SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,020 CVEs1,726 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 249 of 501

CVESummaryPriorityPublished
CVE-2008-6297Cross-site scripting (XSS) vulnerability in order.php in DHCart allows remote attackers to inject arbitrary web script or HTML via the (1) domain and (2) d1 parameters.EXPLOIT ✓MEDIUM 4.3EPSS 1.46%26 February 2009
CVE-2008-6296admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "demo."EXPLOIT ✓HIGH 7.5EPSS 2.50%26 February 2009
CVE-2008-6294admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie cookie to "admin."EXPLOIT ×3 ✓HIGH 7.5EPSS 2.74%26 February 2009
CVE-2008-6293admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie to "admin."EXPLOIT ×3 ✓HIGH 7.5EPSS 2.74%26 February 2009
CVE-2008-6292Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) username_cookie to "admin," (2) right_cookie to "1," and (3) id_cookie to "1."EXPLOIT ×3 ✓HIGH 7.5EPSS 2.74%26 February 2009
CVE-2008-6291Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLETTERLOGIN cookie to "admin".EXPLOIT ✓HIGH 7.5EPSS 2.45%26 February 2009
CVE-2008-6290Directory traversal vulnerability in includefile.php in nicLOR Sito, when register_globals is enabled or magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.93%26 February 2009
CVE-2008-6289SQL injection vulnerability in cityview.php in Tours Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the cityid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%26 February 2009
CVE-2008-6288Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and earlier allows remote attackers to read arbitrary files via a ..EXPLOIT ✓HIGH 7.8EPSS 2.76%25 February 2009
CVE-2008-6287Multiple PHP remote file inclusion vulnerabilities in Broadcast Machine 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) MySQLController.php, (2) SQLController.php, (3) SetupController.php, (4)…EXPLOIT ✓HIGH 7.5EPSS 2.31%25 February 2009
CVE-2008-6286Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail field), or (2) the password parameter (aka password…EXPLOIT ✓HIGH 7.5EPSS 1.00%25 February 2009
CVE-2008-6285SQL injection vulnerability in index.php in PHP TV Portal 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the mid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%25 February 2009
CVE-2008-6284SQL injection vulnerability in edit.php in Z1Exchange 1.0 allows remote attackers to execute arbitrary SQL commands via the site parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%25 February 2009
CVE-2008-6282SQL injection vulnerability in engine/users/users_edit_pub.inc in CMS Ortus 1.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the city parameter in a users_edit_pub action to index.php.EXPLOIT ✓MEDIUM 6.5EPSS 2.07%25 February 2009
CVE-2008-6281SQL injection vulnerability in index.php in Bluo CMS 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%25 February 2009
CVE-2008-6280Cross-site scripting (XSS) vulnerability in apply.cgi on the Linksys WRT160N allows remote attackers to inject arbitrary web script or HTML via the action parameter in a DHCP_Static operation.EXPLOIT ✓MEDIUM 4.3EPSS 6.90%25 February 2009
CVE-2008-6279RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to obtain sensitive information via an invalid PHPSESSID cookie, which reveals the installation path in an error message.EXPLOIT ✓HIGH 7.8EPSS 2.52%25 February 2009
CVE-2008-6278Multiple cross-site scripting (XSS) vulnerabilities in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allow remote attackers to inject arbitrary web script or HTML via the (1) category_id and (2) subcategory_id parameters.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%25 February 2009
CVE-2008-6277SQL injection vulnerability in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to execute arbitrary SQL commands via the subcategory_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%25 February 2009
CVE-2008-6274Multiple SQL injection vulnerabilities in index.php in FamilyProject 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the logmbr parameter (aka login field) or (2) the mdpmbr parameter (aka pass or "Mot de passe" field).EXPLOIT ✓MEDIUM 6.8EPSS 0.98%25 February 2009
CVE-2009-0741SQL injection vulnerability in Login.asp in Craft Silicon Banking@Home 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginName parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%25 February 2009
CVE-2009-0740SQL injection vulnerability in login.php in BlueBird Prelease allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.EXPLOIT ✓HIGH 7.5EPSS 1.08%25 February 2009
CVE-2009-0739SQL injection vulnerability in login.php in MyNews 0.10 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.EXPLOIT ✓HIGH 7.5EPSS 1.08%25 February 2009
CVE-2009-0738SQL injection vulnerability in login.php in Auth Php 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.EXPLOIT ✓HIGH 7.5EPSS 1.14%25 February 2009
CVE-2009-0735Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read and possibly execute arbitrary files via a ..EXPLOIT ✓MEDIUM 5.1EPSS 2.15%25 February 2009
CVE-2009-0734Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file.EXPLOIT ✓HIGH 9.3EPSS 5.13%25 February 2009
CVE-2009-0541Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the username field in an admin/ request to index.php, possibly related to the login[username]…EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.81%25 February 2009
CVE-2008-6272SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execute arbitrary SQL command via the pass parameter.EXPLOIT ✓HIGH 7.5EPSS 0.95%25 February 2009
CVE-2008-6271Directory traversal vulnerability in index.php in TBmnetCMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.86%25 February 2009
CVE-2008-6270SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execute arbitrary SQL command via the user parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%25 February 2009
CVE-2008-6269Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) session_id, session_logged_in, and session_username cookies for user privileges; (2) session_admin_id,…EXPLOIT ✓HIGH 7.5EPSS 2.59%25 February 2009
CVE-2008-6268SQL injection vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%25 February 2009
CVE-2008-6267Cross-site scripting (XSS) vulnerability in detail.php in Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script or HTML via the name parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.47%25 February 2009
CVE-2008-6266SQL injection vulnerability in links.php in Appalachian State University phpWebSite allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewlink action.EXPLOIT ✓HIGH 7.5EPSS 0.96%25 February 2009
CVE-2009-0731Directory traversal vulnerability in pages/play.php in Free Arcade Script 1.0 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 9.3EPSS 5.63%24 February 2009
CVE-2009-0730Multiple SQL injection vulnerabilities in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the gigcal _venues_id parameter in a details…EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.09%24 February 2009
CVE-2009-0728SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showpic action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.95%24 February 2009
CVE-2009-0727SQL injection vulnerability in jobdetails.php in taifajobs 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the jobid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.02%24 February 2009
CVE-2009-0726SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the gigcal_gigs_id parameter in a details action to index.php.EXPLOIT ✓HIGH 7.5EPSS 2.03%24 February 2009
CVE-2009-0722Directory traversal vulnerability in admin.php in Potato News 1.0.0 allows remote attackers to include and execute arbitrary files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.30%24 February 2009
CVE-2008-6265Directory traversal vulnerability in portfolio/css.php in Cyberfolio 7.12.2 and earlier allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.86%24 February 2009
CVE-2008-6264SQL injection vulnerability in admin/admin.php in E-topbiz Slide Popups 1.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%24 February 2009
CVE-2008-6263SQL injection vulnerability in lib/user/t_user.php in SaturnCMS allows remote attackers to execute arbitrary SQL commands via the username parameter to the _userLoggedIn function.EXPLOIT ✓HIGH 7.5EPSS 1.00%24 February 2009
CVE-2008-6262SQL injection vulnerability in lib/url/meta_url.php in SaturnCMS allows remote attackers to execute arbitrary SQL commands via the URL to the translate function.EXPLOIT ✓HIGH 7.5EPSS 0.91%24 February 2009
CVE-2008-6261SQL injection vulnerability in view.php in E-topbiz AdManager 4 allows remote attackers to execute arbitrary SQL commands via the group parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%24 February 2009
CVE-2008-6260SQL injection vulnerability in index.php in Ultrastats 0.2.144 and 0.3.11 allows remote attackers to execute arbitrary SQL commands via the serverid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%24 February 2009
CVE-2008-6259Cross-site scripting (XSS) vulnerability in search.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the srkeys parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.61%24 February 2009
CVE-2008-6258SQL injection vulnerability in users.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the (1) UserID and (2) Pwd parameters.EXPLOIT ✓HIGH 7.5EPSS 0.97%24 February 2009
CVE-2008-6257SQL injection vulnerability in default.asp in Openasp 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idpage parameter in the pages module.EXPLOIT ✓HIGH 7.5EPSS 0.97%24 February 2009
CVE-2008-6254SQL injection vulnerability in scripts/documents.php in Jadu Galaxies allows remote attackers to execute arbitrary SQL commands via the categoryID parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%24 February 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.