SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,447 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 272 of 501

CVESummaryPriorityPublished
CVE-2008-4528Directory traversal vulnerability in notes.php in Phlatline's Personal Information Manager (pPIM) 1.01 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ×4 ✓HIGH 7.5EPSS 2.55%9 October 2008
CVE-2008-4527SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the kat_id parameter in a kategorier action.EXPLOIT ✓HIGH 7.5EPSS 1.00%9 October 2008
CVE-2008-4526Multiple directory traversal vulnerabilities in CCMS 3.1 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 10.0EPSS 3.46%9 October 2008
CVE-2008-4525SQL injection vulnerability in index.php in AmpJuke 0.7.5 allows remote attackers to execute arbitrary SQL commands via the special parameter in a performerid action.EXPLOIT ✓HIGH 7.5EPSS 0.96%9 October 2008
CVE-2008-4524SQL injection vulnerability in the "Check User" feature (includes/check_user.php) in AdaptCMS Lite and AdaptCMS Pro 1.3 allows remote attackers to execute arbitrary SQL commands via the user_name parameter.EXPLOIT ✓HIGH 7.5EPSS 1.25%9 October 2008
CVE-2008-4523SQL injection vulnerability in login.php in IP Reg 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the user_name parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%9 October 2008
CVE-2008-4522Multiple directory traversal vulnerabilities in JMweb MP3 Music Audio Search and Download Script allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.50%9 October 2008
CVE-2008-4521SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the INFO_RAID_ID parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%9 October 2008
CVE-2008-4519Multiple directory traversal vulnerabilities in Fastpublish CMS 1.9999 d allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.37%9 October 2008
CVE-2008-4518Multiple SQL injection vulnerabilities in Fastpublish CMS 1.9.9.9.9 d (1.9999 d) allow remote attackers to execute arbitrary SQL commands via the (1) sprache parameter to index2.php and the (2) artikel parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.00%9 October 2008
CVE-2008-4517SQL injection vulnerability in leggi.php in geccBBlite 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%9 October 2008
CVE-2008-4516SQL injection vulnerability in galerie.php in Galerie 3.2 allows remote attackers to execute arbitrary SQL commands via the pic parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%9 October 2008
CVE-2008-4514The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a font tag with a long color value, which triggers an assertion error.EXPLOIT ×2 ✓MEDIUM 5.0EPSS 7.74%9 October 2008
CVE-2008-4510Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page fault and system crash) via multiple attempts to access a virtual address in a PAGE_NOACCESS memory page.EXPLOIT ✓MEDIUM 4.9EPSS 3.26%9 October 2008
CVE-2008-4509Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request…EXPLOIT ×3 ✓HIGH 10.0EPSS 7.66%9 October 2008
CVE-2008-4508Stack-based buffer overflow in the file parsing function in Tonec Internet Download Manager, possibly 5.14 and earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted AppleDouble file…EXPLOIT ✓HIGH 7.8EPSS 5.72%9 October 2008
CVE-2008-4502Multiple PHP remote file inclusion vulnerabilities in DataFeedFile (DFF) PHP Framework API allow remote attackers to execute arbitrary PHP code via a URL in the DFF_config[dir_include] parameter to (1) DFF_affiliate_client_API.php, (2)…EXPLOIT ✓HIGH 10.0EPSS 4.09%9 October 2008
CVE-2008-4501Directory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to overwrite or create arbitrary files via a ..\ (dot dot backslash) in the RNTO command.EXPLOIT ✓HIGH 9.0EPSS 10.7%9 October 2008
CVE-2008-4500Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted stou command, probably related to MS-DOS device names, as demonstrated using "con:1".EXPLOIT ✓MEDIUM 4.0EPSS 10.3%9 October 2008
CVE-2008-4499Multiple directory traversal vulnerabilities in PHP Web Explorer 0.99b and earlier allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ×2 ✓HIGH 9.3EPSS 2.86%9 October 2008
CVE-2008-4498SQL injection vulnerability in searchresults.php in PHP Autos 2.9.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%9 October 2008
CVE-2008-4497SQL injection vulnerability in event_detail.php in Built2Go Real Estate Listings 1.5 allows remote attackers to execute arbitrary SQL commands via the event_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%9 October 2008
CVE-2008-4496SQL injection vulnerability in view_cat.php in PHP Realtor 1.5 allows remote attackers to execute arbitrary SQL commands via the v_cat parameter.EXPLOIT ✓HIGH 7.5EPSS 1.20%9 October 2008
CVE-2008-4495SQL injection vulnerability in view_cat.php in PHP Auto Dealer 2.7 allows remote attackers to execute arbitrary SQL commands via the v_cat parameter.EXPLOIT ✓HIGH 7.5EPSS 1.20%9 October 2008
CVE-2008-4494SQL injection vulnerability in completed-advance.php in TorrentTrader Classic 1.08 and 1.04 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%9 October 2008
CVE-2008-4493Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to…EXPLOIT ✓MEDIUM 6.8EPSS 17.6%8 October 2008
CVE-2008-4492SQL injection vulnerability in referrals.php in YourOwnBux 4.0 allows remote attackers to execute arbitrary SQL commands via the usNick cookie.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97%8 October 2008
CVE-2008-4490Directory traversal vulnerability in config.inc.php in phpAbook 0.8.8b and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 5.1EPSS 1.91%8 October 2008
CVE-2008-4486Directory traversal vulnerability in index.php in SAC.php (SACphp), as used in Yerba 6.3 and earlier, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ×2 ✓HIGH 10.0EPSS 4.78%8 October 2008
CVE-2008-4484main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to "users," as demonstrated via index.php.EXPLOIT ✓MEDIUM 6.8EPSS 2.57%8 October 2008
CVE-2008-4483Directory traversal vulnerability in index.php in Crux Gallery 1.32 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.86%8 October 2008
CVE-2008-3834The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.EXPLOIT ✓LOW 2.1EPSS 4.58%7 October 2008
CVE-2008-4472The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to execute arbitrary programs via the second argument to the ApplyPatch…EXPLOIT ✓HIGH 9.3EPSS 7.84%7 October 2008
CVE-2008-4471Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to overwrite arbitrary files…EXPLOIT ✓HIGH 9.3EPSS 6.73%7 October 2008
CVE-2008-4421Directory traversal vulnerability in MetaGauge 1.0.0.17, and probably other versions before 1.0.3.38, allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in the URL.EXPLOIT ✓HIGH 7.8EPSS 3.79%7 October 2008
CVE-2008-4393Cross-site scripting (XSS) vulnerability in VeriSign Kontiki Delivery Management System (DMS) 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to zodiac/servlet/zodiac.EXPLOIT ✓MEDIUM 4.3EPSS 1.79%7 October 2008
CVE-2008-4384Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and iseemedia, allow remote attackers to execute arbitrary code via the (1) url, (2) toolbar, and (3) enableZoomPastMax methods.EXPLOIT ✓HIGH 9.3EPSS 28.7%7 October 2008
CVE-2008-4470Stack-based buffer overflow in Numark CUE 5.0 rev2 allows user-assisted attackers to cause a denial of service (application crash) or execute arbitrary code via an M3U playlist file that contains a long absolute pathname.EXPLOIT ✓HIGH 9.3EPSS 4.61%7 October 2008
CVE-2008-4469SQL injection vulnerability in view_cresume.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbitrary SQL commands via the coder_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%7 October 2008
CVE-2008-4468SQL injection vulnerability in view_news.php in Vastal I-Tech Share Zone allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%7 October 2008
CVE-2008-4467SQL injection vulnerability in show_series_ink.php in Vastal I-Tech Toner Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%7 October 2008
CVE-2008-4466SQL injection vulnerability in view_products_cat.php in Vastal I-Tech Cosmetics Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%7 October 2008
CVE-2008-4465SQL injection vulnerability in view_mags.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%7 October 2008
CVE-2008-4464SQL injection vulnerability in view_mags.php in Vastal I-Tech Mag Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%7 October 2008
CVE-2008-4463SQL injection vulnerability in view_news.php in Vastal I-Tech Jobs Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%7 October 2008
CVE-2008-4462SQL injection vulnerability in view_news.php in Vastal I-Tech Visa Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%7 October 2008
CVE-2008-4461SQL injection vulnerability in advanced_search_results.php in Vastal I-Tech Dating Zone, possibly 0.9.9, allows remote attackers to execute arbitrary SQL commands via the fage parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%7 October 2008
CVE-2008-4460SQL injection vulnerability in game.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL commands via the game_id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%7 October 2008
CVE-2008-4459SQL injection vulnerability in pick_users.php in the groups module in eXtrovert Thyme 1.3 allows remote attackers to execute arbitrary SQL commands via the uname_search parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%7 October 2008
CVE-2008-4458SQL injection vulnerability in listings.php in E-Php B2B Trading Marketplace Script allows remote attackers to execute arbitrary SQL commands via the cid parameter in a product action.EXPLOIT ✓HIGH 7.5EPSS 1.00%7 October 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.