SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,478 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 282 of 501

CVESummaryPriorityPublished
CVE-2008-3312Directory traversal vulnerability in lemon_includes/FCKeditor/editor/filemanager/browser/browser.php in Lemon CMS 1.10 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.90%25 July 2008
CVE-2008-3311PHP remote file inclusion vulnerability in config.php in Adam Scheinberg Flip 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the incpath parameter.EXPLOIT ✓HIGH 7.5EPSS 2.35%25 July 2008
CVE-2008-3310SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands via the catid parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.02%25 July 2008
CVE-2008-3309SQL injection vulnerability in info_book.asp in DigiLeave 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%25 July 2008
CVE-2008-3308PHP remote file inclusion vulnerability in cuenta/cuerpo.php in C.EXPLOIT ✓MEDIUM 6.8EPSS 1.97%25 July 2008
CVE-2008-3307SQL injection vulnerability in todos.php in C.EXPLOIT ✓HIGH 7.5EPSS 1.04%25 July 2008
CVE-2008-3306SQL injection vulnerability in info.php in C.EXPLOIT ✓HIGH 7.5EPSS 0.91%25 July 2008
CVE-2008-3305Cross-site scripting (XSS) vulnerability in mensaje.php in C.EXPLOIT ✓MEDIUM 4.3EPSS 3.59%25 July 2008
CVE-2008-3304BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct request to pagination.php, which reveals the installation path in an error message.EXPLOIT ✓MEDIUM 5.0EPSS 6.09%25 July 2008
CVE-2008-3303admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication and obtain administrative access via a direct request that sets the login, admin_login, password, and admin_passwd parameters.EXPLOIT ✓MEDIUM 6.8EPSS 5.40%25 July 2008
CVE-2008-3302SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote authenticated administrators to execute arbitrary SQL commands via the num parameter.EXPLOIT ✓MEDIUM 6.0EPSS 2.18%25 July 2008
CVE-2008-3301Multiple cross-site scripting (XSS) vulnerabilities in BilboBlog 0.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) content parameter to admin/update.php, related to conflicting code in widget.php; and…EXPLOIT ✓LOW 3.5EPSS 2.43%25 July 2008
CVE-2008-3300AlphAdmin CMS 1.0.5/03 allows remote attackers to bypass authentication and gain administrative access by setting the aa_login cookie value to 1.EXPLOIT ✓HIGH 7.5EPSS 5.57%25 July 2008
CVE-2008-3299eSyndiCat 1.6 allows remote attackers to bypass authentication and gain administrative access by setting the admin_lng cookie value to 1.EXPLOIT ✓HIGH 7.5EPSS 6.25%25 July 2008
CVE-2008-3296Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 5.71%25 July 2008
CVE-2008-3295Cross-site scripting (XSS) vulnerability in modules/system/admin.php in XOOPS 2.0.18.1 allows remote attackers to inject arbitrary web script or HTML via the fct parameter.EXPLOIT ✓MEDIUM 4.3EPSS 2.74%25 July 2008
CVE-2008-3293Directory traversal vulnerability in download.php in EZWebAlbum allows remote attackers to read arbitrary files via the dlfilename parameter.EXPLOIT ✓MEDIUM 5.0EPSS 8.88%24 July 2008
CVE-2008-3292constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the photoalbumadmin cookie, as demonstrated via addpage.php.EXPLOIT ✓MEDIUM 6.4EPSS 7.32%24 July 2008
CVE-2008-3291SQL injection vulnerability in index.php in AproxEngine (aka Aprox CMS Engine) 5.1.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.99%24 July 2008
CVE-2008-3286SWAT 4 1.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via a (1) VERIFYCONTENT or (2) GAMECONFIG command sent to the server before user session initialization, which triggers a NULL pointer dereference; or (3) a…EXPLOIT ✓MEDIUM 5.0EPSS 8.95%24 July 2008
CVE-2008-3285The Filesys::SmbClientParser module 2.7 and earlier for Perl allows remote SMB servers to execute arbitrary code via a folder name containing shell metacharacters.EXPLOIT ✓HIGH 9.3EPSS 6.91%24 July 2008
CVE-2008-3269WRPCServer.exe in WinSoftMagic WinRemotePC (WRPC) Lite 2008 and Full 2008 allows remote attackers to cause a denial of service (CPU consumption) via a crafted packet to TCP port 4321.EXPLOIT ✓MEDIUM 5.0EPSS 10.8%24 July 2008
CVE-2008-3267SQL injection vulnerability in mojoJobs.cgi in MojoJobs allows remote attackers to execute arbitrary SQL commands via the cat_a parameter.EXPLOIT ✓HIGH 7.5EPSS 2.08%24 July 2008
CVE-2008-3266SQL injection vulnerability in picture_pic_bv.asp in SoftAcid Hotel Reservation System (HRS) Multi allows remote attackers to execute arbitrary SQL commands via the key parameter.EXPLOIT ✓HIGH 7.5EPSS 2.35%24 July 2008
CVE-2008-3265SQL injection vulnerability in the DT Register (com_dtregister) 2.2.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the eventId parameter in a pay_options action to index.php.EXPLOIT ✓MEDIUM 6.8EPSS 3.04%24 July 2008
CVE-2008-3263The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before B.2.5.4, and C.x.x before C.1.10.3; AsteriskNOW; Appliance Developer Kit 0.x.x; and s800i 1.0.x before…EXPLOIT ✓HIGH 7.8EPSS 28.0%22 July 2008
CVE-2008-3261Open redirect vulnerability in claroline/redirector.php in Claroline before 1.8.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.EXPLOIT ✓MEDIUM 4.3EPSS 4.85%22 July 2008
CVE-2008-3260Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via (1) the cwd parameter in a rqMkHtml action to document/rqmkhtml.php, or the query string to (2)…EXPLOIT ×12 ✓MEDIUM 4.3EPSS 4.63%22 July 2008
CVE-2008-3257Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after…EXPLOIT ×2 ✓HIGH 10.0EPSS 83.6%22 July 2008
CVE-2008-3256SQL injection vulnerability in folder.php in Siteframe CMS 3.2.3 and earlier, and Siteframe Beaumont 5.0.5 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.99%22 July 2008
CVE-2008-3254SQL injection vulnerability in index.php in preCMS 1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a UserProfil action.EXPLOIT ✓MEDIUM 6.8EPSS 2.60%22 July 2008
CVE-2008-3251Multiple SQL injection vulnerabilities in tplSoccerSite 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the opp parameter to tampereunited/opponent.php; or the id parameter to (2) index.php, (3) player.php, (4) matchdetails.php, or…EXPLOIT ✓HIGH 7.5EPSS 2.43%21 July 2008
CVE-2008-3250SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL commands via the filter parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 2.28%21 July 2008
CVE-2008-3245SQL injection vulnerability in phpHoo3.php in phpHoo3 4.3.9, 4.3.10, 4.4.8, and 5.2.6 allows remote attackers to execute arbitrary SQL commands via the viewCat parameter.EXPLOIT ✓HIGH 7.5EPSS 1.99%21 July 2008
CVE-2008-3242Heap-based buffer overflow in the PPMedia Class ActiveX control in PPMPlayer.dll in PPMate 2.3.1.93 allows remote attackers to execute arbitrary code via a long argument to the StartUrl method.EXPLOIT ✓HIGH 10.0EPSS 15.7%21 July 2008
CVE-2008-3241SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 2.08%21 July 2008
CVE-2008-3240SQL injection vulnerability in index.php in AlstraSoft Affiliate Network Pro allows remote attackers to execute arbitrary SQL commands via the pgm parameter in a directory action.EXPLOIT ✓HIGH 7.5EPSS 2.35%21 July 2008
CVE-2008-3239Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP1, when register_globals is enabled, allows remote attackers to upload and execute arbitrary code via a filename in the…EXPLOIT ✓HIGH 9.3EPSS 5.17%21 July 2008
CVE-2008-3238Multiple SQL injection vulnerabilities in ITechBids 7.0 Gold allow remote attackers to execute arbitrary SQL commands via (1) the seller_id parameter in sellers_othersitem.php, (2) the productid parameter in classifieds.php, and (3) the id parameter in…EXPLOIT ✓HIGH 7.5EPSS 1.20%21 July 2008
CVE-2008-3237Cross-site scripting (XSS) vulnerability in forward_to_friend.php in ITechBids 7.0 Gold allows remote attackers to inject arbitrary web script or HTML via the productid parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.72%21 July 2008
CVE-2008-3234sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username.EXPLOIT ✓MEDIUM 6.5EPSS 5.77%18 July 2008
CVE-2008-3233Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.EXPLOIT ✓MEDIUM 4.3EPSS 3.95%18 July 2008
CVE-2008-3213SQL injection vulnerability in secciones/tablon/tablon.php in WebCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id parameter to portal/index.php in a tablon action.EXPLOIT ✓HIGH 7.5EPSS 1.00%18 July 2008
CVE-2008-3212Multiple SQL injection vulnerabilities in Scripteen Free Image Hosting Script 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/login.php, or the (3) uname or (4) pass parameter to…EXPLOIT ✓HIGH 7.5EPSS 0.95%18 July 2008
CVE-2008-3211Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrative access by setting the cookid cookie value to 1.EXPLOIT ✓HIGH 7.5EPSS 3.26%18 July 2008
CVE-2008-3210rutil/dns/DnsStub.cxx in ReSIProcate 1.3.2, as used by repro, allows remote attackers to cause a denial of service (daemon crash) via a SIP (1) INVITE or (2) OPTIONS message with a long domain name in a request URI, which triggers an assert error.EXPLOIT ✓MEDIUM 5.0EPSS 3.45%18 July 2008
CVE-2008-3209Heap-based buffer overflow in the OpenGifFile function in BiGif.dll in Black Ice Document Imaging SDK 10.95 allows remote attackers to execute arbitrary code via a long string argument to the GetNumberOfImagesInGifFile method in the BIImgFrm Control…EXPLOIT ✓HIGH 9.3EPSS 6.03%18 July 2008
CVE-2008-3208Simple DNS Plus 4.1, 5.0, and possibly other versions before 5.1.101 allows remote attackers to cause a denial of service via multiple DNS reply packets.EXPLOIT ✓MEDIUM 5.0EPSS 3.33%18 July 2008
CVE-2008-3207PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the (1) sourceFolder or (2) moduleFolder parameter.EXPLOIT ✓HIGH 9.3EPSS 5.58%18 July 2008
CVE-2008-3206SQL injection vulnerability in browse.groups.php in Yuhhu Pubs Black Cat allows remote attackers to execute arbitrary SQL commands via the category parameter.EXPLOIT ✓HIGH 7.5EPSS 2.06%18 July 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.