SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,478 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 278 of 501

CVESummaryPriorityPublished
CVE-2008-3758Multiple cross-site scripting (XSS) vulnerabilities in Lussumo Vanilla 1.1.4 and earlier (1) allow remote attackers to inject arbitrary web script or HTML via the NewPassword parameter to people.php, and allow remote authenticated users to inject…EXPLOIT ✓MEDIUM 4.3EPSS 2.19%21 August 2008
CVE-2008-3756SQL injection vulnerability in tr.php in YourFreeWorld Viral Marketing Script allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.15%21 August 2008
CVE-2008-3755SQL injection vulnerability in view.php in YourFreeWorld Classifieds Script allows remote attackers to execute arbitrary SQL commands via the category parameter.EXPLOIT ✓HIGH 7.5EPSS 1.15%21 August 2008
CVE-2008-3754SQL injection vulnerability in trl.php in YourFreeWorld Stylish Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.95%21 August 2008
CVE-2008-3752SQL injection vulnerability in tr.php in YourFreeWorld Ad-Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%21 August 2008
CVE-2008-3750SQL injection vulnerability in tr.php in YourFreeWorld URL Rotator Script allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.02%21 August 2008
CVE-2008-3749SQL injection vulnerability in tr.php in YourFreeWorld Banner Management Script allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.19%21 August 2008
CVE-2008-3748SQL injection vulnerability in view_group.php in Active PHP Bookmarks (APB) 1.1.02 and 1.2.06 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.01%21 August 2008
CVE-2008-3734Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in a connection…EXPLOIT ✓HIGH 9.3EPSS 13.9%20 August 2008
CVE-2008-3733Stack-based buffer overflow in EO Video (eo-video) 1.36 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a .eop (aka playlist) file with a ProjectElement element that contains a long Name element.EXPLOIT ×2 ✓HIGH 9.3EPSS 6.03%20 August 2008
CVE-2008-3732Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TTA file, which triggers a heap-based…EXPLOIT ✓HIGH 9.3EPSS 13.4%20 August 2008
CVE-2008-3725SQL injection vulnerability in trr.php in YourFreeWorld Ad Board Script allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.02%20 August 2008
CVE-2008-3723Directory traversal vulnerability in index.php in PHPizabi 0.848b C1 HFP3 allows remote authenticated administrators to read arbitrary files via (1) a ..EXPLOIT ✓MEDIUM 6.3EPSS 3.93%20 August 2008
CVE-2008-3722SQL injection vulnerability in forum/neu.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the kat parameter.EXPLOIT ✓HIGH 7.5EPSS 0.96%20 August 2008
CVE-2008-3721PHP remote file inclusion vulnerability in user_language.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary PHP code via a URL in the language_dir parameter.EXPLOIT ✓HIGH 7.5EPSS 2.45%20 August 2008
CVE-2008-3720SQL injection vulnerability in index.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary SQL commands via the page parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%20 August 2008
CVE-2008-3719SQL injection vulnerability in directory.php in SFS Affiliate Directory allows remote attackers to execute arbitrary SQL commands via the id parameter in a deadlink action.EXPLOIT ✓HIGH 7.5EPSS 1.00%20 August 2008
CVE-2008-3718Multiple SQL injection vulnerabilities in cyberBB 0.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter to show_topic.php and the (2) user parameter to profile.php.EXPLOIT ✓MEDIUM 6.5EPSS 0.90%20 August 2008
CVE-2008-3715Cross-site scripting (XSS) vulnerability in inc-core-admin-editor-previouscolorsjs.php in the FlexCMS 2.5 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the PreviousColorsString parameter.EXPLOIT ✓LOW 2.6EPSS 1.56%19 August 2008
CVE-2008-3714Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.EXPLOIT ✓MEDIUM 4.3EPSS 5.60%19 August 2008
CVE-2008-3713SQL injection vulnerability in product.php in PHPBasket allows remote attackers to execute arbitrary SQL commands via the pro_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%19 August 2008
CVE-2008-3712Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.2 and 4.6.5, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) query string to…EXPLOIT ×2 ✓LOW 2.6EPSS 1.88%19 August 2008
CVE-2008-3711SQL injection vulnerability in index.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter in a browse action.EXPLOIT ✓HIGH 7.5EPSS 1.04%19 August 2008
CVE-2008-3708Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 4.3EPSS 4.64%19 August 2008
CVE-2008-3706SQL injection vulnerability in bannerclick.php in ZEEJOBSITE 2.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%19 August 2008
CVE-2008-2737Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOIT ✓UnscoredEPSS —18 August 2008
CVE-2008-3704Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1…EXPLOIT ×3 ✓HIGH 9.3EPSS 55.9%18 August 2008
CVE-2008-2936Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a…EXPLOIT ✓MEDIUM 6.2EPSS 0.99%18 August 2008
CVE-2008-3533Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to execute arbitrary code via format string specifiers in an invalid URI on the command line, as…EXPLOIT ✓HIGH 10.0EPSS 19.4%18 August 2008
CVE-2008-3702Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used in products such as SpeedBit Download Accelerator Plus (DAP) 8.6, allow remote attackers to execute arbitrary code via a long…EXPLOIT ✓HIGH 9.3EPSS 9.73%15 August 2008
CVE-2008-3701SQL injection vulnerability in staff/index.php in Kayako SupportSuite 3.20.02 and earlier allows remote authenticated users to execute arbitrary SQL commands via the customfieldlinkid parameter in a delcflink action.EXPLOIT ✓MEDIUM 6.5EPSS 1.93%15 August 2008
CVE-2008-3700Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the sessionid parameter in a livesupport startclientchat action to visitor/index.php;…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 4.10%15 August 2008
CVE-2008-3443The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a…EXPLOIT ✓MEDIUM 5.0EPSS 15.7%14 August 2008
CVE-2008-3682SQL injection vulnerability in dpage.php in YPN PHP Realty allows remote attackers to execute arbitrary SQL commands via the docID parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.90%14 August 2008
CVE-2008-36811.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the "first enabled user (lowest id)" password, typically for the administrator.EXPLOIT ✓HIGH 7.5EPSS 9.40%14 August 2008
CVE-2008-3680The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) by sending a type 0 packet with an invalid version followed by another packet to…EXPLOIT ✓MEDIUM 5.0EPSS 9.81%14 August 2008
CVE-2008-3679Multiple cross-site scripting (XSS) vulnerabilities in index.php in IDevSpot PhpLinkExchange 1.01 allow remote attackers to inject arbitrary web script or HTML via the catid parameter in a (1) user_add, (2) recip, (3) tellafriend, or (4) contact action,…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.47%14 August 2008
CVE-2008-3676Unspecified vulnerability in the IMAP server in hMailServer 4.4.1 allows remote authenticated users to cause a denial of service (resource exhaustion or daemon crash) via a long series of IMAP commands.EXPLOIT ✓MEDIUM 4.3EPSS 2.76%14 August 2008
CVE-2008-3675Directory traversal vulnerability in classes/imgsize.php in Gelato 0.95 allows remote attackers to read arbitrary files via (1) a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.92%14 August 2008
CVE-2008-3674SQL injection vulnerability in ugroups.php in PozScripts TubeGuru Video Sharing Script allows remote attackers to execute arbitrary SQL commands via the UID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.15%13 August 2008
CVE-2008-3673SQL injection vulnerability in browsecats.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3672.EXPLOIT ✓HIGH 7.5EPSS 1.15%13 August 2008
CVE-2008-3672SQL injection vulnerability in showcategory.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3673.EXPLOIT ✓HIGH 7.5EPSS 0.91%13 August 2008
CVE-2008-3670SQL injection vulnerability in authordetail.php in Article Friendly Pro allows remote attackers to execute arbitrary SQL commands via the autid parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.08%13 August 2008
CVE-2008-3669SQL injection vulnerability in comments.php in ZeeScripts Reviews Opinions Rating Posting Engine Web-Site PHP Script (aka ZeeReviews) allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.15%13 August 2008
CVE-2008-3668Multiple cross-site scripting (XSS) vulnerabilities in the Yogurt Social Network module 3.2 rc1 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the uid parameter to (1) friends.php, (2) seutubo.php, (3) album.php, (4)…EXPLOIT ×6 ✓MEDIUM 4.3EPSS 1.54%13 August 2008
CVE-2008-3667Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTTP header.EXPLOIT ✓MEDIUM 6.8EPSS 6.87%13 August 2008
CVE-2008-3657The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by…EXPLOIT ✓HIGH 7.5EPSS 13.7%13 August 2008
CVE-2008-3656Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows…EXPLOIT ✓HIGH 7.8EPSS 70.2%13 August 2008
CVE-2008-3655Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to critical variables and methods at various safe levels, which allows context-dependent attackers to bypass intended…EXPLOIT ×2 ✓HIGH 7.5EPSS 14.1%13 August 2008
CVE-2008-3649SQL injection vulnerability in categorydetail.php in Article Friendly Standard allows remote attackers to execute arbitrary SQL commands via the Cat parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.12%13 August 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.