SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,446 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 265 of 501

CVESummaryPriorityPublished
CVE-2008-5309SQL injection vulnerability in NetArt Media Real Estate Portal 1.2 allows remote attackers to execute arbitrary SQL commands via the ad_id parameter in the re_send_email module to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.01%2 December 2008
CVE-2008-5308The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote attackers to change the administrator password via a direct request to modules/simpleforum/admin/index.php.EXPLOIT ✓HIGH 7.5EPSS 7.28%2 December 2008
CVE-2008-5307SQL injection vulnerability in admin/index.php in PG Roommate Finder Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.16%2 December 2008
CVE-2008-5306SQL injection vulnerability in admin/index.php in PG Real Estate Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter (username).EXPLOIT ✓HIGH 7.5EPSS 1.15%2 December 2008
CVE-2008-5297Buffer overflow in No-IP DUC 2.1.7 and earlier allows remote HTTP servers to execute arbitrary code via a crafted response to a DNS update request, related to a missing length check in the GetNextLine function.EXPLOIT ✓HIGH 7.6EPSS 18.5%1 December 2008
CVE-2008-5295SQL injection vulnerability in index.php in Jamit Job Board 3.4.10 allows remote attackers to execute arbitrary SQL commands via the show_emp parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%1 December 2008
CVE-2008-5294SQL injection vulnerability in index.php in WebStudio eCatalogue allows remote attackers to execute arbitrary SQL commands via the pageid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%1 December 2008
CVE-2008-5293SQL injection vulnerability in index.php in WebStudio eHotel allows remote attackers to execute arbitrary SQL commands via the pageid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%1 December 2008
CVE-2008-5292SQL injection vulnerability in view_snaps.php in VideoGirls BiZ allows remote attackers to execute arbitrary SQL commands via the type parameter.EXPLOIT ✓HIGH 7.5EPSS 1.15%1 December 2008
CVE-2008-5291Directory traversal vulnerability in code/track.php in FuzzyLime 3.03 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter, a different vector than CVE-2007-4805 and CVE-2008-3165.EXPLOIT ✓HIGH 7.5EPSS 2.50%1 December 2008
CVE-2008-5290Cross-site scripting (XSS) vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.52%1 December 2008
CVE-2008-5289SQL injection vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.21%1 December 2008
CVE-2008-5288PHP remote file inclusion vulnerability in include/header.php in Werner Hilversum FAQ Manager 1.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config_path parameter.EXPLOIT ✓MEDIUM 6.8EPSS 4.89%1 December 2008
CVE-2008-5287SQL injection vulnerability in catagorie.php in Werner Hilversum FAQ Manager 1.2 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.15%1 December 2008
CVE-2008-5284The web server in IEA Software RadiusNT and RadiusX 5.1.38 and other versions before 5.1.44, Emerald 5.0.49 and other versions before 5.0.52, Air Marshal 2.0.4 and other versions before 2.0.8, and Radius test client (aka Radlogin) 4.0.20 and earlier,…EXPLOIT ✓HIGH 10.0EPSS 4.44%29 November 2008
CVE-2008-5283Google Hack Honeypot (GHH) File Upload Manager 1.3 allows remote attackers to delete uploaded files via unknown vectors related to the delall action to index.php.EXPLOIT ✓MEDIUM 6.4EPSS 1.78%29 November 2008
CVE-2008-5282Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code via (1) a link with a long HREF attribute, and (2) a DIV tag with a long id attribute.EXPLOIT ×2 ✓HIGH 10.0EPSS 17.6%29 November 2008
CVE-2008-5281Heap-based buffer overflow in Titan FTP Server 6.05 build 550 allows remote attackers to execute arbitrary code via a long DELE command.EXPLOIT ✓HIGH 10.0EPSS 6.40%29 November 2008
CVE-2008-5280The Local ZIM Server in Zilab Chat and Instant Messaging (ZIM) Server 2.0 and 2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted requests without required parameters.EXPLOIT ✓MEDIUM 5.0EPSS 7.34%29 November 2008
CVE-2008-5274Todd Woolums ASP News Management 2.2 allows remote attackers to obtain news items via a direct request to (1) rss.asp, (2) viewheadings.asp, or (3) viewnews.asp.EXPLOIT ✓MEDIUM 5.0EPSS 2.14%28 November 2008
CVE-2008-5273SQL injection vulnerability in viewnews.asp in Todd Woolums ASP News Management 2.2 allows remote attackers to execute arbitrary SQL commands via the newsID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%28 November 2008
CVE-2008-5272Multiple directory traversal vulnerabilities in Fred Stuurman SyndeoCMS 2.6.0 allow remote authenticated users to read arbitrary files via a ..EXPLOIT ✓MEDIUM 4.0EPSS 5.62%28 November 2008
CVE-2008-5271Cross-site scripting (XSS) vulnerability in index.php in Fred Stuurman SyndeoCMS 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.52%28 November 2008
CVE-2008-5270SQL injection vulnerability in view.topics.php in Yuhhu Superstar 2008 allows remote attackers to execute arbitrary SQL commands via the board parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%28 November 2008
CVE-2008-5269SQL injection vulnerability in index.php in pSys 0.7.0 alpha allows remote attackers to execute arbitrary SQL commands via the shownews parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%28 November 2008
CVE-2008-5268SQL injection vulnerability in content/forums/reply.asp in ASPPortal allows remote attackers to execute arbitrary SQL commands via the Topic_Id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%28 November 2008
CVE-2008-5267SQL injection vulnerability in answer.php in Experts 1.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the question_id parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.91%28 November 2008
CVE-2008-5266Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application Server 9.1_01 build b09d-fcs and 9.1_02 build b04-fcs allows remote attackers to inject arbitrary…EXPLOIT ✓MEDIUM 4.3EPSS 5.40%28 November 2008
CVE-2008-5265Directory traversal vulnerability in index.php in TNT Forum 0.9.4, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the modulo parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.92%28 November 2008
CVE-2008-5264Cross-site scripting (XSS) vulnerability in searcher.exe in Tornado Knowledge Retrieval System 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the p parameter in a root action.EXPLOIT ✓MEDIUM 4.3EPSS 1.51%28 November 2008
CVE-2008-5232Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote…EXPLOIT ✓HIGH 9.3EPSS 32.2%26 November 2008
CVE-2008-5229Stack-based buffer overflow in Microsoft Device IO Control in iphlpapi.dll in Microsoft Windows Vista Gold and SP1 allows local users in the Network Configuration Operator group to gain privileges or cause a denial of service (system crash) via a large…EXPLOIT ✓MEDIUM 6.9EPSS 2.59%25 November 2008
CVE-2008-5226SQL injection vulnerability in the MambAds (com_mambads) component 1.0 RC1 Beta and 1.0 RC1 for Mambo allows remote attackers to execute arbitrary SQL commands via the ma_cat parameter in a view action to index.php, a different vector than CVE-2007-5177.EXPLOIT ✓HIGH 7.5EPSS 1.01%25 November 2008
CVE-2008-5225Multiple cross-site scripting (XSS) vulnerabilities in Xerox DocuShare 6 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) SearchResults/ and (2) Services/ in dsdn/dsweb/, and (3)…EXPLOIT ×3 ✓MEDIUM 4.3EPSS 4.10%25 November 2008
CVE-2008-5223SQL injection vulnerability in index.php in Airvae Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%25 November 2008
CVE-2008-5222SQL injection vulnerability in login.asp in Dvbbs 8.2.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%25 November 2008
CVE-2008-5221The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified password…EXPLOIT ✓HIGH 7.5EPSS 2.55%25 November 2008
CVE-2008-5220Unrestricted file upload vulnerability in admin/upload_form.php in wPortfolio 0.3 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in…EXPLOIT ✓HIGH 10.0EPSS 14.3%25 November 2008
CVE-2008-5219The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password…EXPLOIT ✓HIGH 7.5EPSS 6.85%25 November 2008
CVE-2008-5218ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext passwords.EXPLOIT ✓MEDIUM 5.0EPSS 2.70%25 November 2008
CVE-2008-5217Directory traversal vulnerability in index.php in txtCMS 0.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 5.1EPSS 1.91%24 November 2008
CVE-2008-5216SQL injection vulnerability in category_list.php in AJ Square ZeusCart 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%24 November 2008
CVE-2008-5215SQL injection vulnerability in service/profil.php in ClanLite 2.2006.05.20 allows remote attackers to execute arbitrary SQL commands via the link parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%24 November 2008
CVE-2008-5214Cross-site scripting (XSS) vulnerability in service/calendrier.php in ClanLite 2.2006.05.20 allows remote attackers to inject arbitrary web script or HTML via the annee parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.52%24 November 2008
CVE-2008-5213SQL injection vulnerability in featured_article.php in AJ Article 1.0 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a search detail action.EXPLOIT ✓HIGH 7.5EPSS 1.00%24 November 2008
CVE-2008-5212SQL injection vulnerability in classifide_ad.php in AJ Auction 6.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the item_id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%24 November 2008
CVE-2008-5211Cross-site scripting (XSS) vulnerability in search.php in Sphider 1.3.4, when the search suggestion feature is enabled, allows remote attackers to inject arbitrary web script or HTML via the query parameter, a different vector than CVE-2006-2506.EXPLOIT ✓LOW 2.6EPSS 1.80%24 November 2008
CVE-2008-5210Multiple PHP remote file inclusion vulnerabilities in PhpBlock A8.5 allow remote attackers to execute arbitrary PHP code via a URL in the PATH_TO_CODE parameter to (1) script/init/createallimagecache.php, (2) allincludefortick.php and (3) test.php in…EXPLOIT ✓HIGH 9.3EPSS 2.78%24 November 2008
CVE-2008-5209Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.76%24 November 2008
CVE-2008-5208SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.EXPLOIT ✓HIGH 7.5EPSS 2.00%24 November 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.