SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,483 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 286 of 501

CVESummaryPriorityPublished
CVE-2008-2889Directory traversal vulnerability in the FTP client in AceBIT WISE-FTP 4.1.0 and 5.5.8 allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to CVE-2002-1345.EXPLOIT ✓MEDIUM 6.8EPSS 2.21%27 June 2008
CVE-2008-2888Multiple PHP remote file inclusion vulnerabilities in MiGCMS 2.0.5, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[application][app_root] parameter to (1) collection.class.php and (2)…EXPLOIT ✓HIGH 10.0EPSS 8.01%27 June 2008
CVE-2008-2887Directory traversal vulnerability in index.php in chaozz@work FubarForum 1.5 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.93%27 June 2008
CVE-2008-2886PHP remote file inclusion vulnerability in include/plugins/jrBrowser/purchase.php in Jamroom 3.3.0 through 3.3.5, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the jamroom[jm_dir] parameter.EXPLOIT ✓HIGH 9.3EPSS 3.79%27 June 2008
CVE-2008-2885PHP remote file inclusion vulnerability in src/browser/resource/categories/resource_categories_view.php in Open Digital Assets Repository System (ODARS) 1.0.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a…EXPLOIT ✓HIGH 9.3EPSS 2.94%27 June 2008
CVE-2008-2884PHP remote file inclusion vulnerability in display.php in RSS-aggregator allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.EXPLOIT ✓HIGH 9.3EPSS 3.16%27 June 2008
CVE-2008-2883PHP remote file inclusion vulnerability in include/plugins/jrBrowser/payment.php in Jamroom 3.3.0 through 3.3.5 allows remote attackers to execute arbitrary PHP code via a URL in the jamroom[jm_dir] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.31%26 June 2008
CVE-2008-2882upgrade.asp in sHibby sHop 2.2 and earlier does not require administrative authentication, which allows remote attackers to update a file or have unspecified other impact via a direct request.EXPLOIT ✓HIGH 7.5EPSS 2.58%26 June 2008
CVE-2008-2881Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.EXPLOIT ✓MEDIUM 5.0EPSS 2.07%26 June 2008
CVE-2008-2878Open redirect vulnerability in rss_getfile.php in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the file parameter.EXPLOIT ✓MEDIUM 6.4EPSS 2.79%26 June 2008
CVE-2008-2877PHP remote file inclusion vulnerability in admin/include/lib.module.php in cmsWorks 2.2 RC4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mod_root parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.81%26 June 2008
CVE-2008-2876Directory traversal vulnerability in index.php in mUnky 0.0.1 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 3.09%26 June 2008
CVE-2008-2875SQL injection vulnerability in index.php in Webdevindo-CMS 1.0.0 allows remote attackers to execute arbitrary SQL commands via the hal parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%26 June 2008
CVE-2008-2874SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitrary SQL commands via the sbjoke_id parameter, a different vector than CVE-2008-1050.EXPLOIT ✓HIGH 7.5EPSS 1.04%26 June 2008
CVE-2008-2873sHibby sHop 2.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request to Db/urun.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.59%26 June 2008
CVE-2008-2872SQL injection vulnerability in default.asp in sHibby sHop 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sayfa parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%26 June 2008
CVE-2008-2871Multiple cross-site scripting (XSS) vulnerabilities in template2.php in PEGames allow remote attackers to inject arbitrary web script or HTML via the (1) sitetitle, (2) sitenav, (3) sitemain, and (4) sitealt parameters.EXPLOIT ✓MEDIUM 4.3EPSS 1.20%26 June 2008
CVE-2008-2870Multiple SQL injection vulnerabilities in ShareCMS 0.1 Beta allow remote attackers to execute arbitrary SQL commands via the (1) eventID parameter to event_info.php and the (2) userID parameter to list_user.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%26 June 2008
CVE-2008-2869SQL injection vulnerability in out.php in E-topbiz Link ADS 1 allows remote attackers to execute arbitrary SQL commands via the linkid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%26 June 2008
CVE-2008-2868SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the iEve parameter.EXPLOIT ✓HIGH 7.5EPSS 1.15%26 June 2008
CVE-2008-2867SQL injection vulnerability in adclick.php in E-topbiz Viral DX 1 2.07 allows remote attackers to execute arbitrary SQL commands via the bannerid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%26 June 2008
CVE-2008-2866SQL injection vulnerability in csc_article_details.php in Caupo.net CaupoShop Classic 1.3 allows remote attackers to execute arbitrary SQL commands via the saArticle[ID] parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%25 June 2008
CVE-2008-2865SQL injection vulnerability in index.php in Kalptaru Infotech PHP Site Lock 2.0 allows remote attackers to execute arbitrary SQL commands via the articleid parameter in a show_article action.EXPLOIT ✓HIGH 7.5EPSS 0.97%25 June 2008
CVE-2008-2864eLineStudio Site Composer (ESC) 2.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) trigger.asp or (2) common2.asp in cms/include/, which reveals the database path.EXPLOIT ✓MEDIUM 5.0EPSS 2.52%25 June 2008
CVE-2008-2863Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create or delete arbitrary directories via a full pathname in the inpCurrFolder parameter to (1) folderdel_.asp or (2) foldernew.asp in…EXPLOIT ✓HIGH 7.5EPSS 2.94%25 June 2008
CVE-2008-2862Multiple SQL injection vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to ansFAQ.asp and the (2) template_id parameter to preview.asp.EXPLOIT ✓HIGH 7.5EPSS 1.68%25 June 2008
CVE-2008-2861Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) button parameters to ansFAQ.asp and the (3) id and (4)…EXPLOIT ✓MEDIUM 4.3EPSS 1.72%25 June 2008
CVE-2008-2860SQL injection vulnerability in category.php in AJSquare AJ Auction Pro web 2.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%25 June 2008
CVE-2008-2859Unspecified vulnerability in the IMAP service in NetWin SurgeMail before 3.9g2 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors related to an "imap command."EXPLOIT ✓MEDIUM 5.0EPSS 3.38%25 June 2008
CVE-2008-2858SQL injection vulnerability in index.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the eml parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.82%25 June 2008
CVE-2008-2857AlstraSoft AskMe Pro 2.1 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.EXPLOIT ✓MEDIUM 5.0EPSS 2.11%25 June 2008
CVE-2008-2856SQL injection vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%25 June 2008
CVE-2008-2855Cross-site scripting (XSS) vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to inject arbitrary web script or HTML via the id parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%25 June 2008
CVE-2008-2854Multiple PHP remote file inclusion vulnerabilities in Orlando CMS 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[preloc] parameter to (1) modules/core/logger/init.php and (2) AJAX/newscat.php.EXPLOIT ✓HIGH 7.5EPSS 2.29%25 June 2008
CVE-2008-2853SQL injection vulnerability in index.php in Easy Webstore 1.2 allows remote attackers to execute arbitrary SQL commands via the cat_path parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%25 June 2008
CVE-2008-2847SQL injection vulnerability in the Trade module in Maxtrade AIO 1.3.23 allows remote attackers to execute arbitrary SQL commands via the categori parameter in a pocategorisell action to modules.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%25 June 2008
CVE-2008-2846SQL injection vulnerability in index.php in BoatScripts Classifieds allows remote attackers to execute arbitrary SQL commands via the type parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%25 June 2008
CVE-2008-2845SQL injection vulnerability in index.php in MyBizz-Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%25 June 2008
CVE-2008-2844SQL injection vulnerability in index.php in Carscripts Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%25 June 2008
CVE-2008-2843Multiple SQL injection vulnerabilities in doITLive CMS 2.50 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter in an USUB action to default.asp and the (2) Licence[SpecialLicenseNumber] (aka LicenceId) cookie…EXPLOIT ✓HIGH 7.5EPSS 1.15%25 June 2008
CVE-2008-2842Cross-site scripting (XSS) vulnerability in edit/showmedia.asp in doITLive CMS 2.50 and earlier allows remote attackers to inject arbitrary web script or HTML via the FILE parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%25 June 2008
CVE-2008-2841Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary commands via the --command parameter in an ircs:// URI.EXPLOIT ✓MEDIUM 6.8EPSS 15.4%24 June 2008
CVE-2008-2839Cross-site scripting (XSS) vulnerability in the search module in Traindepot 0.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter to index.php.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%24 June 2008
CVE-2008-2838Directory traversal vulnerability in index.php in Traindepot 0.1 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.67%24 June 2008
CVE-2008-2837SQL injection vulnerability in index.php in CMS-BRD allows remote attackers to execute arbitrary SQL commands via the menuclick parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%24 June 2008
CVE-2008-2836PHP remote file inclusion vulnerability in send_reminders.php in WebCalendar 1.0.4 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter and a 0 value for the noSet parameter, a different vector than CVE-2007-1483.EXPLOIT ✓HIGH 7.5EPSS 3.09%24 June 2008
CVE-2008-2835SQL injection vulnerability in cgi-bin/igsuite in IGSuite 3.2.4 allows remote attackers to execute arbitrary SQL commands via the formid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%24 June 2008
CVE-2008-2834SQL injection vulnerability in projects.php in Scientific Image DataBase 0.41 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%24 June 2008
CVE-2008-2833admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in images/, via a nonzero value for the submit0 parameter in conjunction with filenames in the filename…EXPLOIT ✓HIGH 10.0EPSS 4.13%24 June 2008
CVE-2008-2832Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an uploadfileprocess action, probably followed by a direct…EXPLOIT ✓HIGH 10.0EPSS 11.8%24 June 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.