SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,478 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 281 of 501

CVESummaryPriorityPublished
CVE-2008-3400XRMS CRM 1.99.2 allows remote attackers to obtain configuration information via a direct request to tests/info.php, which calls the phpinfo function.EXPLOIT ✓MEDIUM 4.3EPSS 2.25%31 July 2008
CVE-2008-3399PHP remote file inclusion vulnerability in activities/workflow-activities.php in XRMS CRM 1.99.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the include_directory parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.91%31 July 2008
CVE-2008-3398Multiple cross-site scripting (XSS) vulnerabilities in XRMS CRM 1.99.2 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to unspecified components, possibly including login.php.EXPLOIT ✓LOW 2.6EPSS 1.87%31 July 2008
CVE-2008-3396Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain sequence of malformed packets.EXPLOIT ✓MEDIUM 5.0EPSS 7.71%31 July 2008
CVE-2008-3391Multiple cross-site scripting (XSS) vulnerabilities in Web Wiz Forum 9.5 allow remote attackers to inject arbitrary web script or HTML via the mode parameter to (1) admin_group_details.asp and (2) admin_category_details.asp.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.52%31 July 2008
CVE-2008-3390Directory traversal vulnerability in libraries/general.init.php in Minishowcase Image Gallery 09b136, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.93%31 July 2008
CVE-2008-3388Multiple SQL injection vulnerabilities in Def-Blog 1.0.3 allow remote attackers to execute arbitrary SQL commands via the article parameter to (1) comaddok.php and (2) comlook.php.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.01%30 July 2008
CVE-2008-3387SQL injection vulnerability in show.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the dbtable parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%30 July 2008
CVE-2008-3386SQL injection vulnerability in album.php in AlstraSoft Video Share Enterprise 4.51 allows remote attackers to execute arbitrary SQL commands via the UID parameter, a different vector than CVE-2007-4086.EXPLOIT ✓HIGH 7.5EPSS 1.00%30 July 2008
CVE-2008-3385Directory traversal vulnerability in include/head_chat.inc.php in php Help Agent 1.0 and 1.1 Full allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 2.03%30 July 2008
CVE-2008-3384Multiple directory traversal vulnerabilities in help/help.php in Interact Learning Community Environment Interact 2.4.1 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 3.16%30 July 2008
CVE-2008-3383SQL injection vulnerability in mojoAuto.cgi in MojoAuto allows remote attackers to execute arbitrary SQL commands via the cat_a parameter in a browse action.EXPLOIT ✓HIGH 7.5EPSS 1.01%30 July 2008
CVE-2008-3382SQL injection vulnerability in mojoClassified.cgi in MojoClassifieds 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_a parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%30 July 2008
CVE-2008-3380Cross-site scripting (XSS) vulnerability in ajaxp_backend.php in MyioSoft EasyBookMarker 4.0 trial edition (tr) allows remote attackers to inject arbitrary web script or HTML via the rs parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.74%30 July 2008
CVE-2008-3378SQL injection vulnerability in comment.php in Fizzmedia 1.51.2 allows remote attackers to execute arbitrary SQL commands via the mid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%30 July 2008
CVE-2008-3377SQL injection vulnerability in picture.php in phpTest 0.6.3 allows remote attackers to execute arbitrary SQL commands via the image_id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%30 July 2008
CVE-2008-3375The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrative access via a boolean value within serialized data in a JMU_Cookie cookie.EXPLOIT ✓HIGH 7.5EPSS 3.56%30 July 2008
CVE-2008-3374SQL injection vulnerability in ajax.php in Gregarius 0.5.4 and earlier allows remote attackers to execute arbitrary SQL commands via the rsargs array parameter in an __exp__getFeedContent action.EXPLOIT ✓HIGH 7.5EPSS 2.34%30 July 2008
CVE-2008-3372SQL injection vulnerability in search_form.php in Getacoder Clone allows remote attackers to execute arbitrary SQL commands via the sb_protype parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%30 July 2008
CVE-2008-3371Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.EXPLOIT ✓HIGH 7.5EPSS 3.54%30 July 2008
CVE-2008-3370SQL injection vulnerability in the CUA Login Module in EMC Centera Universal Access (CUA) 4.0_4735.p4 allows remote attackers to execute arbitrary SQL commands via the user (user name) field.EXPLOIT ✓HIGH 7.5EPSS 1.18%30 July 2008
CVE-2008-3369SQL injection vulnerability in products_rss.php in ViArt Shop 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the category_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.77%30 July 2008
CVE-2008-3368PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via a URL in the type parameter.EXPLOIT ✓MEDIUM 6.5EPSS 2.65%30 July 2008
CVE-2008-3366SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%30 July 2008
CVE-2008-3365Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 3.80%30 July 2008
CVE-2008-3364Buffer overflow in the ObjRemoveCtrl Class ActiveX control in OfficeScanRemoveCtrl.dll 7.3.0.1020 in Trend Micro OfficeScan Corp Edition (OSCE) Web-Deployment 7.0, 7.3 build 1343 Patch 4 and other builds, and 8.0; Client Server Messaging Security (CSM)…EXPLOIT ✓HIGH 9.3EPSS 32.8%30 July 2008
CVE-2008-3363Directory traversal vulnerability in user_portal.php in the Dokeos E-Learning System 1.8.5 on Windows allows remote attackers to include and execute arbitrary local files via a ..\ (dot dot backslash) in the include parameter.EXPLOIT ✓HIGH 7.5EPSS 3.33%30 July 2008
CVE-2008-3362Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the upfile parameter, then…EXPLOIT ✓HIGH 10.0EPSS 16.8%30 July 2008
CVE-2008-3361Stack-based buffer overflow in IntelliTamper 2.07 allows remote web sites to execute arbitrary code via a long HTTP Server header.EXPLOIT ×2 ✓HIGH 7.5EPSS 4.30%29 July 2008
CVE-2008-3360Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code via a long URL in the HREF attribute of an A element, a different vulnerability than CVE-2006-2494.EXPLOIT ×4 ✓HIGH 9.3EPSS 7.81%29 July 2008
CVE-2008-3100Cross-site scripting (XSS) vulnerability in lib/owl.lib.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgebase 0.95 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter in a getpasswd action…EXPLOIT ✓MEDIUM 4.3EPSS 2.28%29 July 2008
CVE-2008-3355SQL injection vulnerability in sitemap.xml.php in Camera Life 2.6.2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action.EXPLOIT ✓HIGH 7.5EPSS 1.04%28 July 2008
CVE-2008-3354Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bbPath[path] parameter to votepolls.php and the (2)…EXPLOIT ×2 ✓HIGH 7.5EPSS 2.54%28 July 2008
CVE-2008-3352SQL injection vulnerability in index.php in Live Music Plus 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a Singer action.EXPLOIT ✓HIGH 7.5EPSS 1.01%28 July 2008
CVE-2008-3351SQL injection vulnerability in atomPhotoBlog.php in Atom PhotoBlog 1.0.9.1 and 1.1.5b1 allows remote attackers to execute arbitrary SQL commands via the photoId parameter in a show action.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.02%28 July 2008
CVE-2008-3347SQL injection vulnerability in staticpages/easycalendar/index.php in MyioSoft EasyDynamicPages 3.0 trial edition (tr) allows remote attackers to execute arbitrary SQL commands via the read parameter.EXPLOIT ✓HIGH 7.5EPSS 1.15%28 July 2008
CVE-2008-3346SQL injection vulnerability in product_detail.php in ShopCart DX allows remote attackers to execute arbitrary SQL commands via the pid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.20%28 July 2008
CVE-2008-3345SQL injection vulnerability in staticpages/easyecards/index.php in MyioSoft EasyE-Cards 3.5 trial edition (tr) and 3.10a, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the sid parameter in a pickup…EXPLOIT ✓MEDIUM 6.8EPSS 0.94%28 July 2008
CVE-2008-3343SQL injection vulnerability in staticpages/easypublish/index.php in MyioSoft EasyPublish 3.0tr (trial edition) allows remote attackers to execute arbitrary SQL commands via the read parameter in a search action.EXPLOIT ✓HIGH 7.5EPSS 1.14%28 July 2008
CVE-2008-3332Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via the value parameter.EXPLOIT ✓MEDIUM 6.5EPSS 9.45%27 July 2008
CVE-2008-3331Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php in Mantis before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the filter_target parameter.EXPLOIT ✓LOW 3.5EPSS 3.80%27 July 2008
CVE-2008-3322admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary recipe_cookie cookie.EXPLOIT ✓HIGH 7.5EPSS 6.60%25 July 2008
CVE-2008-3321admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary uploader_cookie cookie.EXPLOIT ✓HIGH 7.5EPSS 7.77%25 July 2008
CVE-2008-3320admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary gbook_cookie cookie.EXPLOIT ✓HIGH 7.5EPSS 6.51%25 July 2008
CVE-2008-3319admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary links_cookie cookie.EXPLOIT ✓HIGH 7.5EPSS 7.77%25 July 2008
CVE-2008-3318admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary weblog_cookie cookie.EXPLOIT ✓HIGH 7.5EPSS 8.10%25 July 2008
CVE-2008-3317admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary search_cookie cookie.EXPLOIT ✓HIGH 7.5EPSS 8.02%25 July 2008
CVE-2008-3315Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the (1) query string to (a) announcements/messages.php; (b) lostPassword.php and (c) profile.php in auth/; (d)…EXPLOIT ×4 ✓MEDIUM 4.3EPSS 2.03%25 July 2008
CVE-2008-3314ZDaemon 1.08.07 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted type 6 command, which triggers a NULL pointer dereference.EXPLOIT ✓MEDIUM 5.0EPSS 7.58%25 July 2008
CVE-2008-3313Multiple PHP remote file inclusion vulnerabilities in CreaCMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) cfg[document_uri] parameter to _administration/edition_article/edition_article.php and the (2)…EXPLOIT ×2 ✓HIGH 7.5EPSS 2.25%25 July 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.