Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,492 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 290 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-2487 | SQL injection vulnerability in index.php in MAXSITE 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a webboard action. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 28 May 2008 |
| CVE-2008-2484 | SQL injection vulnerability in index.php in Xomol CMS 1.20071213, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the email parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.94% | 28 May 2008 |
| CVE-2008-2483 | Directory traversal vulnerability in index.php in Xomol CMS 1.20071213 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.92% | 28 May 2008 |
| CVE-2008-2482 | Directory traversal vulnerability in install_mod.php in insanevisions OneCMS 2.5 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.84% | 28 May 2008 |
| CVE-2008-2481 | PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pConfig_auth[phpbb_path]… | EXPLOIT ✓HIGH 10.0EPSS 5.04% | 28 May 2008 |
| CVE-2008-2480 | PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the _pages_dir parameter. | EXPLOIT ✓HIGH 10.0EPSS 3.85% | 28 May 2008 |
| CVE-2008-2479 | Multiple SQL injection vulnerabilities in phpFix 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) kind parameter to fix/browse.php and the (2) account parameter to auth/00_pass.php. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 0.95% | 28 May 2008 |
| CVE-2008-2478 | scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with reseller privileges to execute arbitrary code via shell metacharacters in the Email address field (aka Email text box). | EXPLOIT ✓HIGH 8.5EPSS 4.21% | 28 May 2008 |
| CVE-2008-2477 | SQL injection vulnerability in index.php in MxBB (aka MX-System) Portal 2.7.3 allows remote attackers to execute arbitrary SQL commands via the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 28 May 2008 |
| CVE-2008-2461 | SQL injection vulnerability in index.php in Netious CMS 0.4 allows remote attackers to execute arbitrary SQL commands via the pageid parameter, a different vector than CVE-2006-4047. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 27 May 2008 |
| CVE-2008-2459 | Directory traversal vulnerability in page.php in EntertainmentScript 1.4.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.93% | 27 May 2008 |
| CVE-2008-2458 | Cross-site scripting (XSS) vulnerability in index.php in Starsgames Control Panel 4.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the st parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 27 May 2008 |
| CVE-2008-2457 | SQL injection vulnerability in jokes_category.php in PHP-Jokesite 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 27 May 2008 |
| CVE-2008-2456 | SQL injection vulnerability in index.php in ComicShout 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the comic_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 27 May 2008 |
| CVE-2008-2455 | SQL injection vulnerability in comment.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the rid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 27 May 2008 |
| CVE-2008-2454 | SQL injection vulnerability in the xsstream-dm (com_xsstream-dm) component 0.01 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the movie parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 27 May 2008 |
| CVE-2008-2453 | Multiple SQL injection vulnerabilities in PHP Classifieds Script allow remote attackers to execute arbitrary SQL commands via the fatherID parameter to (1) browse.php and (2) search.php. | EXPLOIT ✓HIGH 7.5EPSS 2.00% | 27 May 2008 |
| CVE-2008-2449 | Multiple cross-site scripting (XSS) vulnerabilities in Isaac McGowan phpInstantGallery 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) gallery parameter to (a) index.php and (b) image.php, and the (2) imgnum parameter to… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.48% | 27 May 2008 |
| CVE-2008-2448 | Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) admin/duzenle.asp and (b) admin_oku.asp; the (2) kid parameter to (c) kategori.asp and (d)… | EXPLOIT ✓HIGH 7.5EPSS 2.27% | 27 May 2008 |
| CVE-2008-2447 | SQL injection vulnerability in products.php in the Mytipper ZoGo-shop plugin 1.15.5 and 1.16 Beta 13 for e107 allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 27 May 2008 |
| CVE-2008-2446 | Multiple SQL injection vulnerabilities in Web Group Communication Center (WGCC) 1.0.3 PreRelease 1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) userid parameter to (a) profile.php in a "show moreinfo"… | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 27 May 2008 |
| CVE-2008-2445 | Cross-site scripting (XSS) vulnerability in profile.php in Web Group Communication Center (WGCC) 1.0.3 PreRelease 1 and earlier allows remote attackers to inject arbitrary web script or HTML via the userid parameter in a show action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 27 May 2008 |
| CVE-2008-2444 | SQL injection vulnerability in userreg.php in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary SQL commands via the langsel parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 27 May 2008 |
| CVE-2008-2443 | SQL injection vulnerability in dpage.php in The Real Estate Script allows remote attackers to execute arbitrary SQL commands via the docID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 27 May 2008 |
| CVE-2008-2425 | SQL injection vulnerability in index.php in FicHive 1.0 allows remote attackers to execute arbitrary SQL commands via the letter parameter in a Search action, a different vector than CVE-2008-2416. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 23 May 2008 |
| CVE-2008-2422 | SQL injection vulnerability in index.php in Web Slider 0.6 allows remote attackers to execute arbitrary SQL commands via the slide parameter in a slides action. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 23 May 2008 |
| CVE-2008-2421 | Cross-site scripting (XSS) vulnerability in the Web GUI in SAP Web Application Server (WAS) 7.0, Web Dynpro for ABAP (aka WD4A or WDA), and Web Dynpro for BSP allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the… | EXPLOIT ✓MEDIUM 4.3EPSS 1.83% | 23 May 2008 |
| CVE-2008-2419 | Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code by triggering an error condition during certain Iframe operations between a JSframe write and a… | EXPLOIT ✓MEDIUM 4.3EPSS 6.63% | 23 May 2008 |
| CVE-2008-2333 | Cross-site scripting (XSS) vulnerability in ldap_test.cgi in Barracuda Spam Firewall (BSF) before 3.5.11.025 allows remote attackers to inject arbitrary web script or HTML via the email parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 4.53% | 23 May 2008 |
| CVE-2008-1767 | Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XSL style sheet file with a long XSLT "transformation match" condition that triggers… | EXPLOIT ✓HIGH 7.5EPSS 12.8% | 23 May 2008 |
| CVE-2008-2417 | SQL injection vulnerability in showQAnswer.asp in How2ASP.net Webboard 4.1 allows remote attackers to execute arbitrary SQL commands via the qNo parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 22 May 2008 |
| CVE-2008-2416 | SQL injection vulnerability in index.php in FicHive 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter in a Fiction action, possibly related to sources/fiction.class.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 22 May 2008 |
| CVE-2008-2415 | Directory traversal vulnerability in template/purpletech/base_include.php in DigitalHive (aka hive) 2.0 RC2 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.90% | 22 May 2008 |
| CVE-2008-2414 | Cross-site scripting (XSS) vulnerability in send_email.php in AN Guestbook (ANG) 0.4 allows remote attackers to inject arbitrary web script or HTML via the postid parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 22 May 2008 |
| CVE-2008-2413 | Cross-site scripting (XSS) vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 22 May 2008 |
| CVE-2008-2412 | SQL injection vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 22 May 2008 |
| CVE-2008-2411 | SQL injection vulnerability in index.php in SazCart 1.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the prodid parameter in a details action. | EXPLOIT ✓MEDIUM 6.8EPSS 1.12% | 22 May 2008 |
| CVE-2008-2240 | Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long Accept-Language HTTP… | EXPLOIT ✓HIGH 10.0EPSS 64.8% | 22 May 2008 |
| CVE-2008-2006 | Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a .ics file containing (1) a large 16-bit… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 9.65% | 22 May 2008 |
| CVE-2007-5962 | Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of service (memory consumption) via a… | EXPLOIT ×3 ✓HIGH 7.1EPSS 12.1% | 22 May 2008 |
| CVE-2008-2398 | Cross-site scripting (XSS) vulnerability in index.php in AppServ Open Project 2.5.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the appservlang parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 6.23% | 21 May 2008 |
| CVE-2008-2396 | PHP remote file inclusion vulnerability in index.php in Wajox Software microSSys CMS 1.5 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in an arbitrary element of the PAGES array parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.45% | 21 May 2008 |
| CVE-2008-2395 | SQL injection vulnerability in thread.php in AlkalinePHP 0.80.00 beta and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 21 May 2008 |
| CVE-2008-2394 | Multiple SQL injection vulnerabilities in TAGWORX.CMS 3.00.02 allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to contact.php and the (2) nid parameter to news.php. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 21 May 2008 |
| CVE-2008-2393 | SQL injection vulnerability in play.php in EntertainmentScript 1.4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 21 May 2008 |
| CVE-2008-2390 | Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows remote attackers to execute arbitrary code via an absolute pathname in the first argument. | EXPLOIT ✓MEDIUM 6.8EPSS 6.86% | 21 May 2008 |
| CVE-2008-2356 | SQL injection vulnerability in index.php in Archangel Weblog 0.90.02 and earlier allows remote attackers to execute arbitrary SQL commands via the post_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 20 May 2008 |
| CVE-2008-2355 | Directory traversal vulnerability in index.php in WR-Meeting 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.92% | 20 May 2008 |
| CVE-2008-2353 | Directory traversal vulnerability in admin.php in GNU/Gallery 1.1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.37% | 20 May 2008 |
| CVE-2008-2352 | Directory traversal vulnerability in index.php in Smeego 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 2.38% | 20 May 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.