SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-25 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,149 CVEs1,726 in CISA KEV17,253 with EPSS ≥ 10%25,049 with a public exploitUpdated 25 September 2026

25,049 results · page 257 of 501

CVESummaryPriorityPublished
CVE-2008-5988SQL injection vulnerability in scripts/recruit_details.php in Jadu CMS for Government allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.10%28 January 2009
CVE-2007-2795Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long…EXPLOIT ✓HIGH 9.0EPSS 24.5%27 January 2009
CVE-2009-0304The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial of service (system crash) via a crafted IPv6 packet, related to an "insufficient validation security vulnerability," as demonstrated…EXPLOIT ✓HIGH 7.8EPSS 9.80%27 January 2009
CVE-2009-0302SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arbitrary SQL commands via the url parameter in the Add operation to modules.php.EXPLOIT ×2 ✓MEDIUM 4.6EPSS 1.46%27 January 2009
CVE-2009-0301Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.6.9 allow remote attackers to create and overwrite arbitrary files via the (1) SaveFile and (2) ExportToXML methods.EXPLOIT ✓MEDIUM 6.8EPSS 1.96%27 January 2009
CVE-2009-0300Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOIT ✓UnscoredEPSS —27 January 2009
CVE-2009-0299SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.03%27 January 2009
CVE-2009-0298Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allows remote attackers to execute arbitrary code via a long Supplement property.EXPLOIT ✓HIGH 9.3EPSS 5.59%27 January 2009
CVE-2009-0297SQL injection vulnerability in login_check.asp in ClickAuction allows remote attackers to execute arbitrary SQL commands via the (1) txtEmail and (2) txtPassword parameters.EXPLOIT ✓HIGH 7.5EPSS 2.08%27 January 2009
CVE-2009-0296SQL injection vulnerability in shop_display_products.php in Script Toko Online 5.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%27 January 2009
CVE-2009-0295SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.93%27 January 2009
CVE-2009-0294Multiple PHP remote file inclusion vulnerabilities in WB News 2.0.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the config[installdir] parameter to (1) search.php, (2) archive.php, (3)…EXPLOIT ✓MEDIUM 6.8EPSS 1.82%27 January 2009
CVE-2009-0293SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the userid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%27 January 2009
CVE-2009-0292SQL injection vulnerability in show_cat2.php in SHOP-INET 4 allows remote attackers to execute arbitrary SQL commands via the grid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%27 January 2009
CVE-2009-0291Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary files via a ..EXPLOIT ×2 ✓HIGH 7.5EPSS 7.04%27 January 2009
CVE-2009-0290Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 3.30%27 January 2009
CVE-2009-0286Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a ..EXPLOIT ✓LOW 2.6EPSS 5.56%27 January 2009
CVE-2009-0285Cross-site scripting (XSS) vulnerability in error.asp in BBSXP 5.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%27 January 2009
CVE-2009-0284SQL injection vulnerability in category.php in Flax Article Manager 1.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%27 January 2009
CVE-2009-0283Cross-site scripting (XSS) vulnerability in err.asp in Oblog allows remote attackers to inject arbitrary web script or HTML via the message parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%27 January 2009
CVE-2009-0281SQL injection vulnerability in login.aspx in WarHound Walking Club allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.EXPLOIT ✓HIGH 7.5EPSS 1.13%27 January 2009
CVE-2009-0280Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1.EXPLOIT ✓HIGH 7.5EPSS 2.77%27 January 2009
CVE-2009-0279SQL injection vulnerability in comentar.php in Pardal CMS 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.13%27 January 2009
CVE-2008-5981PacPoll 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) poll.mdb or (2) poll97.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.45%27 January 2009
CVE-2008-5980Ocean12 Mailing List Manager Gold stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for o12mail.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.84%27 January 2009
CVE-2008-5979Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Mailing List Manager Gold allows remote attackers to inject arbitrary web script or HTML via the Email parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.68%27 January 2009
CVE-2008-5978Multiple SQL injection vulnerabilities in Ocean12 Mailing List Manager Gold allow remote attackers to execute arbitrary SQL commands via the Email parameter to (1) default.asp and (2) s_edit.asp.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.14%27 January 2009
CVE-2008-5977SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the adname parameter in a Submit action.EXPLOIT ✓HIGH 7.5EPSS 0.97%27 January 2009
CVE-2008-5976Multiple cross-site scripting (XSS) vulnerabilities in siteadmin/forgot.php in PHP JOBWEBSITE PRO allow remote attackers to inject arbitrary web script or HTML via (1) the adname parameter in a Submit action or (2) the UserName field.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%27 January 2009
CVE-2008-5975SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the linkid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.96%27 January 2009
CVE-2008-5974Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) username fields.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.02%27 January 2009
CVE-2008-5973SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%27 January 2009
CVE-2008-5972SQL injection vulnerability in default.asp in Active Business Directory 2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%27 January 2009
CVE-2008-5971Cross-site scripting (XSS) vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to inject arbitrary web script or HTML via the id parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%27 January 2009
CVE-2008-5970SQL injection vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓MEDIUM 6.5EPSS 0.85%27 January 2009
CVE-2008-5969SQL injection vulnerability in popupproduct.php in Sunbyte e-Flower allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 2.00%27 January 2009
CVE-2009-0275Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/header via the header parameter.EXPLOIT ✓MEDIUM 6.5EPSS 4.53%26 January 2009
CVE-2008-5968Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.92%26 January 2009
CVE-2008-5967admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory…EXPLOIT ✓HIGH 7.5EPSS 3.33%26 January 2009
CVE-2008-5966globsy_edit.php in Globsy 1.0 and earlier allows remote attackers to create or overwrite arbitrary files via a filename in the file parameter and file contents in the data parameter.EXPLOIT ✓HIGH 7.5EPSS 2.29%26 January 2009
CVE-2008-5965Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to check for the existence of arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 6.42%26 January 2009
CVE-2009-0266Stack-based buffer overflow in Triologic Media Player 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3l playlist file.EXPLOIT ✓HIGH 9.3EPSS 4.48%26 January 2009
CVE-2009-0263Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a large Common Chunk (COMM) header value in an AIFF file and (2) a large invalid value in an MP3 file.EXPLOIT ✓HIGH 10.0EPSS 16.7%23 January 2009
CVE-2009-0262Stack-based buffer overflow in Triologic Media Player 7 and 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3u playlist file.EXPLOIT ✓HIGH 9.3EPSS 6.19%23 January 2009
CVE-2009-0261Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary code via a Skins\DefaultSkin\DefaultSkin.ini file with a large ColumnHeaderSpan value.EXPLOIT ✓HIGH 9.3EPSS 13.2%23 January 2009
CVE-2009-0260Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitrary web script or HTML via an AttachFile action to the WikiSandBox component with (1) the rename parameter or (2)…EXPLOIT ✓MEDIUM 4.3EPSS 5.48%23 January 2009
CVE-2008-5963Eval injection vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remote attackers to execute arbitrary PHP code via the objectname parameter.EXPLOIT ✓HIGH 10.0EPSS 3.40%23 January 2009
CVE-2008-5962Directory traversal vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.86%23 January 2009
CVE-2008-5959Multiple SQL injection vulnerabilities in start.asp in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) useremail parameter (aka username field) or (2) password parameter (aka password field).EXPLOIT ✓HIGH 7.5EPSS 1.01%23 January 2009
CVE-2008-5958Multiple SQL injection vulnerabilities in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter to (1) questions.asp, (2) importquestions.asp, and (3) quiztakers.asp.EXPLOIT ✓HIGH 7.5EPSS 1.75%23 January 2009

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.