Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,466 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 274 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-4349 | Multiple cross-site scripting (XSS) vulnerabilities in news.php in s0nic Paranews 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) page parameter in a details action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 30 September 2008 |
| CVE-2008-4347 | SQL injection vulnerability in newskom.php in Powie pNews 2.03 allows remote attackers to execute arbitrary SQL commands via the newsid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 30 September 2008 |
| CVE-2008-4346 | Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.84% | 30 September 2008 |
| CVE-2008-4345 | SQL injection vulnerability in download.php in WebPortal CMS 0.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the aid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 30 September 2008 |
| CVE-2008-4344 | SQL injection vulnerability in cat.php in 6rbScript allows remote attackers to execute arbitrary SQL commands via the CatID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 30 September 2008 |
| CVE-2008-4343 | The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to create, overwrite, and modify arbitrary files for execution via a call to the (1) SaveToFile, (2) SaveToTempFile, or (3) AppendBinary… | EXPLOIT ✓HIGH 9.3EPSS 8.68% | 30 September 2008 |
| CVE-2008-4342 | NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers… | EXPLOIT ✓HIGH 9.3EPSS 17.2% | 30 September 2008 |
| CVE-2008-4341 | add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by setting a cookie with admin=yes and login=admin. | EXPLOIT ✓HIGH 7.5EPSS 2.50% | 30 September 2008 |
| CVE-2008-4340 | Google Chrome 0.2.149.29 and 0.2.149.30 allows remote attackers to cause a denial of service (memory consumption) via an HTML document containing a carriage return ("\r\n\r\n") argument to the window.open function. | EXPLOIT ✓MEDIUM 4.3EPSS 4.21% | 30 September 2008 |
| CVE-2008-4336 | Cross-site scripting (XSS) vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to inject arbitrary web script or HTML via the apa_album_ID parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 30 September 2008 |
| CVE-2008-4335 | SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to execute arbitrary SQL commands via the apa_album_ID parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.05% | 30 September 2008 |
| CVE-2008-4334 | PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the infouser cookie to 1. | EXPLOIT ✓HIGH 7.5EPSS 2.33% | 30 September 2008 |
| CVE-2008-4333 | Cross-site scripting (XSS) vulnerability in PHP infoBoard V.7 Plus allows remote attackers to inject arbitrary web script or HTML via the isname parameter in a newtopic action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 30 September 2008 |
| CVE-2008-4332 | SQL injection vulnerability in the showjavatopic function in func.php in PHP infoBoard V.7 Plus allows remote attackers to execute arbitrary SQL commands via the idcat parameter to showtopic.php. | EXPLOIT ✓HIGH 7.5EPSS 1.99% | 30 September 2008 |
| CVE-2008-4331 | Directory traversal vulnerability in library/pagefunctions.inc.php in phpOCS 0.1 beta3 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 30 September 2008 |
| CVE-2008-4330 | Directory traversal vulnerability in index.php in LanSuite 3.3.2 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 30 September 2008 |
| CVE-2008-4329 | PHP remote file inclusion vulnerability in cms/system/openengine.php in openEngine 2.0 beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the oe_classpath parameter. | EXPLOIT ✓HIGH 10.0EPSS 3.50% | 30 September 2008 |
| CVE-2008-4328 | SQL injection vulnerability in site_search.php in EasyRealtorPRO 2008 allows remote attackers to execute arbitrary SQL commands via the (1) item, (2) search_ordermethod, and (3) search_order parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 30 September 2008 |
| CVE-2008-4327 | gdiplus.dll in GDI+ in Microsoft Windows XP SP3 does not properly handle crafted .ico files, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a certain crash.ico file on a web site, and allows… | EXPLOIT ✓MEDIUM 4.3EPSS 15.7% | 30 September 2008 |
| CVE-2008-4324 | The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a series of keypress, click, onkeydown, onkeyup, onmousedown, and… | EXPLOIT ✓MEDIUM 5.0EPSS 8.92% | 29 September 2008 |
| CVE-2008-4323 | Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application crash) via a crafted .ZIP file. | EXPLOIT ✓MEDIUM 4.3EPSS 8.59% | 29 September 2008 |
| CVE-2008-4322 | Stack-based buffer overflow in RealFlex Technologies Ltd. | EXPLOIT ✓HIGH 10.0EPSS 65.1% | 29 September 2008 |
| CVE-2008-4321 | Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long response to the PWD command. | EXPLOIT ×3 ✓HIGH 9.3EPSS 5.78% | 29 September 2008 |
| CVE-2008-4320 | Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.5.94 allow remote attackers to inject arbitrary web script or HTML via (1) the j_username parameter to j_acegi_security_check, (2) the username parameter to notification/list.jsp,… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.86% | 29 September 2008 |
| CVE-2008-4319 | fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin… | EXPLOIT ✓MEDIUM 6.4EPSS 2.30% | 29 September 2008 |
| CVE-2008-4318 | Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter to (1) whois.php or (2) netcmd.php. | EXPLOIT ✓HIGH 10.0EPSS 14.1% | 29 September 2008 |
| CVE-2008-4302 | fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial… | EXPLOIT ✓MEDIUM 5.5EPSS 0.62% | 29 September 2008 |
| CVE-2008-4210 | fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have… | EXPLOIT ✓MEDIUM 4.6EPSS 2.14% | 29 September 2008 |
| CVE-2008-4192 | The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary file. | EXPLOIT ✓MEDIUM 6.9EPSS 0.71% | 29 September 2008 |
| CVE-2008-4120 | Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.804 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) pass parameter to login.php, or the (3) name parameter to contact.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.76% | 29 September 2008 |
| CVE-2008-4295 | Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot)… | EXPLOIT ✓MEDIUM 5.4EPSS 30.1% | 27 September 2008 |
| CVE-2008-4247 | ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute… | EXPLOIT ✓HIGH 7.5EPSS 5.25% | 25 September 2008 |
| CVE-2008-4245 | The Admin Control Panel in Rianxosencabos CMS 0.9 does not require administrator privileges, which allows remote authenticated users to (1) change a user's privileges, (2) delete a user account, or perform unspecified other administrative actions via… | EXPLOIT ✓MEDIUM 6.5EPSS 1.93% | 25 September 2008 |
| CVE-2008-4244 | Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the usuario and pass cookies to 1. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.86% | 25 September 2008 |
| CVE-2008-4243 | Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 3.70% | 25 September 2008 |
| CVE-2008-4241 | SQL injection vulnerability in CJ Ultra Plus 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via an SID cookie. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 25 September 2008 |
| CVE-2008-0016 | Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link. | EXPLOIT ✓HIGH 10.0EPSS 43.9% | 24 September 2008 |
| CVE-2008-4207 | Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers to obtain sensitive information via a direct request, which invokes the phpinfo function. | EXPLOIT ✓MEDIUM 5.0EPSS 3.12% | 24 September 2008 |
| CVE-2008-4206 | PHP remote file inclusion vulnerability in config.php in Attachmax Dolphin 2.1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rel_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.01% | 24 September 2008 |
| CVE-2008-4205 | SQL injection vulnerability in search.php Attachmax Dolphin 2.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a Search action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.18% | 24 September 2008 |
| CVE-2008-4204 | SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute arbitrary SQL commands via the city parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 24 September 2008 |
| CVE-2008-4203 | SQL injection vulnerability in cn_users.php in CzarNews 1.20 and earlier allows remote attackers to execute arbitrary SQL commands via a recook cookie. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.01% | 24 September 2008 |
| CVE-2008-4202 | SQL injection vulnerability in index.php in Gonafish LinksCaffePRO 4.5 allows remote attackers to execute arbitrary SQL commands via the idd parameter in a deadlink action. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 24 September 2008 |
| CVE-2008-3098 | Cross-site scripting (XSS) vulnerability in admin/usercheck.php in fuzzylime (cms) before 3.03 allows remote attackers to inject arbitrary web script or HTML via the user parameter to the login form. | EXPLOIT ✓MEDIUM 4.3EPSS 1.97% | 24 September 2008 |
| CVE-2008-4194 | The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of service (daemon crash) via a long DNS reply with many entries in the answer section, related to a "dangling pointer bug." | EXPLOIT ×3 ✓MEDIUM 5.0EPSS 6.93% | 24 September 2008 |
| CVE-2008-4193 | Stack-based buffer overflow in SecurityGateway.dll in Alt-N Technologies SecurityGateway 1.0.1 allows remote attackers to execute arbitrary code via a long username parameter. | EXPLOIT ×3 ✓HIGH 10.0EPSS 74.6% | 24 September 2008 |
| CVE-2008-4190 | The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the (1) ipseclive.conn and (2) ipsec.olts.remote.log temporary files. | EXPLOIT ✓MEDIUM 4.4EPSS 1.11% | 24 September 2008 |
| CVE-2008-4151 | Directory traversal vulnerability in collect.php in CYASK 3.x allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.92% | 24 September 2008 |
| CVE-2008-4150 | SQL injection vulnerability in picture_category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-3763. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 24 September 2008 |
| CVE-2008-4146 | Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field and (2) change the visit-counter value via a modified counter field. | EXPLOIT ✓MEDIUM 5.0EPSS 2.20% | 24 September 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.