SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,492 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 288 of 501

CVESummaryPriorityPublished
CVE-2008-2693Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via a long first argument to the SetByteOrder method.EXPLOIT ×2 ✓HIGH 9.3EPSS 10.1%13 June 2008
CVE-2008-2692SQL injection vulnerability in the yvComment (com_yvcomment) component 1.16.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the ArticleID parameter in a comment action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.01%13 June 2008
CVE-2008-2691SQL injection vulnerability in read.asp in JiRo's FAQ Manager eXperience 1.0 allows remote attackers to execute arbitrary SQL commands via the fID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%13 June 2008
CVE-2008-2690Multiple PHP remote file inclusion vulnerabilities in BrowserCRM 5.002.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the bcrm_pub_root parameter to (1) kb.php, (2) login.php, (3) index.php, (4)…EXPLOIT ✓HIGH 9.3EPSS 2.31%13 June 2008
CVE-2008-2689PHP remote file inclusion vulnerability in pub/clients.php in BrowserCRM 5.002.00 allows remote attackers to execute arbitrary PHP code via a URL in the bcrm_pub_root parameter.EXPLOIT ✓HIGH 10.0EPSS 46.2%13 June 2008
CVE-2008-2688SQL injection vulnerability in pilot.asp in ASPilot Pilot Cart 7.3 allows remote attackers to execute arbitrary SQL commands via the article parameter in a kb action.EXPLOIT ×2 ✓HIGH 7.5EPSS 2.01%13 June 2008
CVE-2008-2687Directory traversal vulnerability in inc/config.php in ProManager 0.73 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.49%13 June 2008
CVE-2008-2686webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overwriting a PHP file in webinc/bxe/scripts/ via a filename in the XML parameter and PHP sequences in the request body, then making a…EXPLOIT ✓HIGH 7.5EPSS 3.94%13 June 2008
CVE-2008-2684The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via long strings in the two arguments to the DownloadImageFileURL method, which trigger memory corruption.EXPLOIT ✓HIGH 9.3EPSS 8.74%12 June 2008
CVE-2008-2683The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to force the download and storage of arbitrary files by specifying the origin URL in the first argument to the DownloadImageFileURL method,…EXPLOIT ×3 ✓HIGH 9.3EPSS 34.8%12 June 2008
CVE-2008-2682_RealmAdmin/login.asp in Realm CMS 2.3 and earlier allows remote attackers to bypass authentication and access admin pages via certain modified cookies, probably including (1) cUserRole, (2) cUserName, and (3) cUserID.EXPLOIT ✓HIGH 7.5EPSS 2.53%12 June 2008
CVE-2008-2681Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.asp, which reveals the database path in an error message.EXPLOIT ✓MEDIUM 5.0EPSS 2.61%12 June 2008
CVE-2008-2680Multiple cross-site scripting (XSS) vulnerabilities in _db/compact.asp in Realm CMS 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) CmpctedDB and (2) Boyut parameters.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%12 June 2008
CVE-2008-2679SQL injection vulnerability in the KeyWordsList function in _includes/inc_routines.asp in Realm CMS 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the kwrd parameter in a kwl action to the default URI.EXPLOIT ✓HIGH 7.5EPSS 1.00%12 June 2008
CVE-2008-2678Multiple SQL injection vulnerabilities in Telephone Directory 2008, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) code parameter in a confirm_data action to edit1.php and the (2) id parameter to…EXPLOIT ✓HIGH 7.5EPSS 2.06%12 June 2008
CVE-2008-2677Cross-site scripting (XSS) vulnerability in edit1.php in Telephone Directory 2008 allows remote attackers to inject arbitrary web script or HTML via the action parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.51%12 June 2008
CVE-2008-2676SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.93%12 June 2008
CVE-2008-2673SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the shownews parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%12 June 2008
CVE-2008-2672Multiple directory traversal vulnerabilities in ErfurtWiki R1.02b and earlier, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 3.53%12 June 2008
CVE-2008-2671SQL injection vulnerability in comments.php in DCFM Blog 0.9.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.17%12 June 2008
CVE-2008-2670Multiple SQL injection vulnerabilities in index.php in Insanely Simple Blog 0.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter, or (2) the term parameter in a search action.EXPLOIT ✓HIGH 7.5EPSS 1.00%12 June 2008
CVE-2008-2669Multiple SQL injection vulnerabilities in yBlog 0.2.2.2 allow remote attackers to execute arbitrary SQL commands via (1) the q parameter to search.php, or the n parameter to (2) user.php or (3) uss.php.EXPLOIT ✓HIGH 7.5EPSS 1.18%12 June 2008
CVE-2008-2668Multiple cross-site scripting (XSS) vulnerabilities in yBlog 0.2.2.2 allow remote attackers to inject arbitrary web script or HTML via (1) the q parameter to search.php, or the n parameter to (2) user.php or (3) uss.php.EXPLOIT ✓MEDIUM 4.3EPSS 1.77%12 June 2008
CVE-2008-2652Multiple SQL injection vulnerabilities in catalog.php in SMEWeb 1.4b and 1.4f allow remote attackers to execute arbitrary SQL commands via the (1) idp and (2) category parameters.EXPLOIT ✓HIGH 7.5EPSS 1.04%10 June 2008
CVE-2008-2651SQL injection vulnerability in the Joomla!EXPLOIT ✓HIGH 7.5EPSS 0.93%10 June 2008
CVE-2008-2650Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 18.8%10 June 2008
CVE-2008-2649Multiple PHP remote file inclusion vulnerabilities in DesktopOnNet 3 Beta allow remote attackers to execute arbitrary PHP code via a URL in the app_path parameter to (1) don3_requiem.don3app/don3_requiem.php and (2) frontpage.don3app/frontpage.php.EXPLOIT ✓HIGH 7.5EPSS 2.10%10 June 2008
CVE-2008-2648Unrestricted file upload vulnerability in upload/uploader.html in meBiblio 0.4.7 allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the files/ directory.EXPLOIT ✓MEDIUM 6.8EPSS 3.33%10 June 2008
CVE-2008-2647SQL injection vulnerability in admin/journal_change_mask.inc.php in meBiblio 0.4.7 allows remote attackers to execute arbitrary SQL commands via the JID parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%10 June 2008
CVE-2008-2646Multiple cross-site scripting (XSS) vulnerabilities in meBiblio 0.4.7 allow remote attackers to inject arbitrary web script or HTML via the (1) sql parameter to dbadd.inc.php, (2) InsertJournal parameter to add_journal_mask.inc.php, (3)…EXPLOIT ✓MEDIUM 4.3EPSS 1.44%10 June 2008
CVE-2008-2645Multiple PHP remote file inclusion vulnerabilities in Brim (formerly Booby) 1.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the renderer parameter to template.tpl.php in (1) barrel/, (2) barry/, (3) mylook/, (4) oerdec/, (5)…EXPLOIT ✓HIGH 7.5EPSS 39.0%10 June 2008
CVE-2008-2644Multiple cross-site scripting (XSS) vulnerabilities in SMEWeb 1.4b and 1.4f allow remote attackers to inject arbitrary web script or HTML via the (1) data parameter to catalog.php, the (2) keyword parameter to search.php, the (3) page parameter to…EXPLOIT ✓MEDIUM 4.3EPSS 1.57%10 June 2008
CVE-2008-2643SQL injection vulnerability in the Bible Study (com_biblestudy) component before 6.0.7c for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a mediaplayer action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.01%10 June 2008
CVE-2008-0960SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data…EXPLOIT ✓HIGH 10.0EPSS 68.8%10 June 2008
CVE-2008-2638Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message parameter in an HTML webform, which is written to data.php.EXPLOIT ✓HIGH 10.0EPSS 3.86%10 June 2008
CVE-2008-2637Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN 6.0.2 hotfix 3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via quotes in (1) the css_exceptions parameter in…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.82%10 June 2008
CVE-2008-2634SQL injection vulnerability in index.asp in I-Pos Internet Pay Online Store 1.3 Beta and earlier allows remote attackers to execute arbitrary SQL commands via the item parameter.EXPLOIT ✓HIGH 7.5EPSS 0.93%10 June 2008
CVE-2008-2633Multiple SQL injection vulnerabilities in the EXP JoomRadio (com_joomradio) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) show_radio or (2) show_video action to index.php.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.21%10 June 2008
CVE-2008-2632SQL injection vulnerability in the acctexp (com_acctexp) component 0.12.x and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the usage parameter in a subscribe action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.93%10 June 2008
CVE-2008-2631The WordClient interface in Alt-N Technologies MDaemon 9.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted HTTP POST request.EXPLOIT ✓MEDIUM 5.0EPSS 22.8%10 June 2008
CVE-2008-2630SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter in a category action to index.php.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.02%10 June 2008
CVE-2008-2629SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitrary SQL commands via the albumId parameter in a ViewAlbum action to index.php.EXPLOIT ✓HIGH 7.5EPSS 2.06%10 June 2008
CVE-2008-2628SQL injection vulnerability in the eQuotes (com_equotes) component 0.9.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.93%10 June 2008
CVE-2008-2627SQL injection vulnerability in the IDoBlog (com_idoblog) component b24 and earlier and 1.0, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the userid parameter in a userblog action to index.php.EXPLOIT ✓HIGH 7.5EPSS 2.06%10 June 2008
CVE-2008-2626SQL injection vulnerability in comment.asp in Battle Blog 1.25 and earlier allows remote attackers to execute arbitrary SQL commands via the entry parameter.EXPLOIT ✓HIGH 7.5EPSS 1.20%10 June 2008
CVE-2008-2574Unrestricted file upload vulnerability in admin/Editor/imgupload.php in FlashBlog 0.31 beta allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in tus_imagenes/.EXPLOIT ✓HIGH 7.5EPSS 4.78%6 June 2008
CVE-2008-2573Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a long directory name in an SSH_FXP_OPENDIR (aka opendir) command.EXPLOIT ×2 ✓HIGH 8.5EPSS 5.61%6 June 2008
CVE-2008-2572SQL injection vulnerability in php/leer_comentarios.php in FlashBlog allows remote attackers to execute arbitrary SQL commands via the articulo_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%6 June 2008
CVE-2008-2569SQL injection vulnerability in the EasyBook (com_easybook) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a deleteentry action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.00%6 June 2008
CVE-2008-2568SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component 3.4 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a browse action to index.php.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.05%6 June 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.