Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,447 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 269 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-4771 | Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-Link MPEG4 SHM Audio Control (VAPGDecoder.dll 1.7.0.5), (3) Vivotek RTSP MPEG4 SP Control (RtspVapgDecoderNew.dll… | EXPLOIT ✓HIGH 9.3EPSS 7.14% | 28 October 2008 |
| CVE-2008-4769 | Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. | EXPLOIT ✓HIGH 9.3EPSS 8.97% | 28 October 2008 |
| CVE-2008-4768 | SQL injection vulnerability in TLM CMS 3.1 allows remote attackers to execute arbitrary SQL commands via the nom parameter to a-b-membres.php. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 28 October 2008 |
| CVE-2008-4767 | Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploading a file with (1) .htm, (2) .html, or (3) .txt extensions, then accessing it via a direct request to the file. | EXPLOIT ✓HIGH 9.0EPSS 4.21% | 28 October 2008 |
| CVE-2008-4765 | SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a results operation. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97% | 28 October 2008 |
| CVE-2008-4764 | Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 16.5% | 28 October 2008 |
| CVE-2008-4762 | Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service crash) and potentially execute arbitrary code via a long argument to the (1) rename and (2) realpath parameters. | EXPLOIT ×2 ✓HIGH 9.0EPSS 14.5% | 28 October 2008 |
| CVE-2008-4761 | Cross-site scripting (XSS) vulnerability in includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako eSupport 3.20.2 allows remote attackers to inject arbitrary web script or HTML via the jsMakeSrc parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 28 October 2008 |
| CVE-2008-4760 | SQL injection vulnerability in lecture.php in Graphiks MyForum 1.3, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.94% | 28 October 2008 |
| CVE-2008-4759 | Directory traversal vulnerability in download.php in BuzzyWall 1.3.1 allows remote attackers to read arbitrary local files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.76% | 28 October 2008 |
| CVE-2008-4758 | Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.83% | 28 October 2008 |
| CVE-2008-4757 | Multiple SQL injection vulnerabilities in PHP-Daily allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) add_postit.php (b) delete.php, and (c) mod_prest_date.php; and the (2) prev parameter to (d) prest_detail.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 28 October 2008 |
| CVE-2008-4756 | Cross-site scripting (XSS) vulnerability in add_prest_date.php in PHP-Daily allows remote attackers to inject arbitrary web script or HTML via the date parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 28 October 2008 |
| CVE-2008-4755 | SQL injection vulnerability in gotourl.php in PozScripts Classified Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 28 October 2008 |
| CVE-2008-4754 | SQL injection vulnerability in forum.php in Scripts for Sites (SFS) Ez Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter. | EXPLOIT ✓MEDIUM 5.8EPSS 3.13% | 27 October 2008 |
| CVE-2008-4753 | SQL injection vulnerability in EditUrl.php in AJ Square RSS Reader allows remote attackers to execute arbitrary SQL commands via the url parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 27 October 2008 |
| CVE-2008-4752 | TlNews 2.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlNews_login cookie to admin. | EXPLOIT ✓HIGH 7.5EPSS 2.72% | 27 October 2008 |
| CVE-2008-4751 | Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the pg parameter, a different vector than CVE-2005-4597. | EXPLOIT ✓MEDIUM 4.3EPSS 1.78% | 27 October 2008 |
| CVE-2008-4750 | Stack-based buffer overflow in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allows remote attackers to execute arbitrary code via a long LogFile property. | EXPLOIT ✓HIGH 9.3EPSS 5.55% | 27 October 2008 |
| CVE-2008-4749 | Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allow remote attackers to overwrite arbitrary files via (1) the LogFile property and ClearLogFile method,… | EXPLOIT ✓HIGH 9.3EPSS 3.03% | 27 October 2008 |
| CVE-2008-4748 | Format string vulnerability in the URI handler in KVirc 3.4.0, when set as the default application for processing IRC URIs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string… | EXPLOIT ✓HIGH 7.6EPSS 8.16% | 27 October 2008 |
| CVE-2008-4744 | SQL injection vulnerability in product_detail.php in DXShopCart 4.30mc allows remote attackers to execute arbitrary SQL commands via the pid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 27 October 2008 |
| CVE-2008-4743 | SQL injection vulnerability in index.php in QuidaScript FAQ Management Script allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 27 October 2008 |
| CVE-2008-4742 | Multiple cross-site scripting (XSS) vulnerabilities in interface/Login.php in TimeTrex 2.2.11 allow remote attackers to inject arbitrary web script or HTML via the (1) password and (2) user_name parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.79% | 27 October 2008 |
| CVE-2008-4741 | Directory traversal vulnerability in index.php in FAR-PHP 1.00, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.40% | 27 October 2008 |
| CVE-2008-4740 | Directory traversal vulnerability in templater.php in the ZZ_Templater module in TinyCMS 1.1.2, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 5.1EPSS 2.36% | 27 October 2008 |
| CVE-2006-7234 | Untrusted search path vulnerability in Lynx before 2.8.6rel.4 allows local users to execute arbitrary code via malicious (1) .mailcap and (2) mime.types files in the current working directory. | EXPLOIT ✓MEDIUM 4.6EPSS 0.88% | 27 October 2008 |
| CVE-2008-4739 | Directory traversal vulnerability in index.php in PlugSpace 0.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.85% | 24 October 2008 |
| CVE-2008-4738 | SQL injection vulnerability in gallery.php in MyCard 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 24 October 2008 |
| CVE-2008-4737 | Cross-site scripting (XSS) vulnerability in wholite.cgi in WhoDomLite 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the dom parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 24 October 2008 |
| CVE-2008-4736 | SQL injection vulnerability in index.php in RPG.Board 0.8 Beta2 and earlier allows remote attackers to execute arbitrary SQL commands via the showtopic parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 24 October 2008 |
| CVE-2008-4735 | PHP remote file inclusion vulnerability in header.php in Concord Asset, Software, and Ticket system (CoAST) 0.95 allows remote attackers to execute arbitrary PHP code via a URL in the sections_file parameter. | EXPLOIT ✓HIGH 8.5EPSS 2.33% | 24 October 2008 |
| CVE-2008-4732 | SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the p parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.47% | 24 October 2008 |
| CVE-2008-4729 | Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Control 13.0 and earlier allows remote attackers to execute arbitrary code via a long PlainTextPassword property. | EXPLOIT ✓MEDIUM 6.8EPSS 6.90% | 24 October 2008 |
| CVE-2008-4728 | Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in Hummingbird Deployment Wizard 2008 allow remote attackers to execute arbitrary programs via the (1) Run and (2) PerformUpdateAsync… | EXPLOIT ×3 ✓HIGH 9.3EPSS 31.6% | 24 October 2008 |
| CVE-2008-4727 | Cross-site scripting (XSS) vulnerability in the contact update page (ss/bwgkoemr.P_UpdateEmrgContacts) in SunGard Banner Student 7.3 allows remote attackers to inject arbitrary web script or HTML via the addr1 parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.73% | 24 October 2008 |
| CVE-2008-4726 | Stack-based buffer overflow in the SFTP subsystem in GoodTech SSH 6.4 allows remote authenticated users to execute arbitrary code via a long string to the (1) open (aka SSH_FXP_OPEN), (2) unlink, (3) opendir, and other unspecified parameters. | EXPLOIT ✓HIGH 9.0EPSS 44.3% | 24 October 2008 |
| CVE-2008-4725 | Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly escaped before storage in the History Search database (aka md.dat), a… | EXPLOIT ✓MEDIUM 4.3EPSS 4.89% | 23 October 2008 |
| CVE-2008-4696 | Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML via the anchor identifier (aka the "optional fragment"), which is not properly escaped before storage in the… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 45.7% | 23 October 2008 |
| CVE-2008-4694 | Unspecified vulnerability in Opera before 9.60 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a redirect that specifies a crafted URL. | EXPLOIT ✓HIGH 9.3EPSS 9.75% | 23 October 2008 |
| CVE-2008-4250 | Microsoft Windows Buffer Overflow Vulnerability | KEVEXPLOIT ×6 ✓CRITICAL 9.8EPSS 98.8% | 23 October 2008 |
| CVE-2008-2469 | Heap-based buffer overflow in the SPF_dns_resolv_lookup function in Spf_dns_resolv.c in libspf2 before 1.2.8 allows remote attackers to execute arbitrary code via a long DNS TXT record with a modified length field. | EXPLOIT ✓HIGH 10.0EPSS 22.3% | 23 October 2008 |
| CVE-2008-4721 | PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie to "logged." | EXPLOIT ✓HIGH 7.5EPSS 2.77% | 23 October 2008 |
| CVE-2008-4720 | Multiple PHP remote file inclusion vulnerabilities in The Gemini Portal 4.7 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) page/forums/bottom.php and (2) page/forums/category.php. | EXPLOIT ✓HIGH 9.3EPSS 3.00% | 23 October 2008 |
| CVE-2008-4719 | PHP remote file inclusion vulnerability in cms/classes/openengine/filepool.php in openEngine 2.0 beta2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the oe_classpath parameter, a different vector… | EXPLOIT ✓HIGH 9.3EPSS 2.94% | 23 October 2008 |
| CVE-2008-4718 | Directory traversal vulnerability in help/mini.php in X7 Chat 2.0.1 A1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the help_file parameter, a different vector than CVE-2006-2156. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.67% | 23 October 2008 |
| CVE-2008-4717 | SQL injection vulnerability in bannerclick.php in ZEELYRICS 2.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 23 October 2008 |
| CVE-2008-4716 | SQL injection vulnerability in show.php in BitmixSoft PHP-Lance 1.52 allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 23 October 2008 |
| CVE-2008-4715 | SQL injection vulnerability in the Jpad (com_jpad) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.45% | 23 October 2008 |
| CVE-2008-4714 | Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies. | EXPLOIT ✓HIGH 7.5EPSS 2.56% | 23 October 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.