SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,478 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 280 of 501

CVESummaryPriorityPublished
CVE-2008-3510Cross-site scripting (XSS) vulnerability in livehelp_js.php in Crafty Syntax Live Help (CSLH) 2.14.6 allows remote attackers to inject arbitrary web script or HTML via the department parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.47%7 August 2008
CVE-2008-3509LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or execute arbitrary PHP code via addition of blocks, and…EXPLOIT ×2 ✓HIGH 7.5EPSS 3.43%7 August 2008
CVE-2008-3508LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie.EXPLOIT ✓MEDIUM 5.0EPSS 2.98%7 August 2008
CVE-2008-3507SQL injection vulnerability in index.php in LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.EXPLOIT ✓HIGH 7.5EPSS 1.00%7 August 2008
CVE-2008-3506SQL injection vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to execute arbitrary SQL commands via the nr parameter to the default URI.EXPLOIT ✓HIGH 7.5EPSS 1.01%6 August 2008
CVE-2008-3505Cross-site scripting (XSS) vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via the nr parameter to the default URI.EXPLOIT ✓MEDIUM 4.3EPSS 1.52%6 August 2008
CVE-2008-3498SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in an orders action to index.php.EXPLOIT ✓HIGH 7.5EPSS 2.43%6 August 2008
CVE-2008-3497SQL injection vulnerability in pages.php in MyPHP CMS 0.3.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.96%6 August 2008
CVE-2008-3495SQL injection vulnerability in kategori.asp in Pcshey Portal allows remote attackers to execute arbitrary SQL commands via the kid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.96%6 August 2008
CVE-2008-34948e6 R3000 Internet Filter 2.0.12.10 allows remote attackers to bypass intended restrictions via an extra HTTP Host header with additional leading text placed before the real Host header.EXPLOIT ✓HIGH 7.8EPSS 2.77%6 August 2008
CVE-2008-3493vncviewer.exe in RealVNC Windows Client 4.1.2.0 allows remote VNC servers to cause a denial of service (application crash) via a crafted frame buffer update packet.EXPLOIT ✓MEDIUM 5.0EPSS 5.63%6 August 2008
CVE-2008-3491SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter in a report action.EXPLOIT ×2 ✓HIGH 7.5EPSS 2.02%6 August 2008
CVE-2008-3490SQL injection vulnerability in members/mail.php in E-topbiz Online Dating 3 1.0 allows remote authenticated users to execute arbitrary SQL commands via the mail_id parameter in a veiw action.EXPLOIT ✓MEDIUM 6.5EPSS 0.88%6 August 2008
CVE-2008-3489SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers to execute arbitrary SQL commands via a PXL cookie.EXPLOIT ✓HIGH 7.5EPSS 1.01%6 August 2008
CVE-2008-3487SQL injection vulnerability in profile.php in PHPAuction GPL Enhanced 2.51 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%6 August 2008
CVE-2008-3486Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 6.30%6 August 2008
CVE-2008-3484SQL injection vulnerability in eStoreAff 0.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a showcat action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%5 August 2008
CVE-2008-3483Cross-site scripting (XSS) vulnerability in ScrewTurn Wiki 2.0.29 and 2.0.30 allows remote attackers to inject arbitrary web script or HTML via error messages in the "/admin.aspx - System Log" page.EXPLOIT ✓MEDIUM 4.3EPSS 1.51%5 August 2008
CVE-2008-3481themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.EXPLOIT ✓HIGH 7.5EPSS 2.11%5 August 2008
CVE-2008-3431Oracle VirtualBox Insufficient Input Validation VulnerabilityKEVEXPLOIT ✓HIGH 8.8EPSS 6.88%5 August 2008
CVE-2008-3455PHP remote file inclusion vulnerability in include/admin.php in JnSHosts PHP Hosting Directory 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the rd parameter.EXPLOIT ✓HIGH 10.0EPSS 3.55%4 August 2008
CVE-2008-3454JnSHosts PHP Hosting Directory 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the "adm" cookie value to 1.EXPLOIT ✓HIGH 7.5EPSS 2.53%4 August 2008
CVE-2008-3452SQL injection vulnerability in the Calendar module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL commands via the loc_id parameter in a list_events action to mod.php.EXPLOIT ✓MEDIUM 6.8EPSS 0.91%4 August 2008
CVE-2008-3448Cross-site scripting (XSS) vulnerability in index.php in common solutions csphonebook 1.02 allows remote attackers to inject arbitrary web script or HTML via the letter parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.73%4 August 2008
CVE-2008-3447The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop) via a malformed ZIP archive, probably related to invalid offsets.EXPLOIT ✓MEDIUM 5.0EPSS 7.87%4 August 2008
CVE-2008-3446Directory traversal vulnerability in inc/wysiwyg.php in LetterIt 2 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.99%4 August 2008
CVE-2008-3445SQL injection vulnerability in index.php in phpMyRealty (PMR) 2.0.0 allows remote attackers to execute arbitrary SQL commands via the location parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%4 August 2008
CVE-2008-2370Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal…EXPLOIT ✓MEDIUM 5.0EPSS 52.7%4 August 2008
CVE-2008-2321Unspecified vulnerability in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unknown vectors involving "processing of…EXPLOIT ✓HIGH 9.3EPSS 12.5%4 August 2008
CVE-2008-1232Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to…EXPLOIT ✓MEDIUM 4.3EPSS 75.9%4 August 2008
CVE-2008-2935Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers…EXPLOIT ✓HIGH 7.5EPSS 12.8%1 August 2008
CVE-2008-3430Buffer overflow in the CoVideoWindow.ocx ActiveX control 5.0.907.1 in Eyeball MessengerSDK, as used in products such as SiOL Komunikator 1.3, allows remote attackers to execute arbitrary code via a large argument supplied to the BGColor method.EXPLOIT ✓HIGH 9.3EPSS 5.55%31 July 2008
CVE-2008-3420Multiple SQL injection vulnerabilities in Mobius for Mimsy XG 1 1.4.4.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to browse.php or (2) the s parameter in an exhibitions action to detail.php.EXPLOIT ✓HIGH 7.5EPSS 1.00%31 July 2008
CVE-2008-3419SQL injection vulnerability in ugroups.php in Youtuber Clone allows remote attackers to execute arbitrary SQL commands via the UID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%31 July 2008
CVE-2008-3418SQL injection vulnerability in browse.php in TriO 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%31 July 2008
CVE-2008-3417SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the r parameter, a different vector than CVE-2006-6115 and CVE-2007-2561.EXPLOIT ✓HIGH 7.5EPSS 1.04%31 July 2008
CVE-2008-3416SQL injection vulnerability in modules/members.php in IceBB before 1.0-rc9.3 allows remote attackers to execute arbitrary SQL commands via the username parameter in a members action to index.php, related to an incorrect protection mechanism in the…EXPLOIT ✓HIGH 7.5EPSS 2.35%31 July 2008
CVE-2008-3415Directory traversal vulnerability in common.php in CMScout 2.05, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the bit parameter, as demonstrated by an upload…EXPLOIT ✓HIGH 7.5EPSS 2.94%31 July 2008
CVE-2008-3414SQL injection vulnerability in line2.php in SiteAdmin allows remote attackers to execute arbitrary SQL commands via the art parameter.EXPLOIT ✓HIGH 7.5EPSS 1.20%31 July 2008
CVE-2008-3413SQL injection vulnerability in category.php in Greatclone GC Auction Platinum allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.20%31 July 2008
CVE-2008-3412SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a (1) pro_show or (2) disppro action to the default URI.EXPLOIT ✓HIGH 7.5EPSS 0.97%31 July 2008
CVE-2008-3409Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a UDP packet containing a large value in a certain size field,…EXPLOIT ✓HIGH 7.5EPSS 11.0%31 July 2008
CVE-2008-3408Stack-based buffer overflow in CoolPlayer 2.18, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a crafted m3u file.EXPLOIT ×3 ✓MEDIUM 6.8EPSS 9.66%31 July 2008
CVE-2008-3407phpLinkat 0.1 allows remote attackers to bypass authentication and access unspecified pages under admin/ by sending a login=right cookie.EXPLOIT ✓MEDIUM 5.0EPSS 3.05%31 July 2008
CVE-2008-3406SQL injection vulnerability in showcat.php in phpLinkat 0.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%31 July 2008
CVE-2008-3405Directory traversal vulnerability in index.php in Ricardo Amaral nzFotolog 0.4.1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action_file parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.99%31 July 2008
CVE-2008-3404Cross-site scripting (XSS) vulnerability in guestbook.js.php in MJGuest 6.8 GT allows remote attackers to inject arbitrary web script or HTML via the link parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.73%31 July 2008
CVE-2008-3403SQL injection vulnerability in mojoClassified.cgi in MojoPersonals allows remote attackers to execute arbitrary SQL commands via the cat parameter.EXPLOIT ✓HIGH 7.5EPSS 1.15%31 July 2008
CVE-2008-3402Multiple PHP remote file inclusion vulnerabilities in HIOX Browser Statistics (HBS) 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the hm parameter to (1) hioxupdate.php and (2) hioxstats.php.EXPLOIT ✓HIGH 7.5EPSS 3.12%31 July 2008
CVE-2008-3401PHP remote file inclusion vulnerability in hioxRandomAd.php in HIOX Random Ad (HRA) 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the hm parameter.EXPLOIT ✓HIGH 7.5EPSS 3.12%31 July 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.