Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,483 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 284 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-3123 | SQL injection vulnerability in index.php in Mole Group Real Estate Script 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 10 July 2008 |
| CVE-2008-3119 | SQL injection vulnerability in index.php in DreamPics Builder allows remote attackers to execute arbitrary SQL commands via the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 10 July 2008 |
| CVE-2008-3118 | SQL injection vulnerability in play.php in PHPmotion 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the vid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 10 July 2008 |
| CVE-2008-3117 | Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a .php file with a content type of (1) image/gif, (2) image/jpeg, or (3) image/pjpeg, then… | EXPLOIT ✓MEDIUM 6.5EPSS 3.25% | 10 July 2008 |
| CVE-2008-3116 | Format string vulnerability in dx8render.dll in Snail Game (aka Suzhou Snail Electronic Company) 5th street (aka Hot Step or High Street 5) allows remote attackers to execute arbitrary code via format string specifiers in a chat message. | EXPLOIT ✓HIGH 10.0EPSS 5.55% | 10 July 2008 |
| CVE-2008-3093 | Unrestricted file upload vulnerability in ImperialBB 2.3.5 and earlier allows remote authenticated users to upload and execute arbitrary PHP code by placing a .php filename in the Upload_Avatar parameter and sending the image/gif content type. | EXPLOIT ✓MEDIUM 6.5EPSS 2.17% | 9 July 2008 |
| CVE-2008-3089 | SQL injection vulnerability in user.html in Xpoze Pro 3.06 (aka Xpoze Pro CMS 2008) allows remote attackers to execute arbitrary SQL commands via the uid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 9 July 2008 |
| CVE-2008-3088 | Cross-site scripting (XSS) vulnerability in the Files module in Kasseler CMS 1.3.0 and 1.3.1 Lite allows remote attackers to inject arbitrary web script or HTML via the cid parameter in a Category action to index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.52% | 9 July 2008 |
| CVE-2008-3087 | Directory traversal vulnerability in Kasseler CMS 1.3.0 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.91% | 9 July 2008 |
| CVE-2008-3083 | SQL injection vulnerability in Brightcode Weblinks (com_brightweblinks) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 9 July 2008 |
| CVE-2008-3080 | Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to perform edit actions as administrators. | EXPLOIT ✓MEDIUM 5.1EPSS 0.41% | 9 July 2008 |
| CVE-2007-3653 | Multiple cross-site scripting (XSS) vulnerabilities in Farsi Script (aka FaScript) FaName 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) key or (2) desc parameter to index.php, or (3) the name parameter to page.php. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.47% | 9 July 2008 |
| CVE-2007-1899 | Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a viewuser action to index.php, and allow remote authenticated administrators to execute… | EXPLOIT ✓MEDIUM 5.1EPSS 0.92% | 9 July 2008 |
| CVE-2008-1447 | The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a… | EXPLOIT ×3 ✓MEDIUM 6.8EPSS 95.2% | 8 July 2008 |
| CVE-2008-2950 | The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document. | EXPLOIT ✓HIGH 7.5EPSS 15.0% | 7 July 2008 |
| CVE-2008-2463 | The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 59.1% | 7 July 2008 |
| CVE-2008-3036 | Directory traversal vulnerability in index.php in CMS little 0.0.1 allows remote attackers to include and execute arbitrary local files, and probably remote files, via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.49% | 7 July 2008 |
| CVE-2008-3035 | SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to execute arbitrary SQL commands via the boardID parameter. | EXPLOIT ✓MEDIUM 6.5EPSS 0.90% | 7 July 2008 |
| CVE-2008-3034 | Multiple SQL injection vulnerabilities in RSS-aggregator 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) IdFlux parameter to admin/fonctions/supprimer_flux.php and the (2) IdTag parameter to admin/fonctions/supprimer_tag.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97% | 7 July 2008 |
| CVE-2008-3033 | RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to… | EXPLOIT ✓HIGH 9.3EPSS 3.01% | 7 July 2008 |
| CVE-2008-3031 | Directory traversal vulnerability in index.php in Simple PHP Agenda 2.2.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.30% | 7 July 2008 |
| CVE-2008-3030 | SQL injection vulnerability in default.asp in EfesTECH Shop 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in an urunler action. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 7 July 2008 |
| CVE-2008-3027 | SQL injection vulnerability in get_article.php in VanGogh Web CMS 0.9 allows remote attackers to execute arbitrary SQL commands via the article_ID parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 7 July 2008 |
| CVE-2008-3026 | SQL injection vulnerability in index.php in OneClick CMS (aka Sisplet CMS) 2008-01-24 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 7 July 2008 |
| CVE-2008-3025 | SQL injection vulnerability in ad.php in plx Ad Trader 3.2 allows remote attackers to execute arbitrary SQL commands via the adid parameter in a redir action. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 7 July 2008 |
| CVE-2008-3024 | Stack-based buffer overflow in phgrafx in QNX Momentics (aka RTOS) 6.3.2 and earlier allows local users to gain privileges via a long .pal filename in palette/. | EXPLOIT ✓HIGH 9.3EPSS 5.93% | 7 July 2008 |
| CVE-2008-3022 | Multiple PHP remote file inclusion vulnerabilities in sablonlar/gunaysoft/gunaysoft.php in PHPortal 1.2 Beta allow remote attackers to execute arbitrary PHP code via a URL in (1) icerikyolu, (2) sayfaid, and (3) uzanti parameters. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 7 July 2008 |
| CVE-2008-2997 | Cross-site scripting (XSS) vulnerability in index.php in Gravity Board X (GBX) 2.0 Beta allows remote attackers to inject arbitrary web script or HTML via the subject parameter in a postnewsubmit (aka create new thread) action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 3 July 2008 |
| CVE-2008-2996 | Multiple SQL injection vulnerabilities in index.php in Gravity Board X (GBX) 2.0 Beta, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchquery parameter in a getsearch action, and the (2)… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 0.92% | 3 July 2008 |
| CVE-2008-2995 | Multiple SQL injection vulnerabilities in PHPEasyData 1.5.4 allow remote attackers to execute arbitrary SQL commands via (1) the annuaire parameter to annuaire.php or (2) the username field in admin/login.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97% | 3 July 2008 |
| CVE-2008-2994 | Multiple cross-site scripting (XSS) vulnerabilities in PHPEasyData 1.5.4 allow remote attackers to inject arbitrary web script or HTML via the (1) annuaire parameter to (a) last_records.php and (b) annuaire.php and the (2) by and (3) cat_id parameters… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.49% | 3 July 2008 |
| CVE-2008-2993 | Multiple directory traversal vulnerabilities in index.php in FOG Forum 0.8.1 allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.37% | 3 July 2008 |
| CVE-2008-2990 | PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the ff_compath parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 2 July 2008 |
| CVE-2008-2989 | SQL injection vulnerability in index.php in HoMaP-CMS 0.1 allows remote attackers to execute arbitrary SQL commands via the go parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 2 July 2008 |
| CVE-2008-2987 | Multiple cross-site scripting (XSS) vulnerabilities in Benja CMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin_edit_submenu.php, (2) admin_new_submenu.php, and (3) admin_edit_topmenu.php in admin/. | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.54% | 2 July 2008 |
| CVE-2008-2986 | Multiple PHP remote file inclusion vulnerabilities in phpDMCA 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the ourlinux_root_path parameter to (1) adodb-errorpear.inc.php and (2) adodb-pear.inc.php in adodb/. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 2 July 2008 |
| CVE-2008-2985 | Directory traversal vulnerability in load_language.php in CMReams CMS 1.3.1.1 Beta 2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page_language parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.85% | 2 July 2008 |
| CVE-2008-2984 | Cross-site scripting (XSS) vulnerability in backend/umleitung.php in CMReams CMS 1.3.1.1 Beta 2 allows remote attackers to inject arbitrary web script or HTML via the lang[be_red_text] parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 2 July 2008 |
| CVE-2008-2983 | SQL injection vulnerability in index.php in Demo4 CMS 01 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 2 July 2008 |
| CVE-2008-2982 | Multiple directory traversal vulnerabilities in HomePH Design 2.10 RC2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) thumb_template parameter to (a)… | EXPLOIT ✓MEDIUM 6.8EPSS 1.98% | 2 July 2008 |
| CVE-2008-2981 | PHP remote file inclusion vulnerability in admin/templates/template_thumbnail.php in HomePH Design 2.10 RC2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the thumb_template parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.69% | 2 July 2008 |
| CVE-2008-2980 | Multiple cross-site scripting (XSS) vulnerabilities in HomePH Design 2.10 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) error_meldung parameter to admin/features/register/register.php, the (2)… | EXPLOIT ✓MEDIUM 4.3EPSS 1.22% | 2 July 2008 |
| CVE-2008-2979 | Multiple cross-site scripting (XSS) vulnerabilities in phpi/login.php in Ourvideo CMS 9.5 allow remote attackers to inject arbitrary web script or HTML via the (1) top_page and (2) end_page parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.52% | 2 July 2008 |
| CVE-2008-2978 | Directory traversal vulnerability in phpi/rss.php in Ourvideo CMS 9.5, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the prefix parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.85% | 2 July 2008 |
| CVE-2008-2977 | Multiple PHP remote file inclusion vulnerabilities in Ourvideo CMS 9.5 allow remote attackers to execute arbitrary PHP code via a URL in the include_connection parameter to (1) edit_top_feature.php and (2) edit_topics_feature.php in phpi/. | EXPLOIT ✓HIGH 7.5EPSS 2.43% | 2 July 2008 |
| CVE-2008-2976 | Multiple directory traversal vulnerabilities in TinX/cms 1.1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) language parameter to (a) include_me.php,… | EXPLOIT ✓MEDIUM 6.8EPSS 1.85% | 2 July 2008 |
| CVE-2008-2975 | Cross-site scripting (XSS) vulnerability in admin/objects/obj_image.php in TinX/cms 1.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 2 July 2008 |
| CVE-2008-2974 | Directory traversal vulnerability in chatconfig.php in MM Chat 1.5, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the currentlang parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.98% | 2 July 2008 |
| CVE-2008-2973 | Multiple cross-site scripting (XSS) vulnerabilities in chathead.php in MM Chat 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) sitename and (2) wmessage parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 2 July 2008 |
| CVE-2008-2972 | SQL injection vulnerability in index.php in KbLance allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a comment action. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 2 July 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.