SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,466 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 275 of 501

CVESummaryPriorityPublished
CVE-2008-4145SQL injection vulnerability in user_read_links.php in Addalink 1.0 beta 4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the category_id parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.94%24 September 2008
CVE-2008-4144SQL injection vulnerability in index.php in ACG-ScriptShop E-Gold Script Shop allows remote attackers to execute arbitrary SQL commands via the cid parameter in a showcat action.EXPLOIT ✓HIGH 7.5EPSS 1.01%24 September 2008
CVE-2008-4142SQL injection vulnerability in article.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via the es_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.18%24 September 2008
CVE-2008-4141Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the web_root parameter to (1) includes/function_core.php and (2) templates/layout_lyrics.php.EXPLOIT ✓HIGH 7.5EPSS 3.01%24 September 2008
CVE-2008-4140Cross-site scripting (XSS) vulnerability in admin.php in Quick.Cart 3.1 allows remote attackers to inject arbitrary web script or HTML via the query string.EXPLOIT ✓MEDIUM 4.3EPSS 1.47%24 September 2008
CVE-2008-4139Cross-site scripting (XSS) vulnerability in admin.php in OpenSolution Quick.Cms.Lite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query string.EXPLOIT ✓LOW 2.6EPSS 1.52%24 September 2008
CVE-2008-4138PHP remote file inclusion vulnerability in skin_shop/standard/3_plugin_twindow/twindow_notice.php in TECHNOTE 7 allows remote attackers to execute arbitrary PHP code via a URL in the shop_this_skin_path parameter.EXPLOIT ✓HIGH 10.0EPSS 10.3%24 September 2008
CVE-2008-4137PHP remote file inclusion vulnerability in footer.php in PHP-Crawler 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the footer_file parameter.EXPLOIT ✓HIGH 7.5EPSS 2.50%24 September 2008
CVE-2008-4136Michael Roth Software Personal FTP Server (PFT) 6.0f allows remote attackers to cause a denial of service (service crash) via multiple RETR commands, possibly involving long filenames.EXPLOIT ✓MEDIUM 5.0EPSS 3.22%24 September 2008
CVE-2008-4189Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOIT ✓UnscoredEPSS —23 September 2008
CVE-2008-4187Directory traversal vulnerability in index.php in ProActive CMS allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 4.3EPSS 2.35%23 September 2008
CVE-2008-4186SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id_doc parameter.EXPLOIT ✓HIGH 7.5EPSS 0.91%23 September 2008
CVE-2008-4185SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id parameter in a documentos action, a different vector than CVE-2008-3213.EXPLOIT ✓HIGH 7.5EPSS 1.15%23 September 2008
CVE-2008-4183IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup via a direct request to a backup/backup-yyyy-dd-mm.sql filename.EXPLOIT ✓MEDIUM 5.0EPSS 3.23%23 September 2008
CVE-2008-4181Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Register Globals is enabled, allows remote authenticated users to include and execute arbitrary local files…EXPLOIT ✓MEDIUM 6.8EPSS 2.81%23 September 2008
CVE-2008-4179Multiple cross-site scripting (XSS) vulnerabilities in NooMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) page_id parameter to smileys.php and the (2) q parameter to search.php.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.54%23 September 2008
CVE-2008-4178SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and Downline Goldmine Builder allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ×4 ✓HIGH 7.5EPSS 3.38%23 September 2008
CVE-2008-4177SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the c parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%23 September 2008
CVE-2008-4176SQL injection vulnerability in izle.asp in FoT Video scripti 1.1 beta allows remote attackers to execute arbitrary SQL commands via the oyun parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%23 September 2008
CVE-2008-4175Multiple SQL injection vulnerabilities in Link Bid Script 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) ucat parameter to upgrade.php and the (2) id parameter to linkadmin/edit.php.EXPLOIT ✓MEDIUM 6.5EPSS 1.06%23 September 2008
CVE-2008-4174Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dynamic MP3 Lister 2.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) currentpath, (2) invert, (3) search, and (4) sort parameters.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%23 September 2008
CVE-2008-4164cron.php in MemHT Portal 3.9.0 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.EXPLOIT ✓LOW 2.6EPSS 2.24%22 September 2008
CVE-2008-4161SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands and conduct session fixation attacks via a combination of crafted order and order_by parameters in a search_all action.EXPLOIT ✓MEDIUM 6.8EPSS 1.98%22 September 2008
CVE-2008-4173SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the random parameter to the default URI.EXPLOIT ✓HIGH 7.5EPSS 1.00%22 September 2008
CVE-2008-4172SQL injection vulnerability in page.php in Cars & Vehicle (aka Cars-Vehicle Script) allows remote attackers to execute arbitrary SQL commands via the lnkid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%22 September 2008
CVE-2008-4169SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute arbitrary SQL commands via the produid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%22 September 2008
CVE-2008-4167useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add or (2) remove an Administrator account.EXPLOIT ✓MEDIUM 6.4EPSS 2.61%22 September 2008
CVE-2008-4166Integer overflow in the JavaScript engine in Avant Browser 11.7 Build 9 and earlier allows remote attackers to cause a denial of service (application crash) by attempting to URL encode a string containing many instances of an invalid character.EXPLOIT ✓MEDIUM 4.3EPSS 2.18%22 September 2008
CVE-2008-4159SQL injection vulnerability in index.php in Jaw Portal and Zanfi CMS lite and allows remote attackers to execute arbitrary SQL commands via the page (pageid) parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%22 September 2008
CVE-2008-4158Multiple directory traversal vulnerabilities in index.php in Zanfi CMS lite 1.2 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.98%22 September 2008
CVE-2008-4157SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 1.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2007-3610.EXPLOIT ×2 ✓HIGH 7.5EPSS 5.65%22 September 2008
CVE-2008-4156SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.94%19 September 2008
CVE-2008-4155Multiple directory traversal vulnerabilities in EasySite 2.3 allow remote attackers to read arbitrary files or list directories via a ..EXPLOIT ✓HIGH 7.8EPSS 3.00%19 September 2008
CVE-2008-4154SQL injection vulnerability in living-e webEdition CMS allows remote attackers to execute arbitrary SQL commands via the we_objectID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%19 September 2008
CVE-2008-4135Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause a denial of service (device crash) via multiple deauthentication (DeAuth) frames.EXPLOIT ✓HIGH 7.8EPSS 4.42%19 September 2008
CVE-2008-4134PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other versions before 0.05, allows remote attackers to execute arbitrary PHP code via a URL in the INC parameter.EXPLOIT ✓HIGH 7.5EPSS 7.66%19 September 2008
CVE-2008-4133The web proxy service on the D-Link DIR-100 with firmware 1.12 and earlier does not properly filter web requests with large URLs, which allows remote attackers to bypass web restriction filters.EXPLOIT ✓MEDIUM 4.3EPSS 4.25%19 September 2008
CVE-2008-4131Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors related to handling of tags with (1) the -t option and (2) the :tag command in the (a) vi, (b) ex, (c) vedit, (d) view, and (e) edit…EXPLOIT ✓HIGH 7.2EPSS 0.77%19 September 2008
CVE-2008-4128Cisco IOS Cross-Site Request Forgery VulnerabilityKEVEXPLOIT ✓HIGH 8.1EPSS 33.9%18 September 2008
CVE-2008-4101Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute…EXPLOIT ✓HIGH 9.3EPSS 9.21%18 September 2008
CVE-2008-4116Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long type attribute in a quicktime tag (1) on a web page or embedded in a (2) .mp4 or…EXPLOIT ✓HIGH 9.3EPSS 11.6%18 September 2008
CVE-2008-4096libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function.EXPLOIT ✓HIGH 8.5EPSS 11.2%18 September 2008
CVE-2008-3195Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows remote attackers to read arbitrary files via a query string containing a ..EXPLOIT ×2 ✓MEDIUM 6.8EPSS 8.28%18 September 2008
CVE-2008-4115TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.EXPLOIT ✓MEDIUM 5.0EPSS 2.59%16 September 2008
CVE-2008-4114srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via…EXPLOIT ✓HIGH 7.1EPSS 49.3%16 September 2008
CVE-2008-4113The sctp_getsockopt_hmac_ident function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, relies on an untrusted length value to limit…EXPLOIT ✓MEDIUM 4.7EPSS 0.83%16 September 2008
CVE-2008-4112Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOIT ×2 ✓UnscoredEPSS —16 September 2008
CVE-2008-3950Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iPhone 1.1.4 and 2.0 and iPod touch 1.1.4 and 2.0 allows remote attackers to cause a denial of service (browser crash) via a JavaScript…EXPLOIT ✓MEDIUM 5.0EPSS 7.08%16 September 2008
CVE-2008-4093SQL injection vulnerability in memberstats.php in YourOwnBux 3.1 and 3.2 beta, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.91%15 September 2008
CVE-2008-4092SQL injection vulnerability in printfeature.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitrary SQL commands via the artid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.19%15 September 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.