SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,447 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 270 of 501

CVESummaryPriorityPublished
CVE-2008-4713SQL injection vulnerability in view.php in 212cafe Board 0.07 allows remote attackers to execute arbitrary SQL commands via the qID parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%23 October 2008
CVE-2008-4712Directory traversal vulnerability in pages/showblog.php in LnBlog 0.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.86%23 October 2008
CVE-2008-4711SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.blog.php, (2) view.event.php, (3) view.group.php, (4) view.music.php,…EXPLOIT ✓MEDIUM 6.8EPSS 0.91%23 October 2008
CVE-2008-4709SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%23 October 2008
CVE-2008-4708BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admin_session cookie to 1.EXPLOIT ✓HIGH 7.5EPSS 2.77%23 October 2008
CVE-2008-4707Directory traversal vulnerability in index.php in BbZL.PhP 0.92 allows remote attackers to access unauthorized directories via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.67%23 October 2008
CVE-2008-4706SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL commands via the mapid parameter in a showdetails action to (1) vbgooglemaphse.php and (2) mapa.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%23 October 2008
CVE-2008-4705SQL injection vulnerability in success_story.php in php Online Dating Software MyPHPDating allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%23 October 2008
CVE-2008-4704PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter.EXPLOIT ✓HIGH 10.0EPSS 3.55%23 October 2008
CVE-2008-4703SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands via the article parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%23 October 2008
CVE-2008-4702Multiple directory traversal vulnerabilities in PhpWebGallery 1.3.4 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.49%22 October 2008
CVE-2008-4701SQL injection vulnerability in admin.php in Libera CMS 1.12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the libera_staff_user cookie parameter, a different vector than CVE-2008-4700.EXPLOIT ✓MEDIUM 6.8EPSS 0.91%22 October 2008
CVE-2008-4700SQL injection vulnerability in admin.php in Libera CMS 1.12 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the libera_staff_pass cookie parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.98%22 October 2008
CVE-2008-4699Insecure method vulnerability in the ActiveX control (PAWWeb11.ocx) in Peachtree Accounting 2004 allows remote attackers to execute arbitrary programs via the ExecutePreferredApplication method.EXPLOIT ✓HIGH 9.3EPSS 27.2%22 October 2008
CVE-2008-4687manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.EXPLOIT ×2 ✓HIGH 9.0EPSS 67.5%22 October 2008
CVE-2008-4686Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote attackers to execute arbitrary code via a crafted .ty file, a different vulnerability than CVE-2008-4654.EXPLOIT ×2 ✓HIGH 9.3EPSS 9.94%22 October 2008
CVE-2008-4682wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application abort) via a malformed Tamos CommView capture file (aka .ncf file) with an "unknown/unexpected packet type" that triggers a failed assertion.EXPLOIT ✓MEDIUM 5.0EPSS 9.29%22 October 2008
CVE-2008-4675SQL injection vulnerability in index.php in PHPcounter 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%22 October 2008
CVE-2008-4674SQL injection vulnerability in realestate-index.php in Conkurent Real Estate Manager 1.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in browse mode.EXPLOIT ✓MEDIUM 6.8EPSS 0.98%22 October 2008
CVE-2008-4673PHP remote file inclusion vulnerability in panel/common/theme/default/header_setup.php in WebBiscuits Software Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the (1) path[docroot] and (2) component parameters.EXPLOIT ✓HIGH 10.0EPSS 4.53%22 October 2008
CVE-2008-4672Cross-site scripting (XSS) vulnerability in search_results.php in buymyscripts Lyrics Script allows remote attackers to inject arbitrary web script or HTML via the k parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%22 October 2008
CVE-2008-4671Cross-site scripting (XSS) vulnerability in wp-admin/wp-blogs.php in Wordpress MU (WPMU) before 2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) s and (2) ip_address parameters.EXPLOIT ✓MEDIUM 4.3EPSS 3.81%22 October 2008
CVE-2008-4670Cross-site scripting (XSS) vulnerability in search.php in Ed Pudol Clickbank Portal allows remote attackers to inject arbitrary web script or HTML via the search box.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%22 October 2008
CVE-2008-4669Cross-site scripting (XSS) vulnerability in search.php in Dan Fletcher Recipe Script allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%22 October 2008
CVE-2008-4668Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 9.0EPSS 21.5%22 October 2008
CVE-2008-4667Directory traversal vulnerability in rss.php in ArabCMS 2.0 beta 1 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.36%22 October 2008
CVE-2008-4666SQL injection vulnerability in webboard.php in Ultimate Webboard 3.00 allows remote attackers to execute arbitrary SQL commands via the Category parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.91%22 October 2008
CVE-2008-4665SQL injection vulnerability in PG Matchmaking allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) news_read.php and (2) gifts_show.php.EXPLOIT ✓HIGH 7.5EPSS 1.15%22 October 2008
CVE-2008-4662Directory traversal vulnerability in admin.php in LokiCMS 0.3.4, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 2.44%22 October 2008
CVE-2008-4664Heap-based buffer overflow in QvodInsert.QvodCtrl.1 ActiveX control (QvodInsert.dll) in QVOD Player before 2.1.5 build 0053 allows remote attackers to execute arbitrary code via a long URL property.EXPLOIT ✓HIGH 9.3EPSS 6.29%22 October 2008
CVE-2008-4654Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows remote attackers to execute arbitrary code via a TiVo TY media file with a header containing a crafted…EXPLOIT ×3 ✓HIGH 9.3EPSS 57.5%22 October 2008
CVE-2008-4653SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%22 October 2008
CVE-2008-4652Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execute arbitrary code via a long SecretKey property.EXPLOIT ×2 ✓HIGH 9.3EPSS 10.1%22 October 2008
CVE-2008-4651Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby parameter to admin/cms/images.php and the (2) nav_id parameter in an editrecord action to admin/cms/nav.php.EXPLOIT ×2 ✓MEDIUM 6.0EPSS 0.80%22 October 2008
CVE-2008-4650SQL injection vulnerability in viewevent.php in myEvent 1.6 allows remote attackers to execute arbitrary SQL commands via the eventdate parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%22 October 2008
CVE-2008-4649Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.EXPLOIT ✓HIGH 7.5EPSS 2.45%22 October 2008
CVE-2008-4648Cross-site scripting (XSS) vulnerability in index.php in Elxis CMS 2008.1 revision 2204 allows remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO or the (2) option, (3) Itemid, (4) id, (5) task, (6) bid, and (7) contact_id…EXPLOIT ✓MEDIUM 4.3EPSS 1.46%22 October 2008
CVE-2008-4645plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.EXPLOIT ✓HIGH 9.0EPSS 7.12%22 October 2008
CVE-2008-4644hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For HTTP header.EXPLOIT ✓HIGH 7.5EPSS 2.65%22 October 2008
CVE-2008-4643SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands via the sortby parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%22 October 2008
CVE-2008-4642SQL injection vulnerability in profile.php in AstroSPACES 1.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.EXPLOIT ✓HIGH 7.5EPSS 1.00%21 October 2008
CVE-2008-4632Multiple directory traversal vulnerabilities in index.php in Kure 0.6.3, when magic_quotes_gpc is disabled, allow remote attackers to read and possibly execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.93%21 October 2008
CVE-2008-4628SQL injection vulnerability in del.php in myWebland miniBloggie 1.0 allows remote attackers to execute arbitrary SQL commands via the post_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%21 October 2008
CVE-2008-4627SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote attackers to execute arbitrary SQL commands via the itemID parameter in the RGalleryImageWrapper page in index.php.EXPLOIT ✓HIGH 7.5EPSS 1.04%21 October 2008
CVE-2008-4626Directory traversal vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 and possibly other versions through 2.3.3-beta0, when magic_quotes_gpc is disabled, allows remote attackers to include and…EXPLOIT ✓MEDIUM 6.8EPSS 5.00%21 October 2008
CVE-2008-4625SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the newsletter parameter, a different vector than CVE-2008-0683.EXPLOIT ✓HIGH 7.5EPSS 2.73%21 October 2008
CVE-2008-4624PHP remote file inclusion vulnerability in init.php in Fast Click SQL Lite 1.1.7, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CFG[CDIR] parameter.EXPLOIT ✓HIGH 9.3EPSS 3.56%21 October 2008
CVE-2008-4623SQL injection vulnerability in the DS-Syndicate (com_ds-syndicate) component 1.1.1 for Joomla allows remote attackers to execute arbitrary SQL commands via the feed_id parameter to index2.php.EXPLOIT ✓HIGH 7.5EPSS 1.15%21 October 2008
CVE-2008-4622The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and gain administrative access by setting the fn-loggedin cookie to 1.EXPLOIT ✓HIGH 7.5EPSS 3.10%21 October 2008
CVE-2008-4621SQL injection vulnerability in bannerclick.php in ZeeScripts Zeeproperty allows remote attackers to execute arbitrary SQL commands via the adid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.15%21 October 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.