Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,447 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 271 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-4620 | SQL injection vulnerability in Meeting Room Booking System (MRBS) before 1.4 allows remote attackers to execute arbitrary SQL commands via the area parameter to (1) month.php, and possibly (2) day.php and (3) week.php. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 21 October 2008 |
| CVE-2008-1547 | Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the… | EXPLOIT ✓MEDIUM 4.3EPSS 48.1% | 21 October 2008 |
| CVE-2008-4619 | The RPC subsystem in Sun Solaris 9 allows remote attackers to cause a denial of service (daemon crash) via a crafted request to procedure 8 in program 100000 (rpcbind), related to the XDR_DECODE operation and the taddr2uaddr function. | EXPLOIT ✓HIGH 10.0EPSS 12.0% | 21 October 2008 |
| CVE-2008-4617 | SQL injection vulnerability in the actualite module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 20 October 2008 |
| CVE-2008-4616 | The SpamBam plugin for WordPress allows remote attackers to bypass restrictions and add blog comments by using server-supplied values to calculate a shared key. | EXPLOIT ✓MEDIUM 5.0EPSS 7.29% | 20 October 2008 |
| CVE-2008-4614 | PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to create and delete forums, topics, and replies. | EXPLOIT ✓HIGH 7.5EPSS 3.34% | 20 October 2008 |
| CVE-2008-4613 | SQL injection vulnerability in forums.asp in PortalApp 4.0 allows remote attackers to execute arbitrary SQL commands via the sortby parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.35% | 20 October 2008 |
| CVE-2008-4612 | Cross-site scripting (XSS) vulnerability in PortalApp 4.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) forums.asp and (2) content.asp. | EXPLOIT ✓MEDIUM 4.3EPSS 2.31% | 20 October 2008 |
| CVE-2008-4611 | SQL injection vulnerability in index.php in PHP Arsivimiz Php Ziyaretci Defteri allows remote attackers to execute arbitrary SQL commands via the sayfa parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 20 October 2008 |
| CVE-2008-4610 | MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2) a malformed Ogg Media (OGM) file, as demonstrated by lol-ffplay.ogm, different vectors than… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 9.28% | 20 October 2008 |
| CVE-2008-4606 | Multiple SQL injection vulnerabilities in IP Reg 0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) location_id parameter to locationdel.php and (2) vlan_id parameter to vlanedit.php. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 18 October 2008 |
| CVE-2008-4605 | SQL injection vulnerability in CafeEngine allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) dish.php and (2) menu.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 18 October 2008 |
| CVE-2008-4604 | SQL injection vulnerability in index.php in Easy CafeEngine 1.1 allows remote attackers to execute arbitrary SQL commands via the itemid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 18 October 2008 |
| CVE-2008-4603 | SQL injection vulnerability in search.php in iGaming CMS 2.0 Alpha 1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search_games action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 18 October 2008 |
| CVE-2008-4602 | Directory traversal vulnerability in index.php in Post Affiliate Pro 2.0 allows remote authenticated users to read and possibly execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.5EPSS 2.06% | 18 October 2008 |
| CVE-2008-4601 | Cross-site scripting (XSS) vulnerability in the login feature in Habari CMS 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the habari_username parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.96% | 18 October 2008 |
| CVE-2008-4600 | configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain administrative access by setting the ValidUserAdmin cookie. | EXPLOIT ✓HIGH 7.5EPSS 2.65% | 18 October 2008 |
| CVE-2008-4599 | SQL injection vulnerability in category.php in Mosaic Commerce allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 18 October 2008 |
| CVE-2008-4592 | Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ×2 ✓HIGH 10.0EPSS 4.01% | 16 October 2008 |
| CVE-2008-4591 | Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) lang[access_forbiden] and (2) lang[ident_title] parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 16 October 2008 |
| CVE-2008-4590 | Multiple SQL injection vulnerabilities in Stash 1.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to admin/login.php and (2) the post parameter to admin/news.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 16 October 2008 |
| CVE-2008-4588 | Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long argument to the ABOR command. | EXPLOIT ✓HIGH 10.0EPSS 6.82% | 15 October 2008 |
| CVE-2008-4587 | Insecure method vulnerability in the MSVNClientDownloadManager61Lib.DownloadManager.1 ActiveX control (ISDM.exe 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the… | EXPLOIT ✓HIGH 9.3EPSS 10.5% | 15 October 2008 |
| CVE-2008-4586 | Insecure method vulnerability in the MVSNCLientWebAgent61.WebAgent.1 ActiveX control (isusweb.dll 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the DownloadAndExecute… | EXPLOIT ✓HIGH 9.3EPSS 5.17% | 15 October 2008 |
| CVE-2008-4584 | Insecure method vulnerability in Chilkat Mail 7.8 ActiveX control (ChilkatCert.dll) allows remote attackers to overwrite arbitrary files via a full pathname to the SaveLastError method. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 4.72% | 15 October 2008 |
| CVE-2008-4583 | Insecure method vulnerability in the Chilkat FTP 2.0 ActiveX component (ChilkatCert.dll) allows remote attackers to overwrite arbitrary files via a full pathname in the SavePkcs8File method. | EXPLOIT ✓HIGH 7.5EPSS 5.94% | 15 October 2008 |
| CVE-2008-4582 | Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the… | EXPLOIT ✓MEDIUM 4.3EPSS 10.2% | 15 October 2008 |
| CVE-2008-4574 | SQL injection vulnerability in default.asp in Ayco Okul Portali allows remote attackers to execute arbitrary SQL commands via the linkid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 15 October 2008 |
| CVE-2008-4573 | SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL commands via the kat parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 15 October 2008 |
| CVE-2008-4572 | GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the CWD and LIST commands, which triggers heap corruption related to an improper free… | EXPLOIT ✓HIGH 10.0EPSS 60.7% | 15 October 2008 |
| CVE-2008-4570 | SQL injection vulnerability in index.php in Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 15 October 2008 |
| CVE-2008-4569 | SQL injection vulnerability in xlacomments.asp in XIGLA Software Absolute Poll Manager XE 4.1 allows remote attackers to execute arbitrary SQL commands via the p parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 15 October 2008 |
| CVE-2008-3464 | afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a… | EXPLOIT ✓HIGH 7.2EPSS 4.03% | 15 October 2008 |
| CVE-2008-4558 | Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary code via an XSPF playlist file with a negative identifier tag, which passes a signed comparison. | EXPLOIT ✓MEDIUM 6.8EPSS 8.49% | 15 October 2008 |
| CVE-2008-4557 | plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the text parameter, which is inserted into an executable regular expression. | EXPLOIT ✓HIGH 10.0EPSS 45.3% | 14 October 2008 |
| CVE-2008-4556 | Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted request. | EXPLOIT ×3 ✓HIGH 10.0EPSS 69.9% | 14 October 2008 |
| CVE-2008-4008 | Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 allows remote attackers to affect confidentiality, integrity, and availability via… | EXPLOIT ✓HIGH 10.0EPSS 56.3% | 14 October 2008 |
| CVE-2008-3984 | Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LT and WMSYS.LT, a different… | EXPLOIT ✓MEDIUM 5.5EPSS 41.8% | 14 October 2008 |
| CVE-2008-3983 | Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LT and WMSYS.LT, a different… | EXPLOIT ✓MEDIUM 5.5EPSS 41.8% | 14 October 2008 |
| CVE-2008-4397 | Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to execute arbitrary commands via a .. | EXPLOIT ✓HIGH 10.0EPSS 80.5% | 14 October 2008 |
| CVE-2008-4385 | Husdawg, LLC Systems Requirements Lab 3, as used by Instant Expert Analysis, allows remote attackers to force the download and execution of arbitrary programs via by specifiying a malicious website argument to the Init method in (1) a certain ActiveX… | EXPLOIT ✓HIGH 9.3EPSS 37.7% | 14 October 2008 |
| CVE-2008-4549 | The ImageShack Toolbar ActiveX control (ImageShackToolbar.dll) in ImageShack Toolbar 4.5.7, possibly including 4.5.7.69, allows remote attackers to force the upload of arbitrary image files to the ImageShack site via a file: URI argument to the… | EXPLOIT ✓LOW 2.6EPSS 6.62% | 14 October 2008 |
| CVE-2008-4548 | Stack-based buffer overflow in the PTZCamPanelCtrl ActiveX control (CamPanel.dll) in RTS Sentry 2.1.0.2 allows remote attackers to execute arbitrary code via a long second argument to the ConnectServer method. | EXPLOIT ✓HIGH 9.3EPSS 6.03% | 14 October 2008 |
| CVE-2008-4547 | Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows remote attackers to execute arbitrary code via a long second argument to the TimeSpanFormat method. | EXPLOIT ✓HIGH 9.3EPSS 11.3% | 14 October 2008 |
| CVE-2008-4546 | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows remote web servers to cause a denial of service (NULL pointer dereference and browser crash) by returning a different response when an HTTP request… | EXPLOIT ✓MEDIUM 4.3EPSS 16.8% | 14 October 2008 |
| CVE-2008-3544 | Multiple stack-based buffer overflows in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, and possibly 7.01, 7.50, and 7.53, allow remote attackers to execute arbitrary code via a long (1) REQUEST_SEV_CHANGE (aka number 47), (2)… | EXPLOIT ✓HIGH 9.0EPSS 18.0% | 13 October 2008 |
| CVE-2008-3641 | The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory. | EXPLOIT ✓HIGH 10.0EPSS 24.1% | 10 October 2008 |
| CVE-2008-3432 | Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and 6.3 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames, as demonstrated by the netrw.v3 test case. | EXPLOIT ✓MEDIUM 6.8EPSS 8.62% | 10 October 2008 |
| CVE-2008-4532 | Cross-site scripting (XSS) vulnerability in index.php in MaxiScript Website Directory allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action. | EXPLOIT ✓MEDIUM 4.3EPSS 2.99% | 9 October 2008 |
| CVE-2008-4529 | Multiple PHP remote file inclusion vulnerabilities in asiCMS alpha 0.208 allow remote attackers to execute arbitrary PHP code via a URL in the _ENV[asicms][path] parameter to (1) Association.php, (2) BigMath.php, (3) DiffieHellman.php, (4)… | EXPLOIT ✓HIGH 7.5EPSS 2.47% | 9 October 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.