands via the r parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 2 March 2009 |
| CVE-2008-6349 | SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 2 March 2009 |
| CVE-2008-6348 | Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to gallery_category.php, (2) photo_id parameter to gallery_photo.php, and the (3) user_name… | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 2 March 2009 |
| CVE-2008-6347 | PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 19.9% | 2 March 2009 |
| CVE-2009-0746 | The make_indexed_dir function in fs/ext4/namei.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not validate a certain rec_len field, which allows local users to cause a denial of service (OOPS) by attempting to mount a… | EXPLOIT ✓MEDIUM 4.9EPSS 0.75% | 27 February 2009 |
| CVE-2009-0744 | Apple Safari 4 Beta build 528.16 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a feeds: URI beginning with a (1) % (percent), (2) { (open curly bracket), (3) } (close curly bracket), (4) ^… | EXPLOIT ✓MEDIUM 5.0EPSS 6.65% | 27 February 2009 |
| CVE-2009-0028 | The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting this… | EXPLOIT ✓LOW 2.1EPSS 0.70% | 27 February 2009 |
| CVE-2008-6345 | SQL injection vulnerability in Forum.php in SolarCMS 0.53.8 and 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to indes.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 27 February 2009 |
| CVE-2008-6337 | SQL injection vulnerability in the Volunteer Management System (com_volunteer) module 2.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the job_id parameter in a jobshow action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 27 February 2009 |
| CVE-2008-6336 | Directory traversal vulnerability in download.php in Text Lines Rearrange Script 1.0, when register_globals is enabled, allows remote attackers to read arbitrary local files via directory traversal sequences in the filename parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.20% | 27 February 2009 |
| CVE-2008-6335 | Directory traversal vulnerability in download.php in eMetrix Online Keyword Research Tool allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 2.76% | 27 February 2009 |
| CVE-2008-6334 | Directory traversal vulnerability in download.php in eMetrix Extract Website allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 2.76% | 27 February 2009 |
| CVE-2008-6333 | SQL injection vulnerability in news.php in RSS Simple News (RSSSN), when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the pid parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.85% | 27 February 2009 |
| CVE-2008-6332 | SQL injection vulnerability in login.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL commands via the password parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 27 February 2009 |
| CVE-2008-6330 | SQL injection vulnerability in index.php in MyTopix 1.3.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the send parameter in a notes action. | EXPLOIT ✓MEDIUM 6.5EPSS 0.88% | 27 February 2009 |
| CVE-2008-6329 | SQL injection vulnerability in Employee/login.asp in Pre ASP Job Board allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password parameters, as reachable from Employee/emp_login.asp. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 27 February 2009 |
| CVE-2008-6328 | SQL injection vulnerability in view.php in Butterfly Organizer 2.0.0 and 2.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.02% | 27 February 2009 |
| CVE-2008-6327 | SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via the password parameter, a different vector than CVE-2008-6312. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 27 February 2009 |
| CVE-2008-6326 | SQL injection vulnerability in login.php in Simple Customer as downloaded on 20081118 allows remote attackers to execute arbitrary SQL commands via the email parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 27 February 2009 |
| CVE-2008-6325 | Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) radio parameter to showcategory.php, (2) msg parameter to advertisers/signinform.php, (3) radio… | EXPLOIT ×6 ✓MEDIUM 4.3EPSS 1.49% | 27 February 2009 |
| CVE-2008-6324 | SQL injection vulnerability in forummessages.cfm in CF_Forum allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 27 February 2009 |
| CVE-2008-6323 | SQL injection vulnerability in forummessages.cfm in CFMSource CF_Auction allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 27 February 2009 |
| CVE-2008-6322 | SQL injection vulnerability in index.cfm in CFMSource CFMBlog allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 27 February 2009 |
| CVE-2008-6321 | CF Shopkart 5.2.2 stores cfshopkart52.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information, such as usernames and passwords, via a direct request. | EXPLOIT ✓MEDIUM 5.0EPSS 2.23% | 27 February 2009 |
| CVE-2008-6320 | SQL injection vulnerability in index.cfm in CF Shopkart 5.2.2 allows remote attackers to execute arbitrary SQL commands via the Category parameter in a ViewCategory action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 27 February 2009 |
| CVE-2008-6319 | SQL injection vulnerability in calendarevent.cfm in CF_Calendar allows remote attackers to execute arbitrary SQL commands via the calid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 27 February 2009 |
| CVE-2008-6318 | PHP remote file inclusion vulnerability in _conf/_php-core/common-tpl-vars.php in PHPmyGallery 1.5 beta allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter, a different vector than CVE-2008-6317. | EXPLOIT ✓HIGH 7.5EPSS 2.05% | 27 February 2009 |
| CVE-2008-6317 | Directory traversal vulnerability in _conf/_php-core/common-tpl-vars.php in PHPmyGallery 1.5 beta allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.97% | 27 February 2009 |
| CVE-2008-6316 | Directory traversal vulnerability in _conf/core/common-tpl-vars.php in PHPmyGallery 1.0 beta2 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.97% | 27 February 2009 |
| CVE-2008-6315 | PHP remote file inclusion vulnerability in _conf/core/common-tpl-vars.php in PHPmyGallery 1.0 beta2 allows remote attackers to execute arbitrary PHP code via a URL in the confdir parameter, a different issue than CVE-2008-6316. | EXPLOIT ✓HIGH 7.5EPSS 2.05% | 27 February 2009 |
| CVE-2008-6314 | SQL injection vulnerability in tag_board.php in the Tag Board module 4.0 and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 27 February 2009 |
| CVE-2008-6313 | Directory traversal vulnerability in addedit-render.php in phpAddEdit 1.3, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a URL in the editform parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.97% | 27 February 2009 |
| CVE-2008-6312 | SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.10% | 27 February 2009 |
| CVE-2008-6311 | SQL injection vulnerability in view.php in Butterfly Organizer 2.0.1 allows remote attackers to execute arbitrary SQL commands via the mytable parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.15% | 27 February 2009 |
| CVE-2008-6310 | SQL injection vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.03% | 27 February 2009 |
| CVE-2008-6309 | SQL injection vulnerability in index.php in W3matter AskPert allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.03% | 27 February 2009 |
| CVE-2008-6308 | Multiple directory traversal vulnerabilities in Private Messaging System (PMS) 1.2.3 and earlier for PunBB allow remote attackers to include and execute arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.1EPSS 2.04% | 27 February 2009 |
| CVE-2008-6307 | E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "admin." | EXPLOIT ✓HIGH 7.5EPSS 2.59% | 26 February 2009 |
| CVE-2008-6306 | Cross-site scripting (XSS) vulnerability in signinform.php in Softbiz Classifieds Script allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 26 February 2009 |
| CVE-2008-6305 | PHP remote file inclusion vulnerability in init.php in Free Directory Script 1.1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the API_HOME_DIR parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.82% | 26 February 2009 |
| CVE-2008-6303 | SQL injection vulnerability in tourview.php in ToursManager allows remote attackers to execute arbitrary SQL commands via the tourid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 26 February 2009 |
| CVE-2008-6302 | TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_Admin/admin.php. | EXPLOIT ✓HIGH 7.5EPSS 2.57% | 26 February 2009 |
| CVE-2009-0520 | Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a… | EXPLOIT ✓HIGH 9.3EPSS 28.5% | 26 February 2009 |
| CVE-2009-0187 | Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote attackers to execute arbitrary code via a crafted HTTP URL with a long host name, which is not properly handled when constructing a… | EXPLOIT ×2 ✓HIGH 9.3EPSS 40.0% | 26 February 2009 |
| CVE-2008-6301 | SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 26 February 2009 |
| CVE-2008-6300 | Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass cookies to admin. | EXPLOIT ✓HIGH 7.5EPSS 2.62% | 26 February 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.