SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,446 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 262 of 501

CVESummaryPriorityPublished
CVE-2008-5715Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long string value for the hash property (aka location.hash).EXPLOIT ✓MEDIUM 5.0EPSS 8.50%24 December 2008
CVE-2008-5713The __qdisc_run function in net/sched/sch_generic.c in the Linux kernel before 2.6.25 on SMP machines allows local users to cause a denial of service (soft lockup) by sending a large amount of network traffic, as demonstrated by multiple simultaneous…EXPLOIT ✓MEDIUM 4.9EPSS 0.74%24 December 2008
CVE-2008-5712The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COLOR attribute in an HR element; or a long (a) BGCOLOR or (b) BORDERCOLOR attribute in a (2) TABLE, (3) TD, or (4) TR element.EXPLOIT ×2 ✓MEDIUM 5.0EPSS 3.80%24 December 2008
CVE-2008-5711Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary code via a long FileMask property value.EXPLOIT ×3 ✓HIGH 9.3EPSS 32.7%24 December 2008
CVE-2008-5708redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1.EXPLOIT ✓HIGH 7.5EPSS 2.64%24 December 2008
CVE-2008-2382The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infinite loop) via a certain message.EXPLOIT ✓MEDIUM 5.0EPSS 6.62%24 December 2008
CVE-2008-5707SQL injection vulnerability in urunler.asp in Iltaweb Alisveris Sistemi allows remote attackers to execute arbitrary SQL commands via the catno parameter.EXPLOIT ✓HIGH 7.5EPSS 0.91%24 December 2008
CVE-2008-5706The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/trigger.tmp temporary file.EXPLOIT ✓MEDIUM 6.9EPSS 0.79%22 December 2008
CVE-2008-5705The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier, when user triggers are enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in an argument.EXPLOIT ✓HIGH 9.3EPSS 5.42%22 December 2008
CVE-2008-5698HTMLTokenizer::scriptHandler in Konqueror in KDE 3.5.9 and 3.5.10 allows remote attackers to cause a denial of service (application crash) via an invalid document.load call that triggers use of a deleted object.EXPLOIT ✓MEDIUM 4.3EPSS 3.49%22 December 2008
CVE-2008-5697The skype_tool.copy_num method in the Skype extension BETA 2.2.0.95 for Firefox allows remote attackers to write arbitrary data to the clipboard via a string argument.EXPLOIT ✓MEDIUM 4.3EPSS 2.17%22 December 2008
CVE-2008-5695wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary…EXPLOIT ✓HIGH 8.5EPSS 12.0%19 December 2008
CVE-2008-5692Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with…EXPLOIT ✓MEDIUM 5.0EPSS 12.6%19 December 2008
CVE-2008-5691Heap-based buffer overflow in the Phoenician Casino FlashAX ActiveX control 1.0.0.7 allows remote attackers to execute arbitrary code via a long argument to the SetID method.EXPLOIT ✓HIGH 9.3EPSS 9.73%19 December 2008
CVE-2008-5689tun in IP Tunnel in Solaris 10 and OpenSolaris snv_01 through snv_76 allows local users to cause a denial of service (panic) and possibly execute arbitrary code via a crafted SIOCGTUNPARAM IOCTL request, which triggers a NULL pointer dereference.EXPLOITHIGH 7.2EPSS 1.25%19 December 2008
CVE-2008-1094SQL injection vulnerability in index.cgi in the Account View page in Barracuda Spam Firewall (BSF) before 3.5.12.007 allows remote authenticated administrators to execute arbitrary SQL commands via a pattern_x parameter in a search_count_equals action,…EXPLOIT ✓MEDIUM 6.5EPSS 1.98%19 December 2008
CVE-2008-5680Multiple buffer overflows in Opera before 9.63 might allow (1) remote attackers to execute arbitrary code via a crafted text area, or allow (2) user-assisted remote attackers to execute arbitrary code via a long host name in a file: URL.EXPLOIT ✓HIGH 9.3EPSS 7.51%19 December 2008
CVE-2008-5678Fretwell-Downing Informatics (FDI) OLIB7 WebView 2.5.1.1 allows remote authenticated users to obtain sensitive information from files via the infile parameter to the default URI under cgi/, as demonstrated by the (1) get_settings.ini, (2) setup.ini, and…EXPLOIT ✓MEDIUM 4.0EPSS 2.02%19 December 2008
CVE-2008-5677Unrestricted file upload vulnerability in Kwalbum 2.0.4, 2.0.2, and earlier, when PICS_PATH is located in the web root, allows remote authenticated users with upload capability to execute arbitrary code by uploading a file with an executable extension,…EXPLOIT ✓HIGH 7.1EPSS 4.13%19 December 2008
CVE-2008-5674Multiple array index errors in the HTTP server in Darkwet Network webcamXP 3.72.440.0 and earlier and beta 4.05.280 and earlier allow remote attackers to cause a denial of service (device crash) and read portions of memory via (1) an invalid camnum…EXPLOIT ×2 ✓HIGH 9.4EPSS 4.51%19 December 2008
CVE-2008-5667The scanning engine in VirusBlokAda VBA32 Personal Antivirus 3.12.8.x allows remote attackers to cause a denial of service (memory corruption and application crash) via a malformed RAR archive.EXPLOIT ✓MEDIUM 5.0EPSS 6.39%19 December 2008
CVE-2008-5666WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequence of FTP sessions that include an invalid "NLST -1" command.EXPLOIT ×2 ✓LOW 3.5EPSS 20.6%19 December 2008
CVE-2008-5665SQL injection vulnerability in index.php in the xhresim module in XOOPS allows remote attackers to execute arbitrary SQL commands via the no parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%19 December 2008
CVE-2008-5664Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows remote attackers to execute arbitrary code via a crafted playlist (PLA) file.EXPLOIT ×2 ✓HIGH 9.3EPSS 36.2%19 December 2008
CVE-2008-5663Multiple unrestricted file upload vulnerabilities in Kusaba 1.0.4 and earlier allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension using (1) load_receiver.php or (2) a shipainter action to…EXPLOIT ×2 ✓HIGH 9.0EPSS 6.27%19 December 2008
CVE-2008-5499Unspecified vulnerability in Adobe Flash Player for Linux 10.0.12.36, and 9.0.151.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file.EXPLOIT ✓HIGH 9.3EPSS 79.4%18 December 2008
CVE-2008-5660Format string vulnerability in the vinagre_utils_show_error function (src/vinagre-utils.c) in Vinagre 0.5.x before 0.5.2 and 2.x before 2.24.2 might allow remote attackers to execute arbitrary code via format string specifiers in a crafted URI or VNC…EXPLOIT ✓MEDIUM 6.8EPSS 9.12%17 December 2008
CVE-2008-5659The gnu.java.security.util.PRNG class in GNU Classpath 0.97.2 and earlier uses a predictable seed based on the system time, which makes it easier for context-dependent attackers to conduct brute force attacks against cryptographic routines that use this…EXPLOIT ×2 ✓HIGH 7.5EPSS 3.35%17 December 2008
CVE-2008-5655Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) delete_folder and (2) delete_link parameters to unspecified vectors, possibly to (a)…EXPLOIT ×2 ✓HIGH 7.5EPSS 0.91%17 December 2008
CVE-2008-5654SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyCalendar 4.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter, a different vector than…EXPLOIT ✓HIGH 7.5EPSS 1.04%17 December 2008
CVE-2008-5653SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%17 December 2008
CVE-2008-5652SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyBookMarker 4.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter.EXPLOIT ✓HIGH 7.5EPSS 1.24%17 December 2008
CVE-2008-5651SQL injection vulnerability in plugins/bookmarker/bookmarker_backend.php in MyioSoft EasyBookMarker 4.0 allows remote attackers to execute arbitrary SQL commands via the Parent parameter.EXPLOIT ✓HIGH 7.5EPSS 2.27%17 December 2008
CVE-2008-5650SQL injection vulnerability in the login directory in AlstraSoft Web Host Directory allows remote attackers to execute arbitrary SQL commands via the pwd parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.05%17 December 2008
CVE-2008-5649SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOIT ✓HIGH 10.0EPSS 1.78%17 December 2008
CVE-2008-5648SQL injection vulnerability in admin/login.php in DeltaScripts PHP Shop 1.0 allows remote attackers to execute arbitrary SQL commands via the admin_username parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%17 December 2008
CVE-2008-5643SQL injection vulnerability in the Books (com_books) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter in a book_details action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%17 December 2008
CVE-2008-5642Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 8.93%17 December 2008
CVE-2008-5641SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.EXPLOIT ✓HIGH 7.5EPSS 1.01%17 December 2008
CVE-2008-5640SQL injection vulnerability in bidhistory.asp in Active Bids 3.5 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.20%17 December 2008
CVE-2008-5639Directory traversal vulnerability in index.php in TxtBlog 1.0 Alpha allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 4.3EPSS 2.19%17 December 2008
CVE-2008-5638Multiple SQL injection vulnerabilities in Active Price Comparison 4 allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter to reviews.aspx or the (2) linkid parameter to links.asp.EXPLOIT ✓HIGH 7.5EPSS 1.01%17 December 2008
CVE-2008-5637SQL injection vulnerability in blog.asp in ParsBlogger (Pb) allows remote attackers to execute arbitrary SQL commands via the wr parameter.EXPLOIT ✓HIGH 7.5EPSS 1.99%17 December 2008
CVE-2008-5636SQL injection vulnerability in cate.php in Lito Lite CMS, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cid parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.12%17 December 2008
CVE-2008-5635SQL injection vulnerability in account.asp in Active Membership 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp.EXPLOIT ✓HIGH 7.5EPSS 1.01%17 December 2008
CVE-2008-5634SQL injection vulnerability in account.asp in Active Force Matrix 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp.EXPLOIT ✓HIGH 7.5EPSS 1.01%17 December 2008
CVE-2008-5633SQL injection vulnerability in register.asp in ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp.EXPLOIT ✓HIGH 7.5EPSS 1.00%17 December 2008
CVE-2008-5632SQL injection vulnerability in Account.asp in Active Time Billing 3.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.02%17 December 2008
CVE-2008-5631SQL injection vulnerability in start.asp in Active eWebquiz 8.0 allows remote attackers to execute arbitrary SQL commands via the (1) useremail parameter (aka username field) or the (2) password parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%17 December 2008
CVE-2008-5630SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 3 and 3.1.4 allows remote attackers to execute arbitrary SQL commands via the umprof_status parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.12%17 December 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.