Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,492 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 287 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-2427 | Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted remote attackers to execute arbitrary code via a crafted format keyword in a Sun TAAC file. | EXPLOIT ✓HIGH 9.3EPSS 16.1% | 24 June 2008 |
| CVE-2008-2830 | Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versions, does not properly restrict the loading of scripting addition plugins, which allows local users to gain privileges via scripting addition commands to… | EXPLOIT ✓HIGH 7.2EPSS 0.87% | 23 June 2008 |
| CVE-2008-2827 | The rmtree function in lib/File/Path.pm in Perl 5.10 does not properly check permissions before performing a chmod, which allows local users to modify the permissions of arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448… | EXPLOIT ✓MEDIUM 4.6EPSS 0.84% | 23 June 2008 |
| CVE-2008-2823 | SQL injection vulnerability in newsarchive.php in PHPeasyblog (formerly phpeasynews) 1.13 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the post parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 23 June 2008 |
| CVE-2008-2822 | Multiple directory traversal vulnerabilities in the FTP client in 3D-FTP Client 8.01 (8.0 build 1) allow remote FTP servers to create or overwrite arbitrary files via a .. | EXPLOIT ✓HIGH 9.3EPSS 3.04% | 23 June 2008 |
| CVE-2008-2821 | Directory traversal vulnerability in the FTP client in Glub Tech Secure FTP before 2.5.16 on Windows allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to… | EXPLOIT ✓HIGH 9.3EPSS 2.53% | 23 June 2008 |
| CVE-2008-2820 | Directory traversal vulnerability in lang/lang-system.php in Open Azimyt CMS 0.22 minimal and 0.21 stable allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.4EPSS 2.96% | 23 June 2008 |
| CVE-2008-2818 | Directory traversal vulnerability in Easy-Clanpage 3.0 b1 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 23 June 2008 |
| CVE-2008-2817 | SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the CatId parameter in a show action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 23 June 2008 |
| CVE-2008-2816 | SQL injection vulnerability in post.php in Oxygen (aka O2PHP Bulletin Board) 2.0 allows remote attackers to execute arbitrary SQL commands via the repquote parameter in a reply action, a different vector than CVE-2006-1572. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 23 June 2008 |
| CVE-2008-2815 | SQL injection vulnerability in shopping/index.php in MyMarket 1.72 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 23 June 2008 |
| CVE-2008-2814 | Cross-site scripting (XSS) vulnerability in WallCity-Server Shoutcast Admin Panel 2.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter to the login interface. | EXPLOIT ✓MEDIUM 4.3EPSS 1.20% | 23 June 2008 |
| CVE-2008-2813 | Directory traversal vulnerability in index.php in WallCity-Server Shoutcast Admin Panel 2.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.86% | 23 June 2008 |
| CVE-2008-2796 | SQL injection vulnerability in index.php in FreeCMS 0.2 allows remote attackers to execute arbitrary SQL commands via the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 20 June 2008 |
| CVE-2008-2795 | Directory traversal vulnerability in the FTP and SFTP clients in IDM Computer Solutions Inc UltraEdit 14.00b allows remote FTP servers to create or overwrite arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 9.53% | 20 June 2008 |
| CVE-2008-2793 | SQL injection vulnerability in group_posts.php in ClipShare before 3.0.1 allows remote attackers to execute arbitrary SQL commands via the tid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 20 June 2008 |
| CVE-2008-2792 | SQL injection vulnerability in index.php in eroCMS 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the site parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 20 June 2008 |
| CVE-2008-2791 | SQL injection vulnerability in product.detail.php in Kalptaru Infotech Comparison Engine Power Script 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 20 June 2008 |
| CVE-2008-2790 | SQL injection vulnerability in detail.php in MountainGrafix easyTrade 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.06% | 20 June 2008 |
| CVE-2008-2789 | SQL injection vulnerability in pages/index.php in BASIC-CMS allows remote attackers to execute arbitrary SQL commands via the page_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 22.8% | 20 June 2008 |
| CVE-2008-2787 | Cross-site scripting (XSS) vulnerability in out.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the last_message parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.83% | 20 June 2008 |
| CVE-2008-2666 | Multiple directory traversal vulnerabilities in PHP 5.2.6 and earlier allow context-dependent attackers to bypass safe_mode restrictions by creating a subdirectory named http: and then placing ../ (dot dot slash) sequences in an http URL argument to the… | EXPLOIT ✓MEDIUM 5.0EPSS 13.9% | 20 June 2008 |
| CVE-2008-2783 | Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware, Groupware Webmail Edition, and Kronolith allow remote attackers to inject arbitrary web script or HTML via the timestamp parameter to (1) week.php, (2) workweek.php, and (3)… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.50% | 19 June 2008 |
| CVE-2008-2782 | Multiple directory traversal vulnerabilities in OtomiGenX 2.2 allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.42% | 19 June 2008 |
| CVE-2008-2781 | SQL injection vulnerability in index.php in DZOIC Handshakes 3.5 allows remote attackers to execute arbitrary SQL commands via the fname parameter in a members search action. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 19 June 2008 |
| CVE-2008-2778 | SQL injection vulnerability in inc/class_search.php in the Search System in RevokeBB 1.0 RC11 allows remote attackers to execute arbitrary SQL commands via the search parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 19 June 2008 |
| CVE-2008-2774 | SQL injection vulnerability in item.php in CartKeeper CKGold Shopping Cart 2.5 and 2.7 allows remote attackers to execute arbitrary SQL commands via the category_id parameter, a different vector than CVE-2007-4736. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 19 June 2008 |
| CVE-2008-2770 | SQL injection vulnerability in index.php in MycroCMS 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the entry_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 18 June 2008 |
| CVE-2008-2755 | SQL injection vulnerability in index.php in JAMM CMS allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 18 June 2008 |
| CVE-2008-2754 | SQL injection vulnerability in toplists.php in eFiction 3.0 and 3.4.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the list parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 18 June 2008 |
| CVE-2008-2753 | Multiple SQL injection vulnerabilities in Pooya Site Builder (PSB) 6.0 allow remote attackers to execute arbitrary SQL commands via the (1) xslIdn parameter to (a) utils/getXsl.aspx, and the (2) part parameter to (b) getXml.aspx and (c) getXls.aspx in… | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 18 June 2008 |
| CVE-2008-2752 | Microsoft Word 2000 9.0.2812 and 2003 11.8106.8172 does not properly handle unordered lists, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a… | EXPLOIT ✓HIGH 7.1EPSS 27.8% | 18 June 2008 |
| CVE-2008-2751 | Multiple cross-site scripting (XSS) vulnerabilities in the Glassfish webadmin interface in Sun Java System Application Server 9.1_01 allow remote attackers to inject arbitrary web script or HTML via the (1)… | EXPLOIT ×7 ✓MEDIUM 4.3EPSS 4.83% | 18 June 2008 |
| CVE-2008-2748 | Skulltag 0.97d2-RC2 and earlier allows remote attackers to cause a denial of service (daemon hang) via a series of long, malformed connect packets, related to these packets being "parsed multiple times." | EXPLOIT ✓MEDIUM 5.0EPSS 3.49% | 18 June 2008 |
| CVE-2008-2746 | SQL injection vulnerability in login.php in Gryphon gllcTS2 4.2.4 allows remote attackers to execute arbitrary SQL commands via the detail parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 17 June 2008 |
| CVE-2008-2745 | Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows remote attackers to execute arbitrary code via a long parameter to the AnnoSaveToTiff method. | EXPLOIT ×2 ✓HIGH 9.3EPSS 11.4% | 17 June 2008 |
| CVE-2008-2744 | Cross-site scripting (XSS) vulnerability in vBulletin 3.6.10 and 3.7.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors and an "obscure method." NOTE: the vector is probably in the redirect parameter to the Admin… | EXPLOIT ✓MEDIUM 4.3EPSS 1.98% | 17 June 2008 |
| CVE-2008-2742 | Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php) in Achievo 1.2.0 through 1.3.2 allows remote attackers to execute arbitrary code by uploading a file with .php followed by… | EXPLOIT ✓HIGH 7.5EPSS 4.71% | 17 June 2008 |
| CVE-2008-2719 | Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) 2.02 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted file that triggers a stack-based buffer… | EXPLOIT ✓MEDIUM 6.8EPSS 10.5% | 16 June 2008 |
| CVE-2008-2712 | Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize inputs before invoking the execute or system functions, as demonstrated using (1) filetype.vim, (3)… | EXPLOITHIGH 9.3EPSS 15.0% | 16 June 2008 |
| CVE-2008-2639 | Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows remote attackers to execute arbitrary code via a long string in the second application packet in a TCP session on port 20222. | EXPLOIT ×2 ✓HIGH 7.6EPSS 77.7% | 16 June 2008 |
| CVE-2008-0071 | The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a malformed Range header. | EXPLOIT ✓MEDIUM 4.3EPSS 7.19% | 16 June 2008 |
| CVE-2008-2703 | Multiple stack-based buffer overflows in Novell GroupWise Messenger (GWIM) Client before 2.0.3 HP1 for Windows allow remote attackers to execute arbitrary code via "spoofed server responses" that contain a long string after the NM_A_SZ_TRANSACTION_ID… | EXPLOIT ×2 ✓HIGH 10.0EPSS 61.1% | 13 June 2008 |
| CVE-2008-2702 | Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overwrite arbitrary files via a .. | EXPLOIT ✓HIGH 9.3EPSS 10.7% | 13 June 2008 |
| CVE-2008-2701 | SQL injection vulnerability in the GameQ (com_gameq) component 4.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a page action to index.php. | EXPLOIT ✓MEDIUM 6.8EPSS 1.64% | 13 June 2008 |
| CVE-2008-2700 | SQL injection vulnerability in view.php in Galatolo WebManager 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 13 June 2008 |
| CVE-2008-2699 | Multiple directory traversal vulnerabilities in Galatolo WebManager (GWM) 1.0 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in (1) the plugin parameter to admin/plugins.php or (2) the com parameter… | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 13 June 2008 |
| CVE-2008-2697 | SQL injection vulnerability in the Rapid Recipe (com_rapidrecipe) component 1.6.6 and 1.6.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the recipe_id parameter in a viewrecipe action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 13 June 2008 |
| CVE-2008-2695 | Directory traversal vulnerability in entry.php in phpInv 0.8.0 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 13 June 2008 |
| CVE-2008-2694 | Cross-site scripting (XSS) vulnerability in search.php in phpInv 0.8.0 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 13 June 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.