SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,492 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 291 of 501

CVESummaryPriorityPublished
CVE-2008-2351Multiple SQL injection vulnerabilities in index.php in CMS WebManager-Pro allow remote attackers to execute arbitrary SQL commands via the (1) lang_id and (2) menu_id parameters.EXPLOIT ✓HIGH 7.5EPSS 1.00%20 May 2008
CVE-2008-2350Directory traversal vulnerability in highlight.php in bcoos 1.0.9 through 1.0.13 allows remote attackers to read arbitrary files via (1) ..EXPLOIT ✓MEDIUM 5.0EPSS 2.69%20 May 2008
CVE-2008-2349Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter set to 1.EXPLOIT ✓HIGH 7.5EPSS 2.45%20 May 2008
CVE-2008-2348MeltingIce File System 1.0 allows remote attackers to bypass application authentication, create new user accounts, and exceed application quotas via a direct request to admin/adduser.php.EXPLOIT ✓HIGH 7.5EPSS 2.50%20 May 2008
CVE-2008-2347MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting the userID parameter to "admin" in a direct request to admin/addUser.php.EXPLOIT ✓HIGH 7.5EPSS 2.56%20 May 2008
CVE-2008-2346AlkalinePHP 0.77.35 and earlier allows remote attackers to bypass authentication and gain administrative access by creating an admin account via a direct request to adduser.php.EXPLOIT ✓HIGH 7.5EPSS 2.71%20 May 2008
CVE-2008-2343News Manager 2.0 allows remote attackers to bypass restrictions and obtain sensitive information via a direct request to (1) db/connect_str.php and (2) login/info.php.EXPLOIT ✓HIGH 7.5EPSS 2.37%19 May 2008
CVE-2008-2342Directory traversal vulnerability in attachments.php in News Manager 2.0 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.67%19 May 2008
CVE-2008-2341PHP remote file inclusion vulnerability in ch_readalso.php in News Manager 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the read_xml_include parameter.EXPLOIT ✓HIGH 7.5EPSS 2.29%19 May 2008
CVE-2008-2340Multiple SQL injection vulnerabilities in News Manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) lang parameter to (a) advsearch.php, (b) archive.php, and (c) index.php, and the (2) pid parameter to (d) list_tagitems.php.EXPLOIT ✓HIGH 7.5EPSS 1.00%19 May 2008
CVE-2008-2339SQL injection vulnerability in index.php in Turnkey Web Tools SunShop Shopping Cart 3.5.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an item action, a different vector than CVE-2008-2038, CVE-2007-4597, and…EXPLOIT ✓HIGH 7.5EPSS 1.00%19 May 2008
CVE-2008-2338Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified scripts in /admin.EXPLOIT ✓HIGH 7.5EPSS 6.36%19 May 2008
CVE-2008-2337Multiple SQL injection vulnerabilities in IMGallery 2.5, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kategoria parameter to (a) galeria.php and the (2) id_phot parameter to (b) popup/koment.php…EXPLOIT ✓HIGH 7.5EPSS 1.00%19 May 2008
CVE-2008-2336SQL injection vulnerability in category.php in 68 Classifieds 4.0.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%19 May 2008
CVE-2008-2335Cross-site scripting (XSS) vulnerability in search_results.php in Vastal I-Tech phpVID 1.1 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the query parameter.EXPLOIT ✓MEDIUM 4.3EPSS 4.01%19 May 2008
CVE-2008-2334Multiple SQL injection vulnerabilities in W1L3D4 Philboard 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) forumid parameter to (a) admin/philboard_admin-forumedit.asp, (b) admin/philboard_admin-forum.asp, and (c)…EXPLOIT ×3 ✓HIGH 7.5EPSS 0.98%19 May 2008
CVE-2008-2301SQL injection vulnerability in Kostenloses Linkmanagementscript allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.php and (2) top_view.php.EXPLOIT ✓HIGH 7.5EPSS 1.15%18 May 2008
CVE-2008-2298Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1.EXPLOIT ✓HIGH 7.5EPSS 2.79%18 May 2008
CVE-2008-2297The admin.php file in Rantx allows remote attackers to bypass authentication and gain privileges by setting the logininfo cookie to "<?php" or "?>", which is present in the password file and probably passes an insufficient comparison.EXPLOIT ✓HIGH 7.5EPSS 2.45%18 May 2008
CVE-2008-2296PHP remote file inclusion vulnerability in include/bbs.lib.inc.php in Rgboard 3.0.12 allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.43%18 May 2008
CVE-2008-2295Cross-site scripting (XSS) vulnerability in rg_search.php in Rgboard 3.0.12, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the s_text parameter and other unspecified vectors.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%18 May 2008
CVE-2008-2294Pet Grooming Management System 2.0 allows remote attackers to gain privileges via a direct request to useradded.php with a modified user name for "admin."EXPLOIT ✓HIGH 7.5EPSS 2.69%18 May 2008
CVE-2008-2293admin.php in Multi-Page Comment System (MPCS) 1.0 and 1.1 allows remote attackers to bypass authentication and gain privileges by setting the CommentSystemAdmin cookie to 1.EXPLOIT ✓HIGH 7.5EPSS 2.74%18 May 2008
CVE-2008-2292Buffer overflow in the __snprint_value function in snmp_get in Net-SNMP 5.1.4, 5.2.4, and 5.4.1, as used in SNMP.xs for Perl, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large OCTETSTRING in an…EXPLOIT ✓MEDIUM 6.8EPSS 8.44%18 May 2008
CVE-2008-2286SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows remote attackers to execute arbitrary SQL commands via unspecified string fields in a notification packet.EXPLOIT ✓HIGH 7.5EPSS 32.7%18 May 2008
CVE-2008-2284PHP remote file inclusion vulnerability in fusebox5.php in Fusebox 5.5.1 allows remote attackers to execute arbitrary PHP code via a URL in the FUSEBOX_APPLICATION_PATH parameter.EXPLOIT ✓HIGH 7.5EPSS 2.33%18 May 2008
CVE-2008-2283IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEnhWMF methods in (a) the IDAuto.BarCode.1 ActiveX control in IDAutomationLinear6.dll (aka IDAutomation Linear BarCode) 1.6.0.6, (b)…EXPLOIT ✓HIGH 9.3EPSS 6.00%18 May 2008
CVE-2008-2282admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_admin cookie to true.EXPLOIT ✓HIGH 7.5EPSS 3.04%18 May 2008
CVE-2008-2281Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via an HTML document with a link…EXPLOIT ✓HIGH 9.3EPSS 23.2%18 May 2008
CVE-2008-0167The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other…EXPLOIT ✓MEDIUM 4.6EPSS 0.73%18 May 2008
CVE-2008-2279Freelance Auction Script 1.0 stores user passwords in plaintext in the tbl_users table, which allows attackers to gain privileges by reading the table.EXPLOIT ✓MEDIUM 5.0EPSS 2.27%16 May 2008
CVE-2008-2278SQL injection vulnerability in browseproject.php in Freelance Auction Script 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a pdetails action.EXPLOIT ✓HIGH 7.5EPSS 1.01%16 May 2008
CVE-2008-2277SQL injection vulnerability in detail.php in Feedback and Rating Script 1.0 allows remote attackers to execute arbitrary SQL commands via the listingid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%16 May 2008
CVE-2008-2276Cross-site request forgery (CSRF) vulnerability in manage_user_create.php in Mantis 1.1.1 allows remote attackers to create new administrative users via a crafted link.EXPLOIT ✓MEDIUM 6.8EPSS 3.09%16 May 2008
CVE-2008-2270Multiple PHP remote file inclusion vulnerabilities in PHPWAY Kostenloses Linkmanagementscript allow remote attackers to execute arbitrary PHP code via a URL in the (1) main_page_directory and (2) page_to_include parameters in template\index.php.EXPLOIT ✓HIGH 7.5EPSS 2.29%16 May 2008
CVE-2008-2269AustinSmoke GasTracker (AS-GasTracker) 1.0.0 allows remote attackers to bypass authentication and gain privileges by setting the gastracker_admin cookie to TRUE.EXPLOIT ✓HIGH 7.5EPSS 2.63%16 May 2008
CVE-2008-2267Incomplete blacklist vulnerability in javaUpload.php in Postlet in the FileManager module in CMS Made Simple 1.2.4 and earlier allows remote attackers to execute arbitrary code by uploading a file with a name ending in (1) .jsp, (2) .php3, (3) .cgi, (4)…EXPLOIT ✓HIGH 7.5EPSS 4.81%16 May 2008
CVE-2008-2265SQL injection vulnerability in news.php in EMO Realty Manager allows remote attackers to execute arbitrary SQL commands via the ida parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%16 May 2008
CVE-2008-2264Cross-site scripting (XSS) vulnerability in index.php in CyrixMED 1.4 allows remote attackers to inject arbitrary web script or HTML via the msg_erreur parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.19%16 May 2008
CVE-2008-2263SQL injection vulnerability in linking.page.php in Automated Link Exchange Portal allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%16 May 2008
CVE-2008-2228PHP remote file inclusion vulnerability in portfolio/commentaires/derniers_commentaires.php in Cyberfolio 7.12, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep parameter.EXPLOIT ✓HIGH 9.3EPSS 2.80%14 May 2008
CVE-2008-2227Multiple directory traversal vulnerabilities in PHP-Fusion Forum Rank System 6 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.85%14 May 2008
CVE-2008-2225SQL injection vulnerability in index.php in gameCMS Lite 1.0 allows remote attackers to execute arbitrary SQL commands via the systemId parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%14 May 2008
CVE-2008-2224Multiple PHP remote file inclusion vulnerabilities in SazCart 1.5.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _saz[settings][site_dir] parameter to layouts/default/header.saz.php and the…EXPLOIT ✓MEDIUM 6.8EPSS 1.82%14 May 2008
CVE-2008-2223SQL injection vulnerability in group_posts.php in vShare YouTube Clone 2.6 allows remote attackers to execute arbitrary SQL commands via the tid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.06%14 May 2008
CVE-2008-2222SQL injection vulnerability in login.php in EQdkp 1.3.2f allows remote attackers to bypass EQdkp user authentication via the user_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.06%14 May 2008
CVE-2008-2220Multiple PHP remote file inclusion vulnerabilities in Interact Learning Community Environment Interact 2.4.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[LANGUAGE_CPATH] parameter to…EXPLOIT ✓MEDIUM 6.8EPSS 1.81%14 May 2008
CVE-2008-2219Cross-site scripting (XSS) vulnerability in install.php in C-News.fr C-News 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the etape parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%14 May 2008
CVE-2008-2217Directory traversal vulnerability in cm/graphie.php in Content Management System 0.6.1 for Phprojekt allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.85%14 May 2008
CVE-2008-2216Unrestricted file upload vulnerability in src/yopy_upload.php in Project-Based Calendaring System (PBCS) 0.7.1 allows remote authenticated users to upload arbitrary files to tmp/uploads.EXPLOIT ✓HIGH 9.0EPSS 2.86%14 May 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.