SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,446 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 266 of 501

CVESummaryPriorityPublished
CVE-2008-5204Multiple directory traversal vulnerabilities in PowerAward 1.1.0 RC1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the lang parameter to (1) agb.php, (2)…EXPLOIT ✓MEDIUM 6.8EPSS 1.85%21 November 2008
CVE-2008-5203Cross-site scripting (XSS) vulnerability in external_vote.php in PowerAward 1.1.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the l_vote_done parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%21 November 2008
CVE-2008-5202Cross-site scripting (XSS) vulnerability in index.php in OTManager CMS 24a allows remote attackers to inject arbitrary web script or HTML via the conteudo parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%21 November 2008
CVE-2008-5201Directory traversal vulnerability in index.php in OTManager CMS 24a allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.46%21 November 2008
CVE-2008-5200SQL injection vulnerability in the Xe webtv (com_xewebtv) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.04%21 November 2008
CVE-2008-5199PHP remote file inclusion vulnerability in include.php in PHPOutsourcing IdeaBox (aka IdeBox) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the gorumDir parameter.EXPLOIT ✓HIGH 7.5EPSS 2.91%21 November 2008
CVE-2008-5198SQL injection vulnerability in memberlist.php in Acmlmboard 1.A2 allows remote attackers to execute arbitrary SQL commands via the pow parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%21 November 2008
CVE-2008-5197SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter in a detail_adverts action.EXPLOIT ✓HIGH 7.5EPSS 4.10%21 November 2008
CVE-2008-5196SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the category parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%21 November 2008
CVE-2008-5195Multiple SQL injection vulnerabilities in SebracCMS (sbcms) 0.4 allow remote attackers to execute arbitrary SQL commands via (1) the recid parameter to cms/form/read.php, (2) the uname parameter to cms/index.php, and other unspecified vectors.EXPLOIT ✓HIGH 7.5EPSS 1.00%21 November 2008
CVE-2008-5194SQL injection vulnerability in checkavail.php in SoftVisions Software Online Booking Manager (obm) 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.15%21 November 2008
CVE-2008-5193Cross-site scripting (XSS) vulnerability in search.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.57%21 November 2008
CVE-2008-5192SQL injection vulnerability in forum.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%21 November 2008
CVE-2008-5191Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the (1) poll_id parameter to poll.php and the (2) sp_id parameter to staticpages.php.EXPLOIT ×3 ✓HIGH 7.5EPSS 17.6%21 November 2008
CVE-2008-5190SQL injection vulnerability in index.php in eSHOP100 allows remote attackers to execute arbitrary SQL commands via the SUB parameter.EXPLOIT ✓HIGH 7.5EPSS 2.35%21 November 2008
CVE-2008-5185The highlighting functionality in geshi.php in GeSHi before 1.0.8 allows remote attackers to cause a denial of service (infinite loop) via an XML sequence containing an opening delimiter without a closing delimiter, as demonstrated using "<".EXPLOIT ✓MEDIUM 5.0EPSS 3.89%21 November 2008
CVE-2008-5183cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference.EXPLOIT ✓HIGH 7.5EPSS 9.21%21 November 2008
CVE-2008-5180Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.EXPLOIT ×2 ✓MEDIUM 5.3EPSS 68.0%20 November 2008
CVE-2008-5178Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI.EXPLOIT ✓HIGH 9.3EPSS 31.5%20 November 2008
CVE-2008-5177Stack-based buffer overflow in the DtbClsLogin function in Yosemite Backup 8.7 allows remote attackers to (1) execute arbitrary code on a Linux platform, related to libytlindtb.so; or (2) cause a denial of service (application crash) and possibly…EXPLOIT ✓HIGH 10.0EPSS 16.9%20 November 2008
CVE-2008-5175Directory traversal vulnerability in the FTP client in AceFTP Freeware 3.80.3 and AceFTP Pro 3.80.3 allows remote FTP servers to create or overwrite arbitrary files via a ..EXPLOIT ✓HIGH 9.3EPSS 2.53%19 November 2008
CVE-2008-5174SQL injection vulnerability in joke.php in Jokes Complete Website 2.1.3 allows remote attackers to execute arbitrary SQL commands via the jokeid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%19 November 2008
CVE-2008-5171Multiple directory traversal vulnerabilities in admin/minibb/index.php in phpBLASTER CMS 1.0 RC1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) DB, (2)…EXPLOIT ✓HIGH 9.3EPSS 3.25%19 November 2008
CVE-2008-5170SQL injection vulnerability in item.php in Cheats Complete Website 1.1.1 allows remote attackers to execute arbitrary SQL commands via the itemid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%19 November 2008
CVE-2008-5169SQL injection vulnerability in drinks/drink.php in Drinks Complete Website 2.1.0 allows remote attackers to execute arbitrary SQL commands via the drinkid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%19 November 2008
CVE-2008-5168SQL injection vulnerability in tip.php in Tips Complete Website 1.2.0 allows remote attackers to execute arbitrary SQL commands via the tipid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%19 November 2008
CVE-2008-5167PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the gConf[dir][layouts] parameter.EXPLOIT ✓HIGH 9.3EPSS 3.14%19 November 2008
CVE-2008-5166SQL injection vulnerability in riddle.php in Riddles Website 1.2.1 allows remote attackers to execute arbitrary SQL commands via the riddleid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%19 November 2008
CVE-2008-5164Multiple cross-site scripting (XSS) vulnerabilities in The Rat CMS Pre-Alpha 2 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) viewarticle.php and (b) viewarticle2.php and the (2) PATH_INFO to viewarticle.php.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.49%19 November 2008
CVE-2008-5163Multiple SQL injection vulnerabilities in The Rat CMS Pre-Alpha 2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewarticle.php and (2) viewarticle2.php.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97%19 November 2008
CVE-2008-5160Unspecified vulnerability in MyServer 0.8.11 allows remote attackers to cause a denial of service (daemon crash) via multiple invalid requests with the HTTP GET, DELETE, OPTIONS, and possibly other methods, related to a "204 No Content error."EXPLOIT ✓MEDIUM 5.0EPSS 3.47%18 November 2008
CVE-2008-5159Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote attackers to cause a denial of service (crash) via a large string length argument, which triggers memory corruption.EXPLOIT ×2 ✓HIGH 10.0EPSS 59.7%18 November 2008
CVE-2008-5132SQL injection vulnerability in inc/ajax/ajax_rating.php in MemHT Portal 4.0.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.EXPLOIT ✓HIGH 7.5EPSS 2.40%18 November 2008
CVE-2008-5131Multiple SQL injection vulnerabilities in Develop It Easy News And Article System 1.4 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter to article_details.php, and the (2) username and (3) password to the admin panel…EXPLOIT ✓HIGH 7.5EPSS 1.04%18 November 2008
CVE-2008-5126Cross-site scripting (XSS) vulnerability in search.php in BoutikOne CMS allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%18 November 2008
CVE-2008-5125admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin.EXPLOIT ✓MEDIUM 6.8EPSS 2.16%18 November 2008
CVE-2008-5123SQL injection vulnerability in admin.php in CCleague Pro 1.2 allows remote attackers to execute arbitrary SQL commands via the u parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.98%18 November 2008
CVE-2008-5121dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted…EXPLOIT ✓HIGH 7.2EPSS 1.12%18 November 2008
CVE-2008-5120Stack-based buffer overflow in the Process Software MultiNet finger service (aka FINGERD) for HP OpenVMS 8.3 allows remote attackers to execute arbitrary code via a long request string.EXPLOIT ✓HIGH 10.0EPSS 9.85%18 November 2008
CVE-2008-5115Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hijack the authentication of administrators for requests that update the password via…EXPLOIT ✓MEDIUM 6.8EPSS 3.14%18 November 2008
CVE-2008-5112The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a failed bind attempt depending on whether the user account exists and is permitted to login, which allows remote attackers to…EXPLOIT ✓MEDIUM 5.0EPSS 17.4%17 November 2008
CVE-2008-5105KarjaSoft Sami FTP Server 2.0.x allows remote attackers to cause a denial of service (daemon crash or hang) via certain (1) APPE, (2) CWD, (3) DELE, (4) MKD, (5) RMD, (6) RETR, (7) RNFR, (8) RNTO, (9) SIZE, and (10) STOR commands.EXPLOIT ✓MEDIUM 5.0EPSS 2.70%17 November 2008
CVE-2008-5102PythonScripts in Zope 2 2.11.2 and earlier, as used in Conga and other products, allows remote authenticated users to cause a denial of service (resource consumption or application halt) via certain (1) raise or (2) import statements.EXPLOIT ✓MEDIUM 4.0EPSS 3.92%17 November 2008
CVE-2008-5097SQL injection vulnerability in index.php in MyFWB 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.EXPLOIT ✓HIGH 7.5EPSS 1.17%14 November 2008
CVE-2008-5090Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email parameter, which is processed by the preg_replace function with the eval switch.EXPLOIT ✓HIGH 10.0EPSS 4.60%14 November 2008
CVE-2008-5088Multiple SQL injection vulnerabilities in PHPKB Knowledge Base Software 1.5 Professional allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) email.php and (2) question.php, a different vector than CVE-2008-1909.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97%14 November 2008
CVE-2008-5075Multiple SQL injection vulnerabilities in E-Uploader Pro 1.0 (aka Uploader PRO), when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) img.php, (b) file.php, (c) mail.php, (d)…EXPLOIT ✓MEDIUM 6.8EPSS 0.91%14 November 2008
CVE-2008-5074SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the linkid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%14 November 2008
CVE-2008-5073Heap-based buffer overflow in an ActiveX control in Novell ZENworks Desktop Management 6.5 allows remote attackers to execute arbitrary code via a long argument to the CanUninstall method.EXPLOIT ✓HIGH 9.3EPSS 5.27%14 November 2008
CVE-2008-5072vsfilter.dll in K-Lite Mega Codec Pack 3.5.7.0 allows remote attackers to cause a denial of service (application crash) via a malformed FLV file.EXPLOIT ✓MEDIUM 4.3EPSS 2.35%14 November 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.