SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,478 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 279 of 501

CVESummaryPriorityPublished
CVE-2008-2938Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 99.7%13 August 2008
CVE-2008-2245Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Image Color Management (ICM) component on Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2…EXPLOIT ✓HIGH 9.3EPSS 46.1%13 August 2008
CVE-2008-3607The IMAP server in NoticeWare Email Server NG 4.6.3 and earlier allows remote attackers to cause a denial of service (daemon crash) via multiple long LOGIN commands.EXPLOIT ✓MEDIUM 5.0EPSS 2.67%12 August 2008
CVE-2008-3606Heap-based buffer overflow in the IMAP service in Qbik WinGate 6.2.2.1137 and earlier allows remote authenticated users to cause a denial of service (resource exhaustion) or possibly execute arbitrary code via a long argument to the LIST command.EXPLOIT ✓MEDIUM 6.5EPSS 4.45%12 August 2008
CVE-2008-3604SQL injection vulnerability in bannerclick.php in ZeeBuddy 2.1 allows remote attackers to execute arbitrary SQL commands via the adid parameter.EXPLOIT ✓CRITICAL 9.8EPSS 3.53%12 August 2008
CVE-2008-3603SQL injection vulnerability in index.php in Vacation Rental Script 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a sections action.EXPLOIT ✓HIGH 7.5EPSS 0.97%12 August 2008
CVE-2008-3602admin/wr_admin.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9.1 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.EXPLOIT ✓HIGH 7.5EPSS 2.50%12 August 2008
CVE-2008-3601SQL injection vulnerability in index.php in Quicksilver Forums 1.4.1 allows remote attackers to execute arbitrary SQL commands via the forums array parameter in a search action.EXPLOIT ✓HIGH 7.5EPSS 1.04%12 August 2008
CVE-2008-3599SQL injection vulnerability in image.php in OpenImpro 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%12 August 2008
CVE-2008-3598Multiple SQL injection vulnerabilities in psipuss 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the Cid parameter to categories.php or (2) the Username parameter to login.php.EXPLOIT ✓HIGH 7.5EPSS 1.15%12 August 2008
CVE-2008-3595PHP remote file inclusion vulnerability in examples/txtSQLAdmin/startup.php in txtSQL 2.2 Final allows remote attackers to execute arbitrary PHP code via a URL in the CFG[txtsql][class] parameter.EXPLOIT ✓HIGH 9.3EPSS 2.78%12 August 2008
CVE-2008-3594SQL injection vulnerability in viewdetails.php in MagicScripts E-Store Kit-1, E-Store Kit-2, E-Store Kit-1 Pro PayPal Edition, and E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary SQL commands via the pid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%11 August 2008
CVE-2008-3593Directory traversal vulnerability in index.php in SyzygyCMS 0.3 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.42%11 August 2008
CVE-2008-3592Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in…EXPLOIT ✓HIGH 8.5EPSS 6.81%11 August 2008
CVE-2008-3591SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary SQL commands via the sym_auth cookie in a /publish/filemanager/ request to index.php.EXPLOIT ✓HIGH 7.5EPSS 2.08%11 August 2008
CVE-2008-3590Multiple SQL injection vulnerabilities in admin/login.asp in E.EXPLOIT ✓HIGH 7.5EPSS 0.89%11 August 2008
CVE-2008-3589Directory traversal vulnerability in download.php in moziloCMS 1.10.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 4.3EPSS 2.36%11 August 2008
CVE-2008-3588Multiple SQL injection vulnerabilities in phsBlog 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to comments.php, (2) cid parameter to index.php, and the (3) urltitle parameter to entries.php.EXPLOIT ✓HIGH 7.5EPSS 1.00%11 August 2008
CVE-2008-3587Cross-site scripting (XSS) vulnerability in result.php in Chris Bunting Homes 4 Sale allows remote attackers to inject arbitrary web script or HTML via the r parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.46%11 August 2008
CVE-2008-3586SQL injection vulnerability in the EZ Store (com_ezstore) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.00%11 August 2008
CVE-2008-3585Multiple SQL injection vulnerabilities in PozScripts GreenCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) product_desc.php and (2) store_info.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%11 August 2008
CVE-2008-3583Buffer overflow in the HTML parser in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a long URL in the SRC attribute of an IMG element.EXPLOIT ✓HIGH 7.5EPSS 4.65%10 August 2008
CVE-2008-3582SQL injection vulnerability in login.php in Keld PHP-MySQL News Script 0.7.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.93%10 August 2008
CVE-2008-3581Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links allows remote attackers to inject arbitrary web script or HTML via the login_message parameter in a login action.EXPLOIT ✓MEDIUM 4.3EPSS 1.57%10 August 2008
CVE-2008-3580Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to visit.php, or the PATH_INFO to the default URI under (2) report/, (3) addreview/, or (4) refer/.EXPLOIT ✓HIGH 7.5EPSS 1.20%10 August 2008
CVE-2008-3578HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a long irc:// URI.EXPLOIT ✓MEDIUM 5.0EPSS 7.13%10 August 2008
CVE-2008-3575PHP remote file inclusion vulnerability in modules/calendar/minicalendar.php in ezContents CMS allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[gsLanguage] parameter, a different vector than CVE-2006-4477 and CVE-2004-0132.EXPLOIT ✓HIGH 7.5EPSS 2.27%10 August 2008
CVE-2008-3574Multiple cross-site scripting (XSS) vulnerabilities in Pluck 4.5.2, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) lang_footer parameter to (a) data/inc/footer.php; the (2) pluck_version, (3)…EXPLOIT ✓LOW 2.6EPSS 1.51%10 August 2008
CVE-2008-3573The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_random value) within the URL in the SRC attribute of an IMG element, which allows remote attackers to pass the CAPTCHA…EXPLOIT ✓MEDIUM 5.0EPSS 1.95%10 August 2008
CVE-2008-3571The Xerox Phaser 8400 allows remote attackers to cause a denial of service (reboot) via an empty UDP packet to port 1900.EXPLOIT ✓HIGH 7.8EPSS 35.7%10 August 2008
CVE-2008-3570PHP remote file inclusion vulnerability in index.php in Africa Be Gone (ABG) 1.0a allows remote attackers to execute arbitrary PHP code via a URL in the abg_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.43%10 August 2008
CVE-2008-3569Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.6.7, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the text parameter to (1) iart.php and (2) ming.php.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 3.04%10 August 2008
CVE-2008-3568Absolute path traversal vulnerability in fckeditor/editor/filemanager/browser/default/connectors/php/connector.php in UNAK-CMS 1.5.5 allows remote attackers to include and execute arbitrary local files via a full pathname in the Dirroot parameter, a…EXPLOIT ✓HIGH 7.5EPSS 2.90%10 August 2008
CVE-2008-3566Cross-site scripting (XSS) vulnerability in ZoneO-soft freeForum 1.7 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter to (1) the default URI or (2) index.php, or (3) the PATH_INFO to index.php.EXPLOIT ✓MEDIUM 4.3EPSS 1.47%10 August 2008
CVE-2008-3565Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the area parameter to (1) day.php, (2) week.php, (3) month.php, (4) search.php, (5)…EXPLOIT ×6 ✓MEDIUM 4.3EPSS 1.49%10 August 2008
CVE-2008-3564Multiple directory traversal vulnerabilities in index.php in Dayfox Blog 4 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.46%10 August 2008
CVE-2008-3563Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the checked array parameter to plog-download.php in an album action and (2) unspecified parameters to plog-remote.php, and…EXPLOIT ✓HIGH 7.5EPSS 2.43%10 August 2008
CVE-2008-3562Directory traversal vulnerability in index.php in the Contact module in Chupix CMS 0.1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 5.1EPSS 1.92%10 August 2008
CVE-2008-3561SQL injection vulnerability in s03.php in Powergap Shopsystem, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the ag parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.91%10 August 2008
CVE-2008-3560Cross-site scripting (XSS) vulnerability in kshop_search.php in the Kshop module 2.22 for Xoops allows remote attackers to inject arbitrary web script or HTML via the search parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%8 August 2008
CVE-2008-3559Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice allow remote attackers to inject arbitrary web script or HTML via the (1) filename parameter to search.asp and the (2) page parameter to order.asp.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.49%8 August 2008
CVE-2008-3558Stack-based buffer overflow in the WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before 20.2008.2606.4919 allows remote attackers to execute arbitrary code via a long argument to the NewObject method.EXPLOIT ×2 ✓HIGH 9.3EPSS 65.4%8 August 2008
CVE-2008-3557Free Hosting Manager 1.2 and 2.0 allows remote attackers to bypass authentication and gain administrative access by setting both the adminuser and loggedin cookies.EXPLOIT ✓HIGH 7.5EPSS 2.53%8 August 2008
CVE-2008-3556Multiple SQL injection vulnerabilities in index.php in Battle.net Clan Script 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) showmember parameter in a members action and the (2) thread parameter in a board action.EXPLOIT ✓HIGH 7.5EPSS 0.97%8 August 2008
CVE-2008-3555Directory traversal vulnerability in index.php in (1) WSN Forum 4.1.43 and earlier, (2) Gallery 4.1.30 and earlier, (3) Knowledge Base (WSNKB) 4.1.36 and earlier, (4) Links 4.1.44 and earlier, and possibly (5) Classifieds before 4.1.30 allows remote…EXPLOIT ✓MEDIUM 6.8EPSS 1.93%8 August 2008
CVE-2008-3554SQL injection vulnerability in index.php in Discuz!EXPLOIT ✓HIGH 7.5EPSS 1.00%8 August 2008
CVE-2008-0964Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via a crafted SMB packet.EXPLOIT ✓HIGH 9.3EPSS 13.5%8 August 2008
CVE-2008-3513SQL injection vulnerability in the Book Catalog module 1.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to modules.php.EXPLOIT ✓HIGH 7.5EPSS 1.15%7 August 2008
CVE-2008-3512SQL injection vulnerability in the Kleinanzeigen module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the lid parameter in a visit action to modules.php.EXPLOIT ✓HIGH 7.5EPSS 0.95%7 August 2008
CVE-2008-3511Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c) suggest_image.php, and (d)…EXPLOIT ×9 ✓MEDIUM 4.3EPSS 1.51%7 August 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.