Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,483 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 283 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-3205 | Directory traversal vulnerability in index.php in Easy-Script Wysi Wiki Wyg 1.0 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.77% | 17 July 2008 |
| CVE-2008-3204 | SQL injection vulnerability in tops_top.php in E-topbiz Million Pixels 3 allows remote attackers to execute arbitrary SQL commands via the id_cat parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 17 July 2008 |
| CVE-2008-3203 | js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.58% | 17 July 2008 |
| CVE-2008-3202 | Cross-site scripting (XSS) vulnerability in index.php in Xomol CMS 1.2 allows remote attackers to inject arbitrary web script or HTML via the current_url parameter in a tellafriend action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 17 July 2008 |
| CVE-2008-3201 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Pagefusion 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) acct_fname and (2) acct_lname parameters in an edit action, and the (3) PID, (4) PGID, and (5)… | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 17 July 2008 |
| CVE-2008-3200 | SQL injection vulnerability in vlc_forum.php in Avlc Forum as of 20080715 allows remote attackers to execute arbitrary SQL commands via the id parameter in an affich_message action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 17 July 2008 |
| CVE-2008-3194 | Multiple directory traversal vulnerabilities in data/inc/themes/predefined_variables.php in pluck 4.5.1 allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 2.55% | 16 July 2008 |
| CVE-2008-3193 | SQL injection vulnerability in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the page parameter to the default URI. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 16 July 2008 |
| CVE-2008-3192 | Directory traversal vulnerability in index.php in jSite 1.0 OE allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.92% | 16 July 2008 |
| CVE-2008-3191 | Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) City, (2) Interest, (3) Email, (4) Icq, (5) msn, or (6) Yahoo Messenger field in… | EXPLOIT ✓MEDIUM 6.8EPSS 1.09% | 16 July 2008 |
| CVE-2008-3190 | Directory traversal vulnerability in list.php in 1Scripts CodeDB 1.1.1 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 2.30% | 16 July 2008 |
| CVE-2008-3189 | SQL injection vulnerability in dreamnews-rss.php in DreamNews Manager allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 16 July 2008 |
| CVE-2008-2595 | Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.4.2 has unknown impact and remote attack vectors. | EXPLOIT ✓MEDIUM 5.0EPSS 11.3% | 15 July 2008 |
| CVE-2008-3186 | Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blog (Blogger) allow remote attackers to inject arbitrary web script or HTML via the membername parameter to (1) members.php, (2) comments.php, (3) photos.php, (4) archive.php, or (5)… | EXPLOIT ×5 ✓MEDIUM 4.3EPSS 1.22% | 15 July 2008 |
| CVE-2008-3185 | SQL injection vulnerability in index.php in Relative Real Estate Systems 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action. | EXPLOIT ✓MEDIUM 6.8EPSS 1.11% | 15 July 2008 |
| CVE-2008-3184 | Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.10 PL2 and earlier, and 3.7.2 and earlier 3.7.x versions, allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO (PHP_SELF) or (2) the do parameter, as… | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 15 July 2008 |
| CVE-2008-3183 | PHP remote file inclusion vulnerability in ktmlpro/includes/ktedit/toolbar.php in gapicms 9.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the dirDepth parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.12% | 15 July 2008 |
| CVE-2008-3182 | Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allows user-assisted remote attackers to execute arbitrary code via an M3U (.m3u) file containing a long MP3 URL. | EXPLOIT ×2 ✓HIGH 9.3EPSS 7.39% | 15 July 2008 |
| CVE-2008-3181 | Unrestricted file upload vulnerability in upload.php in ContentNow CMS 1.4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/. | EXPLOIT ✓MEDIUM 6.5EPSS 3.07% | 15 July 2008 |
| CVE-2008-3180 | Multiple cross-site scripting (XSS) vulnerabilities in upload/file/language_menu.php in ContentNow CMS 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) pageid parameter or (2) PATH_INFO. | EXPLOIT ✓MEDIUM 4.3EPSS 1.57% | 15 July 2008 |
| CVE-2008-3179 | Directory traversal vulnerability in website.php in Web 2 Business (W2B) phpDatingClub (aka Dating Club) 3.7 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.84% | 15 July 2008 |
| CVE-2008-3178 | Unrestricted file upload vulnerability in upload_pictures.php in WebXell Editor 0.1.3 allows remote attackers to execute arbitrary code by uploading a .php file with a jpeg content type, then accessing it via a direct request to the file in upload/. | EXPLOIT ✓HIGH 7.5EPSS 5.11% | 15 July 2008 |
| CVE-2008-3167 | Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) dir[plugins] parameter to (a) HTMLSax3.php and (b) safehtml.php in… | EXPLOIT ✓HIGH 9.3EPSS 6.46% | 14 July 2008 |
| CVE-2008-3166 | PHP remote file inclusion vulnerability in modules/global/inc/content.inc.php in BoonEx Ray 3.5, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the sIncPath parameter. | EXPLOIT ×2 ✓HIGH 9.3EPSS 6.24% | 14 July 2008 |
| CVE-2008-3165 | Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 2.30% | 14 July 2008 |
| CVE-2008-3164 | Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.6EPSS 3.75% | 14 July 2008 |
| CVE-2008-3163 | Directory traversal vulnerability in dodosmail.php in DodosMail 2.5 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.93% | 14 July 2008 |
| CVE-2008-3162 | Stack-based buffer overflow in the str_read_packet function in libavformat/psxstr.c in FFmpeg before r13993 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted STR file that interleaves audio… | EXPLOIT ✓HIGH 9.3EPSS 9.25% | 14 July 2008 |
| CVE-2008-3161 | Multiple cross-site scripting (XSS) vulnerabilities in jsp/common/system/debug.jsp in IBM Maximo 4.1 and 5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Accept, (2) Accept-Language, (3) UA-CPU, (4) Accept-Encoding, (5)… | EXPLOIT ✓MEDIUM 4.3EPSS 1.19% | 14 July 2008 |
| CVE-2008-2304 | Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a .funhouse file with a string… | EXPLOIT ✓MEDIUM 6.8EPSS 5.68% | 14 July 2008 |
| CVE-2008-2303 | Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript array indices that trigger an… | EXPLOIT ✓HIGH 10.0EPSS 13.0% | 14 July 2008 |
| CVE-2008-3158 | Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possibly related to IOCTL requests that overwrite arbitrary memory. | EXPLOITMEDIUM 6.9EPSS 5.48% | 11 July 2008 |
| CVE-2008-3156 | The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CAB) files via unspecified URLs passed to the Update method. | EXPLOIT ✓HIGH 9.3EPSS 4.07% | 11 July 2008 |
| CVE-2008-3155 | Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the Update method. | EXPLOIT ✓HIGH 9.3EPSS 7.71% | 11 July 2008 |
| CVE-2008-3154 | SQL injection vulnerability in index.php in WebBlizzard CMS allows remote attackers to execute arbitrary SQL commands via the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 11 July 2008 |
| CVE-2008-3153 | SQL injection vulnerability in Triton CMS Pro allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 11 July 2008 |
| CVE-2008-3152 | SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary SQL commands via the idDirectory parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.05% | 11 July 2008 |
| CVE-2008-3151 | SQL injection vulnerability in the 4ndvddb 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a show_dvd action. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 11 July 2008 |
| CVE-2008-3150 | Directory traversal vulnerability in index.php in Neutrino Atomic Edition 0.8.4 allows remote attackers to read and modify files, as demonstrated by manipulating data/sess.php in (1) usb and (2) del_pag actions. | EXPLOIT ✓HIGH 10.0EPSS 6.27% | 11 July 2008 |
| CVE-2008-3148 | Stack-based buffer overflow in (1) OllyDBG 1.10 and (2) ImpREC 1.7f allows user-assisted attackers to execute arbitrary code via a crafted DLL file that contains a long string. | EXPLOIT ✓MEDIUM 6.8EPSS 3.39% | 11 July 2008 |
| CVE-2008-3140 | The syslog dissector in Wireshark (formerly Ethereal) 1.0.0 allows remote attackers to cause a denial of service (application crash) via unknown vectors, possibly related to an "incomplete SS7 MSU syslog encapsulated packet." | EXPLOIT ✓MEDIUM 5.0EPSS 4.95% | 10 July 2008 |
| CVE-2008-3136 | SQL injection vulnerability in catalogue.php in AShop Deluxe 4.x allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 10 July 2008 |
| CVE-2008-3133 | SQL injection vulnerability in admin/index.php in BareNuked CMS 1.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the password parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.95% | 10 July 2008 |
| CVE-2008-3132 | SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pet parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 10 July 2008 |
| CVE-2008-3131 | SQL injection vulnerability in chatbox.php in pSys 0.7.0 Alpha, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the showid parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 10 July 2008 |
| CVE-2008-3129 | Multiple SQL injection vulnerabilities in index.php in Catviz 0.4 beta 1 allow remote attackers to execute arbitrary SQL commands via the (1) foreign_key_value parameter in the news page and (2) webpage parameter in the webpage_multi_edit form. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 10 July 2008 |
| CVE-2008-3128 | Directory traversal vulnerability in search.php in Pivot 1.40.5 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.62% | 10 July 2008 |
| CVE-2008-3127 | PHP remote file inclusion vulnerability in hioxBannerRotate.php in HIOX Banner Rotator (HBR) 1.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the hm parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.36% | 10 July 2008 |
| CVE-2008-3125 | SQL injection vulnerability in index.php in Mole Group Lastminute Script 4.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 10 July 2008 |
| CVE-2008-3124 | SQL injection vulnerability in index.php in Mole Group Hotel Script 1.0 allows remote attackers to execute arbitrary SQL commands via the file parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 10 July 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.