Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,466 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 275 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-4145 | SQL injection vulnerability in user_read_links.php in Addalink 1.0 beta 4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the category_id parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.94% | 24 September 2008 |
| CVE-2008-4144 | SQL injection vulnerability in index.php in ACG-ScriptShop E-Gold Script Shop allows remote attackers to execute arbitrary SQL commands via the cid parameter in a showcat action. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 24 September 2008 |
| CVE-2008-4142 | SQL injection vulnerability in article.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via the es_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.18% | 24 September 2008 |
| CVE-2008-4141 | Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the web_root parameter to (1) includes/function_core.php and (2) templates/layout_lyrics.php. | EXPLOIT ✓HIGH 7.5EPSS 3.01% | 24 September 2008 |
| CVE-2008-4140 | Cross-site scripting (XSS) vulnerability in admin.php in Quick.Cart 3.1 allows remote attackers to inject arbitrary web script or HTML via the query string. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 24 September 2008 |
| CVE-2008-4139 | Cross-site scripting (XSS) vulnerability in admin.php in OpenSolution Quick.Cms.Lite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query string. | EXPLOIT ✓LOW 2.6EPSS 1.52% | 24 September 2008 |
| CVE-2008-4138 | PHP remote file inclusion vulnerability in skin_shop/standard/3_plugin_twindow/twindow_notice.php in TECHNOTE 7 allows remote attackers to execute arbitrary PHP code via a URL in the shop_this_skin_path parameter. | EXPLOIT ✓HIGH 10.0EPSS 10.3% | 24 September 2008 |
| CVE-2008-4137 | PHP remote file inclusion vulnerability in footer.php in PHP-Crawler 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the footer_file parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.50% | 24 September 2008 |
| CVE-2008-4136 | Michael Roth Software Personal FTP Server (PFT) 6.0f allows remote attackers to cause a denial of service (service crash) via multiple RETR commands, possibly involving long filenames. | EXPLOIT ✓MEDIUM 5.0EPSS 3.22% | 24 September 2008 |
| CVE-2008-4189 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ✓UnscoredEPSS — | 23 September 2008 |
| CVE-2008-4187 | Directory traversal vulnerability in index.php in ProActive CMS allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 2.35% | 23 September 2008 |
| CVE-2008-4186 | SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id_doc parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 23 September 2008 |
| CVE-2008-4185 | SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id parameter in a documentos action, a different vector than CVE-2008-3213. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 23 September 2008 |
| CVE-2008-4183 | IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup via a direct request to a backup/backup-yyyy-dd-mm.sql filename. | EXPLOIT ✓MEDIUM 5.0EPSS 3.23% | 23 September 2008 |
| CVE-2008-4181 | Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Register Globals is enabled, allows remote authenticated users to include and execute arbitrary local files… | EXPLOIT ✓MEDIUM 6.8EPSS 2.81% | 23 September 2008 |
| CVE-2008-4179 | Multiple cross-site scripting (XSS) vulnerabilities in NooMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) page_id parameter to smileys.php and the (2) q parameter to search.php. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.54% | 23 September 2008 |
| CVE-2008-4178 | SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and Downline Goldmine Builder allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ×4 ✓HIGH 7.5EPSS 3.38% | 23 September 2008 |
| CVE-2008-4177 | SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the c parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 23 September 2008 |
| CVE-2008-4176 | SQL injection vulnerability in izle.asp in FoT Video scripti 1.1 beta allows remote attackers to execute arbitrary SQL commands via the oyun parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 23 September 2008 |
| CVE-2008-4175 | Multiple SQL injection vulnerabilities in Link Bid Script 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) ucat parameter to upgrade.php and the (2) id parameter to linkadmin/edit.php. | EXPLOIT ✓MEDIUM 6.5EPSS 1.06% | 23 September 2008 |
| CVE-2008-4174 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dynamic MP3 Lister 2.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) currentpath, (2) invert, (3) search, and (4) sort parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 23 September 2008 |
| CVE-2008-4164 | cron.php in MemHT Portal 3.9.0 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message. | EXPLOIT ✓LOW 2.6EPSS 2.24% | 22 September 2008 |
| CVE-2008-4161 | SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands and conduct session fixation attacks via a combination of crafted order and order_by parameters in a search_all action. | EXPLOIT ✓MEDIUM 6.8EPSS 1.98% | 22 September 2008 |
| CVE-2008-4173 | SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the random parameter to the default URI. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 22 September 2008 |
| CVE-2008-4172 | SQL injection vulnerability in page.php in Cars & Vehicle (aka Cars-Vehicle Script) allows remote attackers to execute arbitrary SQL commands via the lnkid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 22 September 2008 |
| CVE-2008-4169 | SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute arbitrary SQL commands via the produid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 22 September 2008 |
| CVE-2008-4167 | useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add or (2) remove an Administrator account. | EXPLOIT ✓MEDIUM 6.4EPSS 2.61% | 22 September 2008 |
| CVE-2008-4166 | Integer overflow in the JavaScript engine in Avant Browser 11.7 Build 9 and earlier allows remote attackers to cause a denial of service (application crash) by attempting to URL encode a string containing many instances of an invalid character. | EXPLOIT ✓MEDIUM 4.3EPSS 2.18% | 22 September 2008 |
| CVE-2008-4159 | SQL injection vulnerability in index.php in Jaw Portal and Zanfi CMS lite and allows remote attackers to execute arbitrary SQL commands via the page (pageid) parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 22 September 2008 |
| CVE-2008-4158 | Multiple directory traversal vulnerabilities in index.php in Zanfi CMS lite 1.2 allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.98% | 22 September 2008 |
| CVE-2008-4157 | SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 1.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2007-3610. | EXPLOIT ×2 ✓HIGH 7.5EPSS 5.65% | 22 September 2008 |
| CVE-2008-4156 | SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.94% | 19 September 2008 |
| CVE-2008-4155 | Multiple directory traversal vulnerabilities in EasySite 2.3 allow remote attackers to read arbitrary files or list directories via a .. | EXPLOIT ✓HIGH 7.8EPSS 3.00% | 19 September 2008 |
| CVE-2008-4154 | SQL injection vulnerability in living-e webEdition CMS allows remote attackers to execute arbitrary SQL commands via the we_objectID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 19 September 2008 |
| CVE-2008-4135 | Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause a denial of service (device crash) via multiple deauthentication (DeAuth) frames. | EXPLOIT ✓HIGH 7.8EPSS 4.42% | 19 September 2008 |
| CVE-2008-4134 | PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other versions before 0.05, allows remote attackers to execute arbitrary PHP code via a URL in the INC parameter. | EXPLOIT ✓HIGH 7.5EPSS 7.66% | 19 September 2008 |
| CVE-2008-4133 | The web proxy service on the D-Link DIR-100 with firmware 1.12 and earlier does not properly filter web requests with large URLs, which allows remote attackers to bypass web restriction filters. | EXPLOIT ✓MEDIUM 4.3EPSS 4.25% | 19 September 2008 |
| CVE-2008-4131 | Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors related to handling of tags with (1) the -t option and (2) the :tag command in the (a) vi, (b) ex, (c) vedit, (d) view, and (e) edit… | EXPLOIT ✓HIGH 7.2EPSS 0.77% | 19 September 2008 |
| CVE-2008-4128 | Cisco IOS Cross-Site Request Forgery Vulnerability | KEVEXPLOIT ✓HIGH 8.1EPSS 33.9% | 18 September 2008 |
| CVE-2008-4101 | Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute… | EXPLOIT ✓HIGH 9.3EPSS 9.21% | 18 September 2008 |
| CVE-2008-4116 | Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long type attribute in a quicktime tag (1) on a web page or embedded in a (2) .mp4 or… | EXPLOIT ✓HIGH 9.3EPSS 11.6% | 18 September 2008 |
| CVE-2008-4096 | libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function. | EXPLOIT ✓HIGH 8.5EPSS 11.2% | 18 September 2008 |
| CVE-2008-3195 | Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows remote attackers to read arbitrary files via a query string containing a .. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 8.28% | 18 September 2008 |
| CVE-2008-4115 | TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function. | EXPLOIT ✓MEDIUM 5.0EPSS 2.59% | 16 September 2008 |
| CVE-2008-4114 | srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via… | EXPLOIT ✓HIGH 7.1EPSS 49.3% | 16 September 2008 |
| CVE-2008-4113 | The sctp_getsockopt_hmac_ident function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, relies on an untrusted length value to limit… | EXPLOIT ✓MEDIUM 4.7EPSS 0.83% | 16 September 2008 |
| CVE-2008-4112 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ×2 ✓UnscoredEPSS — | 16 September 2008 |
| CVE-2008-3950 | Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iPhone 1.1.4 and 2.0 and iPod touch 1.1.4 and 2.0 allows remote attackers to cause a denial of service (browser crash) via a JavaScript… | EXPLOIT ✓MEDIUM 5.0EPSS 7.08% | 16 September 2008 |
| CVE-2008-4093 | SQL injection vulnerability in memberstats.php in YourOwnBux 3.1 and 3.2 beta, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 15 September 2008 |
| CVE-2008-4092 | SQL injection vulnerability in printfeature.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitrary SQL commands via the artid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 15 September 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.