Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,020 CVEs1,726 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026
25,049 results · page 249 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-6297 | Cross-site scripting (XSS) vulnerability in order.php in DHCart allows remote attackers to inject arbitrary web script or HTML via the (1) domain and (2) d1 parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.46% | 26 February 2009 |
| CVE-2008-6296 | admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "demo." | EXPLOIT ✓HIGH 7.5EPSS 2.50% | 26 February 2009 |
| CVE-2008-6294 | admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie cookie to "admin." | EXPLOIT ×3 ✓HIGH 7.5EPSS 2.74% | 26 February 2009 |
| CVE-2008-6293 | admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie to "admin." | EXPLOIT ×3 ✓HIGH 7.5EPSS 2.74% | 26 February 2009 |
| CVE-2008-6292 | Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) username_cookie to "admin," (2) right_cookie to "1," and (3) id_cookie to "1." | EXPLOIT ×3 ✓HIGH 7.5EPSS 2.74% | 26 February 2009 |
| CVE-2008-6291 | Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLETTERLOGIN cookie to "admin". | EXPLOIT ✓HIGH 7.5EPSS 2.45% | 26 February 2009 |
| CVE-2008-6290 | Directory traversal vulnerability in includefile.php in nicLOR Sito, when register_globals is enabled or magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.93% | 26 February 2009 |
| CVE-2008-6289 | SQL injection vulnerability in cityview.php in Tours Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the cityid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 26 February 2009 |
| CVE-2008-6288 | Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and earlier allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 2.76% | 25 February 2009 |
| CVE-2008-6287 | Multiple PHP remote file inclusion vulnerabilities in Broadcast Machine 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) MySQLController.php, (2) SQLController.php, (3) SetupController.php, (4)… | EXPLOIT ✓HIGH 7.5EPSS 2.31% | 25 February 2009 |
| CVE-2008-6286 | Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail field), or (2) the password parameter (aka password… | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 25 February 2009 |
| CVE-2008-6285 | SQL injection vulnerability in index.php in PHP TV Portal 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the mid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 25 February 2009 |
| CVE-2008-6284 | SQL injection vulnerability in edit.php in Z1Exchange 1.0 allows remote attackers to execute arbitrary SQL commands via the site parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 25 February 2009 |
| CVE-2008-6282 | SQL injection vulnerability in engine/users/users_edit_pub.inc in CMS Ortus 1.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the city parameter in a users_edit_pub action to index.php. | EXPLOIT ✓MEDIUM 6.5EPSS 2.07% | 25 February 2009 |
| CVE-2008-6281 | SQL injection vulnerability in index.php in Bluo CMS 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 25 February 2009 |
| CVE-2008-6280 | Cross-site scripting (XSS) vulnerability in apply.cgi on the Linksys WRT160N allows remote attackers to inject arbitrary web script or HTML via the action parameter in a DHCP_Static operation. | EXPLOIT ✓MEDIUM 4.3EPSS 6.90% | 25 February 2009 |
| CVE-2008-6279 | RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to obtain sensitive information via an invalid PHPSESSID cookie, which reveals the installation path in an error message. | EXPLOIT ✓HIGH 7.8EPSS 2.52% | 25 February 2009 |
| CVE-2008-6278 | Multiple cross-site scripting (XSS) vulnerabilities in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allow remote attackers to inject arbitrary web script or HTML via the (1) category_id and (2) subcategory_id parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 25 February 2009 |
| CVE-2008-6277 | SQL injection vulnerability in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to execute arbitrary SQL commands via the subcategory_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 25 February 2009 |
| CVE-2008-6274 | Multiple SQL injection vulnerabilities in index.php in FamilyProject 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the logmbr parameter (aka login field) or (2) the mdpmbr parameter (aka pass or "Mot de passe" field). | EXPLOIT ✓MEDIUM 6.8EPSS 0.98% | 25 February 2009 |
| CVE-2009-0741 | SQL injection vulnerability in Login.asp in Craft Silicon Banking@Home 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginName parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 25 February 2009 |
| CVE-2009-0740 | SQL injection vulnerability in login.php in BlueBird Prelease allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.08% | 25 February 2009 |
| CVE-2009-0739 | SQL injection vulnerability in login.php in MyNews 0.10 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.08% | 25 February 2009 |
| CVE-2009-0738 | SQL injection vulnerability in login.php in Auth Php 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.14% | 25 February 2009 |
| CVE-2009-0735 | Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read and possibly execute arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.1EPSS 2.15% | 25 February 2009 |
| CVE-2009-0734 | Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file. | EXPLOIT ✓HIGH 9.3EPSS 5.13% | 25 February 2009 |
| CVE-2009-0541 | Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the username field in an admin/ request to index.php, possibly related to the login[username]… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.81% | 25 February 2009 |
| CVE-2008-6272 | SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execute arbitrary SQL command via the pass parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 25 February 2009 |
| CVE-2008-6271 | Directory traversal vulnerability in index.php in TBmnetCMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.86% | 25 February 2009 |
| CVE-2008-6270 | SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execute arbitrary SQL command via the user parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 25 February 2009 |
| CVE-2008-6269 | Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) session_id, session_logged_in, and session_username cookies for user privileges; (2) session_admin_id,… | EXPLOIT ✓HIGH 7.5EPSS 2.59% | 25 February 2009 |
| CVE-2008-6268 | SQL injection vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 25 February 2009 |
| CVE-2008-6267 | Cross-site scripting (XSS) vulnerability in detail.php in Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script or HTML via the name parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 25 February 2009 |
| CVE-2008-6266 | SQL injection vulnerability in links.php in Appalachian State University phpWebSite allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewlink action. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 25 February 2009 |
| CVE-2009-0731 | Directory traversal vulnerability in pages/play.php in Free Arcade Script 1.0 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 9.3EPSS 5.63% | 24 February 2009 |
| CVE-2009-0730 | Multiple SQL injection vulnerabilities in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the gigcal _venues_id parameter in a details… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.09% | 24 February 2009 |
| CVE-2009-0728 | SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showpic action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 24 February 2009 |
| CVE-2009-0727 | SQL injection vulnerability in jobdetails.php in taifajobs 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the jobid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 24 February 2009 |
| CVE-2009-0726 | SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the gigcal_gigs_id parameter in a details action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.03% | 24 February 2009 |
| CVE-2009-0722 | Directory traversal vulnerability in admin.php in Potato News 1.0.0 allows remote attackers to include and execute arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.30% | 24 February 2009 |
| CVE-2008-6265 | Directory traversal vulnerability in portfolio/css.php in Cyberfolio 7.12.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.86% | 24 February 2009 |
| CVE-2008-6264 | SQL injection vulnerability in admin/admin.php in E-topbiz Slide Popups 1.0 allows remote attackers to execute arbitrary SQL commands via the password parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 24 February 2009 |
| CVE-2008-6263 | SQL injection vulnerability in lib/user/t_user.php in SaturnCMS allows remote attackers to execute arbitrary SQL commands via the username parameter to the _userLoggedIn function. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 24 February 2009 |
| CVE-2008-6262 | SQL injection vulnerability in lib/url/meta_url.php in SaturnCMS allows remote attackers to execute arbitrary SQL commands via the URL to the translate function. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 24 February 2009 |
| CVE-2008-6261 | SQL injection vulnerability in view.php in E-topbiz AdManager 4 allows remote attackers to execute arbitrary SQL commands via the group parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 24 February 2009 |
| CVE-2008-6260 | SQL injection vulnerability in index.php in Ultrastats 0.2.144 and 0.3.11 allows remote attackers to execute arbitrary SQL commands via the serverid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 24 February 2009 |
| CVE-2008-6259 | Cross-site scripting (XSS) vulnerability in search.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the srkeys parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.61% | 24 February 2009 |
| CVE-2008-6258 | SQL injection vulnerability in users.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the (1) UserID and (2) Pwd parameters. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 24 February 2009 |
| CVE-2008-6257 | SQL injection vulnerability in default.asp in Openasp 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idpage parameter in the pages module. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 24 February 2009 |
| CVE-2008-6254 | SQL injection vulnerability in scripts/documents.php in Jadu Galaxies allows remote attackers to execute arbitrary SQL commands via the categoryID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 24 February 2009 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.