SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,401 CVEs1,726 in CISA KEV17,261 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 260 of 501

CVESummaryPriorityPublished
CVE-2008-5873Yerba SACphp 6.3 and earlier allows remote attackers to bypass authentication and gain administrative access via a galleta[sesion] cookie that has a value beginning with 1:1: followed by a username.EXPLOIT ✓HIGH 7.5EPSS 2.65%8 January 2009
CVE-2008-5870FastStone Image Viewer 3.6 allows user-assisted attackers to cause a denial of service (application crash) via a malformed BMP image with large width and height values, possibly a related issue to CVE-2007-1942.EXPLOIT ✓MEDIUM 4.3EPSS 2.10%8 January 2009
CVE-2008-5869Cross-site scripting (XSS) vulnerability in the Proxim Wireless Tsunami MP.11 2411 with firmware 3.0.3 allows remote authenticated users to inject arbitrary web script or HTML via the system.sysName.0 SNMP OID.EXPLOIT ✓MEDIUM 4.3EPSS 1.49%8 January 2009
CVE-2008-5868Stack-based buffer overflow in IntelliTamper 2.07 and 2.08 allows user-assisted attackers to execute arbitrary code via a long ProxyLogin value in a configuration (.cfg) file.EXPLOIT ✓HIGH 9.3EPSS 3.86%8 January 2009
CVE-2009-0065Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.28-git8 allows remote attackers to have an unknown impact via an FWD-TSN (aka FORWARD-TSN) chunk with a large…EXPLOIT ✓HIGH 10.0EPSS 16.7%7 January 2009
CVE-2008-5865SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the r_type parameter in a showhoteldetails action to…EXPLOIT ×4 ✓HIGH 7.5EPSS 1.01%6 January 2009
CVE-2008-5864SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails…EXPLOIT ×4 ✓HIGH 7.5EPSS 2.01%6 January 2009
CVE-2008-5863SQL injection vulnerability in locator.php in the Userlocator module 3.0 for Woltlab Burning Board (wBB) allows remote attackers to execute arbitrary SQL commands via the y parameter in a get_user action.EXPLOIT ✓HIGH 7.5EPSS 0.97%6 January 2009
CVE-2008-5862Directory traversal vulnerability in webcamXP 5.3.2.375 and 5.3.2.410 build 2132 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the URI.EXPLOIT ✓MEDIUM 5.0EPSS 5.91%6 January 2009
CVE-2008-5861Directory traversal vulnerability in source.php in FreeLyrics 1.0 allows remote attackers to read arbitrary files via directory traversal sequences in the p parameter.EXPLOIT ✓MEDIUM 5.0EPSS 2.69%6 January 2009
CVE-2008-5860Directory traversal vulnerability in backend/template.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to create or read arbitrary files via directory traversal…EXPLOIT ✓MEDIUM 5.1EPSS 2.05%6 January 2009
CVE-2008-5859SQL injection vulnerability in index.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the show_page parameter.EXPLOIT ✓MEDIUM 5.1EPSS 0.92%6 January 2009
CVE-2008-5856Directory traversal vulnerability in scripts/export.php in ClaSS before 0.8.61 allows remote attackers to read arbitrary files via directory traversal sequences in the ftype parameter.EXPLOIT ✓MEDIUM 5.0EPSS 8.01%6 January 2009
CVE-2008-5855myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover usernames, e-mail addresses, and password hashes via a direct request for users.txt.EXPLOIT ✓MEDIUM 5.0EPSS 2.61%6 January 2009
CVE-2008-5854Multiple cross-site scripting (XSS) vulnerabilities in login.php in myPHPscripts Login Session 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) ls_user and (2) ls_email parameters (aka the User form) in an ls_register action.EXPLOIT ✓MEDIUM 4.3EPSS 1.57%6 January 2009
CVE-2008-5853Chilek Content Management System (aka ChiCoMaS) 2.0.4 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to (1) obtain database credentials via a direct request for config.inc or…EXPLOIT ✓MEDIUM 5.0EPSS 2.54%6 January 2009
CVE-2008-5852Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for guestbook.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.61%6 January 2009
CVE-2008-5851SQL injection vulnerability in index.php in My PHP Baseball Stats (MyPBS) allows remote attackers to execute arbitrary SQL commands via the seasonID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.99%6 January 2009
CVE-2008-5847Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.EXPLOIT ✓LOW 2.6EPSS 1.78%5 January 2009
CVE-2004-2761The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.EXPLOIT ✓CRITICAL 9.8EPSS 9.93%5 January 2009
CVE-2008-5841Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the browse parameter to (1) previews.php and (2) reviews.php, and the (3) id parameter to index.php in a viewarticle action.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.02%5 January 2009
CVE-2008-5840PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1.EXPLOIT ✓HIGH 7.5EPSS 3.02%5 January 2009
CVE-2008-5839Buffer overflow in Foxmail 6.5 allows remote attackers to execute arbitrary code via a long mailto URI in the HREF attribute of an A element.EXPLOIT ✓HIGH 9.3EPSS 5.57%5 January 2009
CVE-2008-5838SQL injection vulnerability in search_results.php in E-Php Scripts E-Shop (aka E-Php Shopping Cart) Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.15%5 January 2009
CVE-2008-5824Heap-based buffer overflow in msadpcm.c in libaudiofile in audiofile 0.2.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WAV file.EXPLOIT ✓MEDIUM 6.8EPSS 6.02%2 January 2009
CVE-2008-5821Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause a denial of service (memory consumption and browser crash) via a long ALINK attribute in a BODY element in an HTML document.EXPLOIT ×3 ✓MEDIUM 5.0EPSS 3.92%2 January 2009
CVE-2008-5820SQL injection vulnerability in eDNews_view.php in eDreamers eDNews 2 allows remote attackers to execute arbitrary SQL commands via the newsid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%2 January 2009
CVE-2008-5819Directory traversal vulnerability in eDNews_archive.php in eDreamers eDNews 2, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.93%2 January 2009
CVE-2008-5818Directory traversal vulnerability in index.php in eDreamers eDContainer 2.22, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.96%2 January 2009
CVE-2008-5817Multiple SQL injection vulnerabilities in index.php in Web Scribble Solutions webClassifieds 2005 allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) password fields in a sign_in action.EXPLOIT ✓MEDIUM 6.8EPSS 1.13%2 January 2009
CVE-2008-5816SQL injection vulnerability in repository.php in ILIAS 3.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ref_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.27%2 January 2009
CVE-2008-5815SQL injection vulnerability in Acomment.php in phpAlumni allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.99%2 January 2009
CVE-2008-5811SQL injection vulnerability in the PaxGallery (com_paxgallery) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gid parameter in a table action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.00%2 January 2009
CVE-2006-7236The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attackers to execute arbitrary code or have unspecified other impact via escape sequences.EXPLOIT ✓HIGH 9.3EPSS 7.47%2 January 2009
CVE-2008-5806SQL injection vulnerability in login.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka admin field).EXPLOIT ✓HIGH 7.5EPSS 1.15%31 December 2008
CVE-2008-5805SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the siteid parameter, a different vector than CVE-2006-5828.EXPLOIT ✓HIGH 7.5EPSS 1.00%31 December 2008
CVE-2008-5804SQL injection vulnerability in admin/admin_catalog.php in e-topbiz Number Links 1 Php Script allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action.EXPLOIT ✓HIGH 7.5EPSS 1.00%31 December 2008
CVE-2008-5803SQL injection vulnerability in admin/login.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka username field).EXPLOIT ✓HIGH 7.5EPSS 1.04%31 December 2008
CVE-2008-5802SQL injection vulnerability in index.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%31 December 2008
CVE-2008-5794Directory traversal vulnerability in system/admin/images.php in LoveCMS 1.6.2 Final allows remote attackers to delete arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.60%31 December 2008
CVE-2008-5793Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a)…EXPLOIT ✓MEDIUM 6.8EPSS 24.5%31 December 2008
CVE-2008-5792PHP remote file inclusion vulnerability in show_joined.php in Indiscripts Enthusiast 3.1.4, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.57%31 December 2008
CVE-2008-5790Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) add.php…EXPLOIT ✓HIGH 7.5EPSS 36.4%31 December 2008
CVE-2008-5789Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) mosConfig_absolute_path parameter to (a)…EXPLOIT ✓HIGH 7.5EPSS 45.0%31 December 2008
CVE-2008-5788SQL injection vulnerability in index.php in Domain Seller Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.15%31 December 2008
CVE-2008-5787Directory traversal vulnerability in mod.php in Arab Portal 2.1 on Windows allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.4EPSS 3.00%31 December 2008
CVE-2008-5785SQL injection vulnerability in V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.EXPLOIT ✓HIGH 7.5EPSS 1.00%31 December 2008
CVE-2008-5784V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.EXPLOIT ×2 ✓CRITICAL 9.8EPSS 7.10%31 December 2008
CVE-2008-5783admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.EXPLOIT ×2 ✓HIGH 7.5EPSS 3.37%31 December 2008
CVE-2008-5782SQL injection vulnerability in bannerclick.php in ZeeMatri 3.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.02%31 December 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.