Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,466 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 273 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-4457 | SQL injection vulnerability in inc/inc_statistics.php in MemHT Portal 3.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a stats_res cookie to index.php. | EXPLOIT ✓MEDIUM 6.8EPSS 1.21% | 7 October 2008 |
| CVE-2008-4456 | Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by… | EXPLOIT ✓LOW 2.6EPSS 7.05% | 6 October 2008 |
| CVE-2008-4455 | Directory traversal vulnerability in index.php in EKINdesigns MySQL Quick Admin 1.5.5 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read and execute arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.93% | 6 October 2008 |
| CVE-2008-4454 | Directory traversal vulnerability in EKINdesigns MySQL Quick Admin 1.5.5 allows remote attackers to read and execute arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 2.27% | 6 October 2008 |
| CVE-2008-4453 | The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePro5S.Imaging ActiveX control (gdpicturepro5s.ocx) 5.7.0.1 allows remote attackers to create, overwrite,… | EXPLOIT ✓HIGH 9.3EPSS 10.5% | 6 October 2008 |
| CVE-2008-4452 | Buffer overflow in Cambridge Computer Corporation vxFtpSrv 2.0.3 allows remote attackers to cause a denial of service (crash and hang) and possibly execute arbitrary code via a long CWD request. | EXPLOIT ✓HIGH 9.0EPSS 5.41% | 6 October 2008 |
| CVE-2008-4451 | The SysInspector AntiStealth driver (esiasdrv.sys) 3.0.65535.0 in ESET System Analyzer Tool 1.1.1.0 allows local users to execute arbitrary code via a certain METHOD_NEITHER IOCTL request to \Device\esiasdrv that overwrites a pointer. | EXPLOIT ✓HIGH 7.2EPSS 1.00% | 6 October 2008 |
| CVE-2008-4449 | Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIVMSG message. | EXPLOIT ×3 ✓HIGH 9.3EPSS 38.7% | 6 October 2008 |
| CVE-2008-4447 | Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to inject arbitrary web script or HTML via (1) the fn parameter during a dload action, (2) the mask parameter during a search… | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 6 October 2008 |
| CVE-2008-4439 | PHP remote file inclusion vulnerability in admin/bin/patch.php in MartinWood Datafeed Studio before 1.6.3 allows remote attackers to execute arbitrary PHP code via a URL in the INSTALL_FOLDER parameter. | EXPLOIT ✓HIGH 10.0EPSS 3.65% | 3 October 2008 |
| CVE-2008-4438 | Cross-site scripting (XSS) vulnerability in search.php in Datafeed Studio 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 3 October 2008 |
| CVE-2008-4437 | Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. | EXPLOIT ✓HIGH 7.1EPSS 5.64% | 3 October 2008 |
| CVE-2008-4436 | SQL injection vulnerability in bblog_plugins/builtin.help.php in bBlog 0.7.6 allows remote attackers to execute arbitrary SQL commands via the mod parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 3 October 2008 |
| CVE-2008-4435 | Multiple cross-site scripting (XSS) vulnerabilities in the RMSOFT Downloads Plus (rmdp) module 1.5 and 1.7 for Xoops allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to search.php and the (2) id parameter to… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.46% | 3 October 2008 |
| CVE-2008-4434 | Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Created By field in a… | EXPLOIT ✓HIGH 9.3EPSS 11.0% | 3 October 2008 |
| CVE-2008-4432 | Cross-site scripting (XSS) vulnerability in search.php in the RMSOFT MiniShop module 1.0 for Xoops allows remote attackers to inject arbitrary web script or HTML via the itemsxpag parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 3 October 2008 |
| CVE-2008-4428 | Unrestricted file upload vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in the… | EXPLOIT ×3 ✓HIGH 10.0EPSS 7.03% | 3 October 2008 |
| CVE-2008-4427 | changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows remote attackers to change arbitrary passwords. | EXPLOIT ×3 ✓HIGH 7.5EPSS 2.99% | 3 October 2008 |
| CVE-2008-4426 | Cross-site scripting (XSS) vulnerability in events.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to inject arbitrary web script or HTML via the date parameter in a new action. | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.60% | 3 October 2008 |
| CVE-2008-4425 | Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter within a delfile action. | EXPLOIT ×3 ✓HIGH 8.8EPSS 2.97% | 3 October 2008 |
| CVE-2008-4424 | Cross-site scripting (XSS) vulnerability in index.php in Domain Group Network GooCMS 1.02 allows remote attackers to inject arbitrary web script or HTML via the s parameter in a comments action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.46% | 3 October 2008 |
| CVE-2008-4423 | SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the item parameter in a contact modify action. | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 1.09% | 3 October 2008 |
| CVE-2008-4409 | libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a… | EXPLOIT ✓MEDIUM 5.0EPSS 8.53% | 3 October 2008 |
| CVE-2008-4405 | xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, which allows guest OS users to cause a denial of service and possibly have… | EXPLOIT ✓HIGH 7.2EPSS 1.04% | 3 October 2008 |
| CVE-2008-3832 | A certain Fedora patch for the utrace subsystem in the Linux kernel before 2.6.26.5-28 on Fedora 8, and before 2.6.26.5-45 on Fedora 9, allows local users to cause a denial of service (NULL pointer dereference and system crash or hang) via a call to the… | EXPLOIT ✓MEDIUM 4.9EPSS 0.78% | 3 October 2008 |
| CVE-2008-4380 | The web interface in Samsung DVR SHR2040 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, related to the filter for configuration properties and "/x" characters. | EXPLOIT ✓HIGH 7.8EPSS 3.73% | 1 October 2008 |
| CVE-2008-4379 | Cross-site scripting (XSS) vulnerability in report.php in Mr. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 1 October 2008 |
| CVE-2008-4378 | SQL injection vulnerability in report.php in Mr. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 1 October 2008 |
| CVE-2008-4377 | SQL injection vulnerability in index.asp in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the sideid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 1 October 2008 |
| CVE-2008-4376 | SQL injection vulnerability in index.php in Live TV Script allows remote attackers to execute arbitrary SQL commands via the mid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 1 October 2008 |
| CVE-2008-4375 | SQL injection vulnerability in viewprofile.php in Availscript Classmate Script allows remote attackers to execute arbitrary SQL commands via the p parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 1 October 2008 |
| CVE-2008-4374 | SQL injection vulnerability in index.php in CMS Buzz allows remote attackers to execute arbitrary SQL commands via the id parameter in a playgame action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 1 October 2008 |
| CVE-2008-4373 | SQL injection vulnerability in job_seeker/applynow.php in AvailScript Job Portal Script allows remote attackers to execute arbitrary SQL commands via the jid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 1 October 2008 |
| CVE-2008-4372 | Cross-site scripting (XSS) vulnerability in articles.php in AvailScript Article Script allows remote attackers to inject arbitrary web script or HTML via the aIDS parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.49% | 1 October 2008 |
| CVE-2008-4371 | SQL injection vulnerability in articles.php in AvailScript Article Script allows remote attackers to execute arbitrary SQL commands via the aIDS parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 1 October 2008 |
| CVE-2008-4370 | Multiple cross-site scripting (XSS) vulnerabilities in Availscript Photo Album allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to pics.php and the (2) a parameter to view.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 1 October 2008 |
| CVE-2008-4369 | SQL injection vulnerability in pics.php in Availscript Photo Album allows remote attackers to execute arbitrary SQL commands via the sid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 1 October 2008 |
| CVE-2008-4366 | Unrestricted file upload vulnerability in the image upload component in Camera Life 2.6.2b4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file… | EXPLOIT ✓MEDIUM 6.5EPSS 3.06% | 30 September 2008 |
| CVE-2008-4364 | SQL injection vulnerability in default.aspx in ParsaGostar ParsaWeb CMS allows remote attackers to execute arbitrary SQL commands via the (1) id parameter in the "page" page and (2) txtSearch parameter in the "Search" page. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 30 September 2008 |
| CVE-2008-4363 | DLMFENC.sys 1.0.0.28 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) or potentially execute arbitrary code via a certain DLMFENC_IOCTL request to \\.\DLKPFSD_Device that overwrites a pointer, probably related to use of… | EXPLOIT ×2 ✓HIGH 7.2EPSS 1.18% | 30 September 2008 |
| CVE-2008-4362 | The Virtual Token driver (vdlptokn.sys) 1.0.2.43 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) via a crafted IOCTL request to \Device\DLPTokenWalter0. | EXPLOIT ✓MEDIUM 4.9EPSS 0.82% | 30 September 2008 |
| CVE-2008-4361 | Directory traversal vulnerability in PowerPortal 2.0.13 allows remote attackers to list and possibly read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 3.00% | 30 September 2008 |
| CVE-2008-4357 | SQL injection vulnerability in linkto.php in Powie pLink 2.07 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 30 September 2008 |
| CVE-2008-4356 | Multiple SQL injection vulnerabilities in Kasseler CMS 1.1.0 and 1.2.0 allow remote attackers to execute arbitrary SQL commands via (1) the nid parameter to index.php in a View action to the News module; (2) the vid parameter to index.php in a Result… | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 30 September 2008 |
| CVE-2008-4355 | SQL injection vulnerability in showprofil.php in Powie PSCRIPT Forum (aka PHP Forum or pForum) 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 30 September 2008 |
| CVE-2008-4354 | SQL injection vulnerability in the products module in NetArt Media iBoutique 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 30 September 2008 |
| CVE-2008-4353 | SQL injection vulnerability in link.php in Linkarity allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 30 September 2008 |
| CVE-2008-4352 | SQL injection vulnerability in inc/pages/viewprofile.php in phpSmartCom 0.2 allows remote attackers to execute arbitrary SQL commands via the uid parameter in a viewprofile action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 30 September 2008 |
| CVE-2008-4351 | Directory traversal vulnerability in index.php in phpSmartCom 0.2 allows remote attackers to include and execute arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 30 September 2008 |
| CVE-2008-4350 | SQL injection vulnerability in main.php in vbLOGIX Tutorial Script 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 30 September 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.