SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,492 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 289 of 501

CVESummaryPriorityPublished
CVE-2008-2566Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the group parameter to (1) index.php or (2) the default URI.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.53%6 June 2008
CVE-2008-2565Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.php and (2) edit.php.EXPLOIT ×3 ✓HIGH 7.5EPSS 1.91%6 June 2008
CVE-2008-2564SQL injection vulnerability in the JotLoader (com_jotloader) component 1.2.1.a and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.01%6 June 2008
CVE-2008-2562SQL injection vulnerability in edCss.php in PowerPhlogger 2.2.5 and earlier allows remote authenticated users to execute arbitrary SQL commands via the css_str parameter in an edit action.EXPLOIT ✓MEDIUM 6.5EPSS 0.90%6 June 2008
CVE-2008-2561Multiple cross-site scripting (XSS) vulnerabilities in 427BB 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to (a) register.php, (b) reminder.php, and (c) search.php; the (2) uname, (3) email, and (4) email2…EXPLOIT ✓MEDIUM 4.3EPSS 1.52%6 June 2008
CVE-2008-2560SQL injection vulnerability in showpost.php in 427BB 2.3.1 allows remote attackers to execute arbitrary SQL commands via the post parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%6 June 2008
CVE-2008-2556SQL injection vulnerability in read.php in PHP Visit Counter 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the datespan parameter in a read action.EXPLOIT ✓HIGH 7.5EPSS 0.93%5 June 2008
CVE-2008-2555SQL injection vulnerability in index.php in EasyWay CMS allows remote attackers to execute arbitrary SQL commands via the mid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%5 June 2008
CVE-2008-2554Multiple SQL injection vulnerabilities in BP Blog 6.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp and (2) cat parameter to template_archives_cat.asp.EXPLOIT ✓HIGH 7.5EPSS 1.04%5 June 2008
CVE-2008-2542Stack-based buffer overflow in the getline function in Ppm/ppm.C in NASA Ames Research Center BigView 1.8 allows user-assisted remote attackers to execute arbitrary code via a crafted PNM file.EXPLOIT ✓MEDIUM 6.8EPSS 4.76%5 June 2008
CVE-2008-2551The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution of arbitrary files via a URL in the propDownloadUrl parameter with the propPostDownloadAction parameter…EXPLOIT ×2 ✓HIGH 9.3EPSS 46.9%4 June 2008
CVE-2008-1770CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an encoded LF followed by a malicious target line.EXPLOIT ✓HIGH 9.3EPSS 10.4%4 June 2008
CVE-2008-0953The StartApp function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary programs via a .exe filename in the argument, a different vulnerability…EXPLOIT ✓HIGH 10.0EPSS 8.82%4 June 2008
CVE-2008-0952The AppendStringToFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to create files with arbitrary content via a full pathname in the first argument and…EXPLOIT ✓HIGH 9.3EPSS 5.53%4 June 2008
CVE-2007-5610The DeleteSingleFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to delete an arbitrary file via a full pathname in the argument.EXPLOIT ✓HIGH 10.0EPSS 8.82%4 June 2008
CVE-2007-5607Buffer overflow in the RegistryString function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long first argument, a different…EXPLOIT ✓HIGH 7.5EPSS 12.8%4 June 2008
CVE-2007-5604Buffer overflow in the ExtractCab function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long first argument, a different…EXPLOIT ✓HIGH 7.5EPSS 11.7%4 June 2008
CVE-2008-2549Adobe Acrobat Reader 8.1.2 and earlier, and before 7.1.1, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed PDF document, as demonstrated by 2008-HI2.pdf.EXPLOIT ✓MEDIUM 4.3EPSS 52.6%4 June 2008
CVE-2008-2119Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic parsing (aka pedanticsipchecking) is enabled, allows remote attackers to cause a denial of service (daemon crash) via a SIP INVITE…EXPLOIT ✓MEDIUM 4.3EPSS 7.27%4 June 2008
CVE-2008-1661Stack-based buffer overflow in DoubleTake.exe in HP StorageWorks Storage Mirroring (SWSM) before 4.5 SP2 allows remote attackers to execute arbitrary code via a crafted encoded authentication request.EXPLOIT ×2 ✓HIGH 10.0EPSS 69.0%4 June 2008
CVE-2008-1035Use-after-free vulnerability in Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to trigger memory corruption or possibly execute arbitrary code via an "ATTACH;VALUE=URI:S=osumi" line in a .ics file, which…EXPLOIT ✓MEDIUM 4.3EPSS 10.1%3 June 2008
CVE-2008-2537SQL injection vulnerability in cat.php in HispaH Model Search allows remote attackers to execute arbitrary SQL commands via the cat parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%3 June 2008
CVE-2008-2536SQL injection vulnerability in out.php in YABSoft Advanced Image Hosting (AIH) Script 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the t parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%3 June 2008
CVE-2008-2535Multiple SQL injection vulnerabilities in Phoenix View CMS Pre Alpha2 and earlier allow remote attackers to execute arbitrary SQL commands via the del parameter to (1) gbuch.admin.php, (2) links.admin.php, (3) menue.admin.php, (4) news.admin.php, and…EXPLOIT ✓HIGH 7.5EPSS 0.93%3 June 2008
CVE-2008-2534Directory traversal vulnerability in admin/admin_frame.php in Phoenix View CMS Pre Alpha2 and earlier allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.40%3 June 2008
CVE-2008-2533Multiple cross-site scripting (XSS) vulnerabilities in Phoenix View CMS Pre Alpha2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ltarget parameter to (a) admin/admin_frame.php and the (2) conf parameter to (b)…EXPLOIT ✓MEDIUM 4.3EPSS 1.44%3 June 2008
CVE-2008-2532SQL injection vulnerability in forum/topic_detail.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%3 June 2008
CVE-2008-2530Multiple SQL injection vulnerabilities in Concepts & Solutions QuickUpCMS allow remote attackers to execute arbitrary SQL commands via the (1) nr parameter to (a) frontend/news.php, the (2) id parameter to (b) events3.php and (c) videos2.php in…EXPLOIT ✓HIGH 7.5EPSS 1.00%3 June 2008
CVE-2008-2529SQL injection vulnerability in read.php in Advanced Links Management (ALM) 1.5.2 allows remote attackers to execute arbitrary SQL commands via the catId parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%3 June 2008
CVE-2008-2522SQL injection vulnerability in members.php in Battle.net Clan Script for PHP 1.5.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the showmember parameter in a members action.EXPLOIT ✓MEDIUM 6.8EPSS 0.95%3 June 2008
CVE-2008-2521SQL injection vulnerability in members.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote authenticated users to execute arbitrary SQL commands via the fid parameter.EXPLOIT ✓MEDIUM 6.5EPSS 0.90%3 June 2008
CVE-2008-2520Multiple PHP remote file inclusion vulnerabilities in BigACE 2.4, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[_BIGACE][DIR][addon] parameter to (a)…EXPLOIT ✓HIGH 7.5EPSS 2.50%3 June 2008
CVE-2008-2511Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEventCli.dll in CA Internet Security Suite 2008 allows remote attackers to create and overwrite arbitrary files via a ..EXPLOIT ✓HIGH 9.3EPSS 10.0%2 June 2008
CVE-2008-2510SQL injection vulnerability in wp-uploadfile.php in the Upload File plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the f_id parameter.EXPLOIT ✓HIGH 7.5EPSS 2.01%29 May 2008
CVE-2008-2509SQL injection vulnerability in pwd.asp in Excuse Online allows remote attackers to execute arbitrary SQL commands via the pID parameter.EXPLOIT ✓HIGH 7.5EPSS 0.96%29 May 2008
CVE-2008-2508Cross-site scripting (XSS) vulnerability in news.php in Tr Script News 2.1 allows remote attackers to inject arbitrary web script or HTML via the "nb" parameter in voir mode.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%29 May 2008
CVE-2008-2507Cross-site scripting (XSS) vulnerability in Calcium40.pl in Brown Bear Software Calcium 3.10 and 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the CalendarName parameter in a ShowIt action.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%29 May 2008
CVE-2008-2506Multiple SQL injection vulnerabilities in Simpel Side Weblosning 1 through 4 allow remote attackers to execute arbitrary SQL commands via the (1) mainid and (2) id parameters to index2.php.EXPLOIT ✓HIGH 7.5EPSS 1.00%29 May 2008
CVE-2008-2505Cross-site scripting (XSS) vulnerability in result.php in Simpel Side Weblosning 1 through 4 allows remote attackers to inject arbitrary web script or HTML via the search parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%29 May 2008
CVE-2008-2504Multiple SQL injection vulnerabilities in Simpel Side Netbutik 1 through 4 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to netbutik.php and the (2) id parameter to product.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%29 May 2008
CVE-2008-2501Multiple SQL injection vulnerabilities in PHPhotoalbum 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) album parameter to thumbnails.php and the (2) pid parameter to displayimage.php.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.01%29 May 2008
CVE-2008-2499Stack-based buffer overflow in the Community Services Multiplexer (aka MUX or StMux.exe) in IBM Lotus Sametime 7.5.1 CF1 and earlier, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code via a crafted URL.EXPLOIT ×2 ✓HIGH 7.5EPSS 77.5%29 May 2008
CVE-2008-2158Multiple stack-based buffer overflows in the Command Line Interface process in the Server Agent in EMC AlphaStor 3.1 SP1 for Windows allow remote attackers to execute arbitrary code via crafted TCP packets to port 41025.EXPLOIT ✓HIGH 10.0EPSS 58.4%29 May 2008
CVE-2008-1105Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute arbitrary code via a crafted SMB response.EXPLOIT ✓HIGH 7.5EPSS 69.1%29 May 2008
CVE-2008-0955Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote attackers to execute arbitrary code via a long CacheFolder property value.EXPLOIT ×2 ✓HIGH 9.3EPSS 41.2%29 May 2008
CVE-2008-2496Multiple cross-site scripting (XSS) vulnerabilities in Quate CMS 0.3.4 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) login.php, and (3) credits.php in admin/, and (4) upgrade/index.php.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%28 May 2008
CVE-2008-2493Cross-site scripting (XSS) vulnerability in post3/Book.asp in Campus Bulletin Board 3.4 allows remote attackers to inject arbitrary web script or HTML via the review parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%28 May 2008
CVE-2008-2492Multiple SQL injection vulnerabilities in Campus Bulletin Board 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to post3/view.asp and the (2) review parameter to post3/book.asp.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97%28 May 2008
CVE-2008-2491SQL injection vulnerability in adv_cat.php in AbleSpace 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.96%28 May 2008
CVE-2008-2488admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated users to create new admin accounts.EXPLOIT ✓MEDIUM 6.5EPSS 1.94%28 May 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.