SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,447 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 268 of 501

CVESummaryPriorityPublished
CVE-2008-4906SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote attackers to execute arbitrary SQL commands via the l_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.15%4 November 2008
CVE-2008-4902SQL injection vulnerability in contact_author.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%4 November 2008
CVE-2008-4901SQL injection vulnerability in admin/admin.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%4 November 2008
CVE-2008-4900SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.01%4 November 2008
CVE-2008-4897SQL injection vulnerability in fichiers/add_url.php in Logz podcast CMS 1.3.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the art parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.12%4 November 2008
CVE-2008-4896Cross-site scripting (XSS) vulnerability in fichiers/add_url.php in Logz CMS 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the art parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%4 November 2008
CVE-2008-4895SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ×3 ✓HIGH 7.5EPSS 1.05%4 November 2008
CVE-2008-4894Directory traversal vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS 5.0.10a, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local…EXPLOIT ✓MEDIUM 5.1EPSS 2.00%4 November 2008
CVE-2008-4893Cross-site scripting (XSS) vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS 5.0.10a, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the template_path…EXPLOIT ✓LOW 2.6EPSS 1.50%4 November 2008
CVE-2008-4913Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to delete arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.69%4 November 2008
CVE-2008-4912SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute arbitrary SQL commands via the fotoID parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%4 November 2008
CVE-2008-4911PHP remote file inclusion vulnerability in read.php in Chattaitaliano Istant-Replay allows remote attackers to execute arbitrary PHP code via a URL in the data parameter.EXPLOIT ✓HIGH 7.5EPSS 2.28%4 November 2008
CVE-2008-4910The BasicService in Sun Java Web Start allows remote attackers to execute arbitrary programs on a client machine via a file:// URL argument to the showDocument method.EXPLOIT ✓HIGH 10.0EPSS 10.3%4 November 2008
CVE-2008-4890SQL injection vulnerability in products.php in 1st News 4 Professional (PR 1) allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%4 November 2008
CVE-2008-4889SQL injection vulnerability in index.php in deV!L'z Clanportal (DZCP) 1.4.9.6 and earlier allows remote attackers to execute arbitrary SQL commands via the users parameter in an addbuddy operation in a buddys action.EXPLOIT ✓HIGH 7.5EPSS 1.19%4 November 2008
CVE-2008-4888Cross-site scripting (XSS) vulnerability in error.php in NetRisk 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter to index.php.EXPLOIT ✓MEDIUM 4.3EPSS 1.71%4 November 2008
CVE-2008-4887SQL injection vulnerability in index.php in NetRisk 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) profile page (profile.php) or (2) game page (game.php).EXPLOIT ✓HIGH 7.5EPSS 1.18%4 November 2008
CVE-2008-4886SQL injection vulnerability in index.php in YourFreeWorld Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the c parameter.EXPLOIT ✓HIGH 7.5EPSS 2.43%4 November 2008
CVE-2008-4885SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.05%4 November 2008
CVE-2008-4884SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97%4 November 2008
CVE-2008-4883SQL injection vulnerability in tr.php in YourFreeWorld Blog Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.03%4 November 2008
CVE-2008-4882SQL injection vulnerability in tr.php in YourFreeWorld Autoresponder Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.01%4 November 2008
CVE-2008-4881SQL injection vulnerability in tr.php in YourFreeWorld Reminder Service Script allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.98%4 November 2008
CVE-2008-4880SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-4879.EXPLOIT ✓HIGH 7.5EPSS 1.17%4 November 2008
CVE-2008-4879SQL injection vulnerability in prod.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2008-4880.EXPLOIT ✓HIGH 7.5EPSS 1.04%4 November 2008
CVE-2008-4878Unrestricted file upload vulnerability in the "Add Image Macro" feature in WebCards 1.3 allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the…EXPLOIT ✓HIGH 8.5EPSS 4.02%1 November 2008
CVE-2008-4877SQL injection vulnerability in admin.php in WebCards 1.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.98%1 November 2008
CVE-2008-4876Cross-site scripting (XSS) vulnerability in the web server component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote attackers to inject arbitrary web script or HTML via the request URL, which is not properly…EXPLOIT ✓MEDIUM 4.3EPSS 1.80%1 November 2008
CVE-2008-4875Directory traversal vulnerability in the web server in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote authenticated users to read arbitrary files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 3.14%1 November 2008
CVE-2008-4874The web component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 has a back door "service" account with "service" as its password, which makes it easier for remote attackers to obtain access.EXPLOIT ✓MEDIUM 5.0EPSS 3.55%1 November 2008
CVE-2008-4873board.cgi in Sepal SPBOARD 4.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter during a down_file action.EXPLOIT ✓HIGH 10.0EPSS 4.93%1 November 2008
CVE-2008-4864Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent attackers to break out of the Python VM and execute arbitrary code via large integer values in certain arguments to the crop function,…EXPLOIT ×2 ✓HIGH 7.5EPSS 21.0%1 November 2008
CVE-2008-4803Cross-site scripting (XSS) vulnerability in index.php in Simple PHP Scripts gallery 0.1, 0.3, and 0.4 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.20%31 October 2008
CVE-2008-4800The DebugDiag ActiveX control in CrashHangExt.dll, possibly 1.0, in Microsoft Debug Diagnostic Tool allows remote attackers to cause a denial of service (NULL pointer dereference and Internet Explorer 6.0 crash) via a large negative integer argument to…EXPLOIT ✓MEDIUM 5.0EPSS 25.8%31 October 2008
CVE-2008-4795The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which allows remote attackers to inject arbitrary web script or HTML via cross-site scripting (XSS) attacks.EXPLOIT ✓MEDIUM 4.3EPSS 4.34%30 October 2008
CVE-2008-4787Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a URL with a hostname containing many   (Non-Blocking Space character) sequences, which are rendered as whitespace, aka MSRC…EXPLOIT ✓MEDIUM 5.8EPSS 13.6%29 October 2008
CVE-2008-4786SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary SQL commands via the category_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%29 October 2008
CVE-2008-4785SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%29 October 2008
CVE-2008-4784aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a cookie to "A" or "O" in (1) edit_delete.php, (2) edit_cat.php, (3) edit_lock.php, and (4) edit_form.php.EXPLOIT ✓HIGH 7.5EPSS 2.77%29 October 2008
CVE-2008-4783tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login cookie to "admin."EXPLOIT ✓HIGH 7.5EPSS 2.77%29 October 2008
CVE-2008-4782SQL injection vulnerability in public/code/cp_polls_results.php in All In One Control Panel (AIOCP) 1.4 allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.01%29 October 2008
CVE-2008-4781Directory traversal vulnerability in update.php in MyKtools 2.4 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.36%29 October 2008
CVE-2008-4780Directory traversal vulnerability in admin/centre.php in MyForum 1.3, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the padmin parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.90%29 October 2008
CVE-2008-4779Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary code via a long filename in a .zip file.EXPLOIT ×3 ✓HIGH 10.0EPSS 64.7%29 October 2008
CVE-2008-4778SQL injection vulnerability in the gallery module in Koobi CMS 4.3.0 allows remote attackers to execute arbitrary SQL commands via the galid parameter in a showimages action.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.05%29 October 2008
CVE-2008-4777SQL injection vulnerability in the Showroom Joomlearn LMS (com_lms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the cat parameter in a showTests task.EXPLOIT ✓HIGH 7.5EPSS 1.03%29 October 2008
CVE-2008-4775Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter,…EXPLOIT ✓LOW 2.6EPSS 6.06%28 October 2008
CVE-2008-4774Cross-site scripting (XSS) vulnerability in main/main.php in QuestCMS allows remote attackers to inject arbitrary web script or HTML via the cx parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%28 October 2008
CVE-2008-4773Directory traversal vulnerability in main/main.php in QuestCMS allows remote attackers to read arbitrary local files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.67%28 October 2008
CVE-2008-4772SQL injection vulnerability in main/main.php in QuestCMS allows remote attackers to execute arbitrary SQL commands via the obj parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%28 October 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.