Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,466 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 276 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-4091 | SQL injection vulnerability in index.php in Web Directory Script 1.5.3 allows remote attackers to execute arbitrary SQL commands via the site parameter in an open action. | EXPLOIT ✓MEDIUM 6.8EPSS 0.95% | 15 September 2008 |
| CVE-2008-4090 | SQL injection vulnerability in index.php in PHP Coupon Script 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in an addtocart action, a different vector than CVE-2007-2672. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 15 September 2008 |
| CVE-2008-4089 | Cross-site scripting (XSS) vulnerability in print.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to inject arbitrary web script or HTML via the sid parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.52% | 15 September 2008 |
| CVE-2008-4088 | SQL injection vulnerability in print.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitrary SQL commands via the sid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 15 September 2008 |
| CVE-2008-4087 | Stack-based buffer overflow in Acoustica Beatcraft 1.02 Build 19 allows user-assisted attackers to cause a denial of service or execute arbitrary code via a Beatcraft Project (aka bcproj) file with a long string in a certain instruments title field. | EXPLOIT ✓MEDIUM 6.8EPSS 3.32% | 15 September 2008 |
| CVE-2008-4086 | SQL injection vulnerability in index.php in Reciprocal Links Manager 1.1 allows remote attackers to execute arbitrary SQL commands via the site parameter in an open action. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 15 September 2008 |
| CVE-2008-4084 | SQL injection vulnerability in staticpages/easyclassifields/index.php in MyioSoft EasyClassifields 3.0 allows remote attackers to execute arbitrary SQL commands via the go parameter in a browse action. | EXPLOIT ✓MEDIUM 6.8EPSS 0.98% | 15 September 2008 |
| CVE-2008-4083 | Cross-site scripting (XSS) vulnerability in the Bookmarks plugin in Brim 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in an addItemPost action to index.php. | EXPLOIT ✓LOW 3.5EPSS 1.33% | 15 September 2008 |
| CVE-2008-4082 | SQL injection vulnerability in the Tasks plugin in Brim 2.0.0, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via an arbitrary field in a search action to index.php. | EXPLOIT ✓MEDIUM 4.6EPSS 0.84% | 15 September 2008 |
| CVE-2008-4081 | admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by setting a bsm cookie. | EXPLOIT ✓HIGH 7.5EPSS 2.56% | 15 September 2008 |
| CVE-2008-4080 | SQL injection vulnerability in Stash 1.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username parameter to admin/library/authenticate.php and the (2) download parameter to downloadmp3.php. | EXPLOIT ✓MEDIUM 6.8EPSS 3.11% | 15 September 2008 |
| CVE-2008-4075 | Directory traversal vulnerability in index.php in D-iscussion Board 3.01 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.90% | 15 September 2008 |
| CVE-2008-4074 | SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.03% | 15 September 2008 |
| CVE-2008-4073 | SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a DBpAGE action. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.05% | 15 September 2008 |
| CVE-2008-4072 | Multiple SQL injection vulnerabilities in index.php in phsBlog 0.2 allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter in a pickup action or (2) the sql_cid parameter, different vectors than CVE-2008-3588. | EXPLOIT ✓HIGH 7.5EPSS 1.36% | 15 September 2008 |
| CVE-2008-4071 | A certain ActiveX control in Adobe Acrobat 9, when used with Microsoft Windows Vista and Internet Explorer 7, allows remote attackers to cause a denial of service (browser crash) via an src property value with an invalid acroie:// URL. | EXPLOIT ✓MEDIUM 5.0EPSS 18.4% | 15 September 2008 |
| CVE-2008-3824 | Cross-site scripting (XSS) vulnerability in (1) Text_Filter/Filter/xss.php in Horde 3.1.x before 3.1.9 and 3.2.x before 3.2.2 and (2) externalinput.php in Popoon r22196 and earlier allows remote attackers to inject arbitrary web script or HTML by using… | EXPLOIT ✓MEDIUM 4.3EPSS 5.15% | 12 September 2008 |
| CVE-2008-3823 | Cross-site scripting (XSS) vulnerability in MIME/MIME/Contents.php in the MIME library in Horde 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via the filename of a MIME attachment in an e-mail message. | EXPLOIT ✓MEDIUM 4.3EPSS 3.29% | 12 September 2008 |
| CVE-2008-3529 | Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name. | EXPLOIT ✓HIGH 10.0EPSS 23.4% | 12 September 2008 |
| CVE-2008-4056 | Cross-site scripting (XSS) vulnerability in admin/login.php in Matterdaddy Market 1.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 11 September 2008 |
| CVE-2008-4055 | SQL injection vulnerability in tops_top.php in Million Pixel Ad Script (Million Pixel Script) allows remote attackers to execute arbitrary SQL commands via the id_cat parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.03% | 11 September 2008 |
| CVE-2008-4054 | SQL injection vulnerability in indir.php in Kolifa.net Download Script 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 11 September 2008 |
| CVE-2008-4053 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Bluemoon PopnupBLOG module 3.20 and 3.30 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the (1) param, (2) cat_id, and (3) view parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 11 September 2008 |
| CVE-2008-4051 | Cross-site scripting (XSS) vulnerability in surveyresults.asp in Smart Survey 1.0 allows remote attackers to inject arbitrary web script or HTML via the sid parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 11 September 2008 |
| CVE-2008-4050 | A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to (1) create and read arbitrary registry values via the RegistryValue method, and (2) read arbitrary files via the… | EXPLOIT ✓HIGH 9.3EPSS 6.75% | 11 September 2008 |
| CVE-2008-4049 | A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to execute arbitrary programs via arguments to the RunApp method. | EXPLOIT ✓MEDIUM 6.8EPSS 4.23% | 11 September 2008 |
| CVE-2008-4048 | Heap-based buffer overflow in a certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to execute arbitrary code via a long third argument to the CreateURLShortcut method. | EXPLOIT ✓MEDIUM 6.8EPSS 6.90% | 11 September 2008 |
| CVE-2008-4046 | SQL injection vulnerability in index.php in eliteCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 11 September 2008 |
| CVE-2008-4044 | SQL injection vulnerability in article/readarticle.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the artid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 11 September 2008 |
| CVE-2008-4043 | Multiple SQL injection vulnerabilities in AJ Square AJ HYIP Acme allow remote attackers to execute arbitrary SQL commands via the artid parameter to (1) acme/article/comment.php and (2) prime/article/comment.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 11 September 2008 |
| CVE-2008-4042 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ✓UnscoredEPSS — | 11 September 2008 |
| CVE-2008-4041 | The IMAP server in Softalk Mail Server (formerly WorkgroupMail) 8.5.1.431 allows remote authenticated users to cause a denial of service (resource consumption and daemon crash) via a long IMAP APPEND command with certain repeated parameters. | EXPLOIT ✓MEDIUM 4.0EPSS 2.35% | 11 September 2008 |
| CVE-2008-4039 | SQL injection vulnerability in index.php in Spice Classifieds allows remote attackers to execute arbitrary SQL commands via the cat_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 11 September 2008 |
| CVE-2008-3963 | MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows remote attackers to cause a denial of service (daemon crash) by using this… | EXPLOIT ✓MEDIUM 4.0EPSS 6.46% | 11 September 2008 |
| CVE-2008-3957 | The Microsoft Windows Image Acquisition Logger ActiveX control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in… | EXPLOIT ×2 ✓HIGH 9.3EPSS 17.8% | 11 September 2008 |
| CVE-2008-3956 | orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .opx file. | EXPLOIT ✓HIGH 9.3EPSS 13.4% | 11 September 2008 |
| CVE-2008-3955 | SQL injection vulnerability in index.php in Masir Camp E-Shop Module 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ordercode parameter in a veiworderstatus page. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 11 September 2008 |
| CVE-2008-3954 | SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange allows remote attackers to execute arbitrary SQL commands via the cat parameter in a showcat action. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.18% | 11 September 2008 |
| CVE-2008-3953 | SQL injection vulnerability in keyword_search_action.php in Vastal I-Tech Shaadi Zone 1.0.9 allows remote attackers to execute arbitrary SQL commands via the tage parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 11 September 2008 |
| CVE-2008-3952 | SQL injection vulnerability in questions.php in EsFaq 2.0 allows remote attackers to execute arbitrary SQL commands via the idcat parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 11 September 2008 |
| CVE-2008-3951 | SQL injection vulnerability in view_ann.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the ann_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.05% | 11 September 2008 |
| CVE-2008-3013 | gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint… | EXPLOIT ✓HIGH 9.3EPSS 52.1% | 11 September 2008 |
| CVE-2008-3008 | Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series allows remote attackers to execute arbitrary code via a long first argument to the GetDetailsString method, aka "Windows Media… | EXPLOIT ×2 ✓HIGH 9.3EPSS 54.6% | 11 September 2008 |
| CVE-2008-2326 | mDNSResponder in the Bonjour Namespace Provider in Apple Bonjour for Windows before 1.0.5 allows attackers to cause a denial of service (NULL pointer dereference and application crash) by resolving a crafted .local domain name that contains a long label. | EXPLOIT ✓MEDIUM 5.0EPSS 7.49% | 11 September 2008 |
| CVE-2007-5348 | Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2,… | EXPLOIT ✓HIGH 9.3EPSS 52.9% | 11 September 2008 |
| CVE-2008-3664 | Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTML via (1) the real name field, related to the user list; (2) the target parameter to login.php, (3) the title parameter to… | EXPLOIT ×9 ✓MEDIUM 4.3EPSS 1.49% | 5 September 2008 |
| CVE-2008-3531 | Stack-based buffer overflow in sys/kern/vfs_mount.c in the kernel in FreeBSD 7.0 and 7.1, when vfs.usermount is enabled, allows local users to gain privileges via a crafted (1) mount or (2) nmount system call, related to copying of "user defined data"… | EXPLOIT ✓MEDIUM 6.9EPSS 1.03% | 5 September 2008 |
| CVE-2008-3945 | SQL injection vulnerability in index.php in Words tag 1.2 allows remote attackers to execute arbitrary SQL commands via the word parameter in a claim action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 5 September 2008 |
| CVE-2008-3944 | SQL injection vulnerability in index.php in ACG-PTP 1.0.6 allows remote attackers to execute arbitrary SQL commands via the adid parameter in an adorder action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 5 September 2008 |
| CVE-2008-3943 | SQL injection vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to execute arbitrary SQL commands via the r parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 5 September 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.