Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,466 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 277 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-3942 | SQL injection vulnerability in landsee.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 5 September 2008 |
| CVE-2008-3941 | Cross-site scripting (XSS) vulnerability in BizDirectory 2.04 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter in a search action to the default URI. | EXPLOIT ✓MEDIUM 4.3EPSS 1.46% | 5 September 2008 |
| CVE-2008-3937 | Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) user_id parameter in an edit action to user_admin.php, the (2) title parameter… | EXPLOIT ×3 ✓MEDIUM 6.1EPSS 1.36% | 5 September 2008 |
| CVE-2008-3926 | Multiple directory traversal vulnerabilities in Content Management Made Easy (CMME) 1.12 allow remote attackers to (1) read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.8EPSS 2.30% | 4 September 2008 |
| CVE-2008-3925 | Cross-site request forgery (CSRF) vulnerability in admin.php in Content Management Made Easy (CMME) 1.12 allows remote attackers to trigger the logout of an administrative user via a logout action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.11% | 4 September 2008 |
| CVE-2008-3924 | The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover (1) account names and (2) password hashes via a… | EXPLOIT ✓MEDIUM 4.3EPSS 2.25% | 4 September 2008 |
| CVE-2008-3923 | Multiple cross-site scripting (XSS) vulnerabilities in statistics.php in Content Management Made Easy (CMME) 1.12 allow remote attackers to inject arbitrary web script or HTML via the (1) page and (2) year parameters in an hstat_year action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.57% | 4 September 2008 |
| CVE-2008-3922 | awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which is used by the multisort function when dynamically creating an anonymous PHP function. | EXPLOIT ×2 ✓HIGH 9.3EPSS 53.2% | 4 September 2008 |
| CVE-2008-3918 | SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the field parameter in a search action. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.91% | 4 September 2008 |
| CVE-2008-3917 | Cross-site scripting (XSS) vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to inject arbitrary web script or HTML via the field parameter in a search action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 4 September 2008 |
| CVE-2008-3906 | CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string. | EXPLOIT ✓MEDIUM 4.3EPSS 7.10% | 4 September 2008 |
| CVE-2008-3892 | Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build… | EXPLOIT ✓HIGH 10.0EPSS 24.4% | 3 September 2008 |
| CVE-2008-3101 | Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the parenttab parameter in an index action to the Products module, as reachable through index.php; (2) the… | EXPLOIT ✓MEDIUM 4.3EPSS 3.77% | 3 September 2008 |
| CVE-2008-3888 | SQL injection vulnerability in members.asp in Mini-NUKE Freehost 2.3 allows remote attackers to execute arbitrary SQL commands via the uid parameter in a member_details action. | EXPLOIT ✓HIGH 7.5EPSS 0.89% | 2 September 2008 |
| CVE-2008-3879 | The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open… | EXPLOIT ✓HIGH 9.3EPSS 3.69% | 2 September 2008 |
| CVE-2008-3878 | Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows remote attackers to execute arbitrary code via long strUrl, strFile, and strPostData parameters to the… | EXPLOIT ×2 ✓HIGH 9.3EPSS 36.2% | 2 September 2008 |
| CVE-2008-3877 | Stack-based buffer overflow in Acoustica Mixcraft 4.1 Build 96 and 4.2 Build 98 allows user-assisted attackers to execute arbitrary code via a crafted .mx4 file. | EXPLOIT ×2 ✓HIGH 9.3EPSS 9.95% | 2 September 2008 |
| CVE-2008-2930 | Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 allow remote attackers to cause a denial of service (CPU consumption and search outage) via crafted LDAP search requests with patterns, related to a… | EXPLOIT ✓HIGH 7.1EPSS 6.55% | 29 August 2008 |
| CVE-2008-3480 | Stack-based buffer overflow in the Anzio Web Print Object (WePO) ActiveX control 3.2.19 and 3.2.24, as used in Anzio Print Wizard, allows remote attackers to execute arbitrary code via a long mainurl parameter. | EXPLOIT ✓HIGH 9.3EPSS 11.2% | 29 August 2008 |
| CVE-2008-3861 | Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in pages.php and (2) the price_max parameter in search.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 29 August 2008 |
| CVE-2008-3859 | Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a direct request to conf/admins.php. | EXPLOIT ✓MEDIUM 5.0EPSS 2.61% | 29 August 2008 |
| CVE-2008-3851 | Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute arbitrary local files via a ..\ (dot dot backslash) in the (1) blogpost, (2) cat, and (3) file parameters to… | EXPLOIT ✓MEDIUM 5.0EPSS 7.94% | 27 August 2008 |
| CVE-2008-3850 | Cross-site scripting (XSS) vulnerability in Accellion File Transfer FTA_7_0_135 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to courier/forgot_password.html. | EXPLOIT ✓MEDIUM 4.3EPSS 1.46% | 27 August 2008 |
| CVE-2008-3848 | SQL injection vulnerability in single.php in Z-Breaknews 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 27 August 2008 |
| CVE-2008-3845 | Multiple SQL injection vulnerabilities in Crafty Syntax Live Help (CSLH) 2.14.6 and earlier allow remote attackers to execute arbitrary SQL commands via the department parameter to (1) is_xmlhttp.php and (2) is_flush.php. | EXPLOIT ✓HIGH 7.5EPSS 1.77% | 27 August 2008 |
| CVE-2008-3790 | The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML document with recursively nested entities, aka an "XML entity explosion." | EXPLOIT ✓MEDIUM 5.0EPSS 15.2% | 27 August 2008 |
| CVE-2007-1682 | Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.4.0 allow remote attackers to execute arbitrary code via unspecified calls to the (1) BuildPath, (2) GetDriveName, (3) DriveExists,… | EXPLOIT ✓HIGH 9.3EPSS 29.6% | 27 August 2008 |
| CVE-2008-3795 | Buffer overflow in Ipswitch WS_FTP Home client allows remote FTP servers to have an unknown impact via a long "message response." | EXPLOIT ✓HIGH 10.0EPSS 15.1% | 27 August 2008 |
| CVE-2008-3794 | Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execute arbitrary code via a crafted mmst link with a negative size value, which bypasses a size check and… | EXPLOIT ✓MEDIUM 6.8EPSS 11.0% | 26 August 2008 |
| CVE-2008-3788 | Multiple SQL injection vulnerabilities in PICTURESPRO Photo Cart 3.9, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) qtitle, (2) qid, and (3) qyear parameters to (a) search.php, and the (4) email… | EXPLOIT ✓MEDIUM 6.8EPSS 1.08% | 26 August 2008 |
| CVE-2008-3787 | SQL injection vulnerability in listing_view.php in Web Directory Script 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 26 August 2008 |
| CVE-2008-3786 | Cross-site scripting (XSS) vulnerability in index.php in PICTURESPRO Photo Cart 3.9 allows remote attackers to inject arbitrary web script or HTML via the qtitle parameter (aka "Gallery or event name" field) in a search action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.46% | 26 August 2008 |
| CVE-2008-3785 | Multiple SQL injection vulnerabilities in the com_content component in MiaCMS 4.6.5 allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) view, (2) category, or (3) blogsection action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.05% | 26 August 2008 |
| CVE-2008-3784 | SQL injection vulnerability in scrape.php in BtiTracker 1.4.7 and earlier and xBtiTracker 2.0.542 and earlier allows remote attackers to execute arbitrary SQL commands via the info_hash parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.65% | 26 August 2008 |
| CVE-2008-3783 | Multiple SQL injection vulnerabilities in index.php in Matterdaddy Market 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) type parameters. | EXPLOIT ✓MEDIUM 6.8EPSS 0.94% | 26 August 2008 |
| CVE-2008-3780 | SQL injection vulnerability in recommend.php in Five Star Review Script allows remote attackers to execute arbitrary SQL commands via the item_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 26 August 2008 |
| CVE-2008-3779 | Cross-site scripting (XSS) vulnerability in search/index.php in Five Star Review Script allows remote attackers to inject arbitrary web script or HTML via the words parameter in a search action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 26 August 2008 |
| CVE-2008-3776 | Directory traversal vulnerability in Fujitsu Web-Based Admin View 2.1.2 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.69% | 25 August 2008 |
| CVE-2008-3774 | SQL injection vulnerability in index.php in Simasy CMS allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 22 August 2008 |
| CVE-2008-3773 | Cross-site scripting (XSS) vulnerability in vBulletin 3.7.2 PL1 and 3.6.10 PL3, when "Show New Private Message Notification Pop-Up" is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a private message subject (aka… | EXPLOIT ✓MEDIUM 4.3EPSS 3.77% | 22 August 2008 |
| CVE-2008-3772 | SQL injection vulnerability in categories_portal.php in Pars4u Videosharing 1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 22 August 2008 |
| CVE-2008-3771 | Cross-site scripting (XSS) vulnerability in members.php in Pars4u Videosharing 1 allows remote attackers to inject arbitrary web script or HTML via the PageNo parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 22 August 2008 |
| CVE-2008-3770 | Multiple directory traversal vulnerabilities in Freeway 1.4.1.171, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ×8 ✓MEDIUM 6.8EPSS 2.39% | 22 August 2008 |
| CVE-2008-3768 | Multiple SQL injection vulnerabilities in class.ajax.php in Turnkey Web Tools SunShop Shopping Cart before 4.1.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in an edit_registry action to index.php, (2) a vector… | EXPLOIT ✓HIGH 7.5EPSS 1.57% | 22 August 2008 |
| CVE-2008-3767 | SQL injection vulnerability in classified.php in phpBazar 2.0.2 allows remote attackers to execute arbitrary SQL commands via the adid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 22 August 2008 |
| CVE-2008-3765 | SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 21 August 2008 |
| CVE-2008-3764 | Eval injection vulnerability in globalsoff.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary PHP code via the test parameter, and probably arbitrary parameters, to chat.php. | EXPLOIT ✓HIGH 7.5EPSS 3.33% | 21 August 2008 |
| CVE-2008-3763 | Variable overwrite vulnerability in libsecure.php in Turnkey PHP Live Helper 2.0.1 and earlier, when register_globals is enabled, allows remote attackers to overwrite arbitrary variables related to the db config file. | EXPLOIT ✓MEDIUM 6.8EPSS 2.58% | 21 August 2008 |
| CVE-2008-3762 | SQL injection vulnerability in onlinestatus_html.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the dep parameter, related to lack of input sanitization in the get function in global.php. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 21 August 2008 |
| CVE-2008-3761 | hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 uses the METHOD_NEITHER communication method for… | EXPLOIT ✓MEDIUM 4.9EPSS 1.00% | 21 August 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.