Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,493 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 292 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-2215 | Multiple directory traversal vulnerabilities in Project-Based Calendaring System (PBCS) 0.7.1-1 allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.69% | 14 May 2008 |
| CVE-2008-2214 | Stack-based buffer overflow in the Network Manager in Castle Rock Computing SNMPc 7.1 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long community string in an SNMP TRAP packet. | EXPLOIT ✓HIGH 10.0EPSS 8.84% | 14 May 2008 |
| CVE-2008-2202 | Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to upload/admin/index.php in a search action, the (2) msg_charset and (3) msg_header9… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.54% | 14 May 2008 |
| CVE-2008-2199 | PHP remote file inclusion vulnerability in kmitaadmin/kmitam/htmlcode.php in Kmita Mail 3.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.44% | 14 May 2008 |
| CVE-2008-2198 | PHP remote file inclusion vulnerability in kmitaadmin/kmitat/htmlcode.php in Kmita Tellfriend 2.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.35% | 14 May 2008 |
| CVE-2008-2197 | SQL injection vulnerability in the blogwriter module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter to index.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.98% | 14 May 2008 |
| CVE-2008-2196 | Cross-site scripting (XSS) vulnerability in admin.php in LifeType 1.2.8 allows remote attackers to inject arbitrary web script or HTML via the newBlogUserName parameter in an addBlogUser action, a different vector than CVE-2008-2178. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 14 May 2008 |
| CVE-2008-2195 | Static code injection vulnerability in admincp.php in DeluxeBB 1.2 and earlier allows remote authenticated administrators to inject arbitrary PHP code into logs/cp.php via the URI. | EXPLOIT ✓MEDIUM 6.5EPSS 2.06% | 14 May 2008 |
| CVE-2008-2194 | SQL injection vulnerability in forums.php in DeluxeBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 14 May 2008 |
| CVE-2008-2193 | PHP remote file inclusion vulnerability in example.php in Thomas Gossmann ScorpNews 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the site parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 14 May 2008 |
| CVE-2008-2192 | Static code injection vulnerability in box/minichat/boxpop.php in IT!CMS (aka itcms) 1.9 allows remote attackers to inject arbitrary PHP code into box/MiniChat/data/shouts.php via the shout parameter. | EXPLOIT ✓HIGH 10.0EPSS 3.74% | 14 May 2008 |
| CVE-2008-2191 | SQL injection vulnerability in the pnEncyclopedia module 0.2.0 and earlier for PostNuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a display_term action to index.php. | EXPLOIT ✓MEDIUM 6.8EPSS 1.08% | 14 May 2008 |
| CVE-2008-2190 | SQL injection vulnerability in index.php in Online Rent (aka Online Rental Property Script) 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.17% | 14 May 2008 |
| CVE-2008-2189 | SQL injection vulnerability in viewfaqs.php in AnServ Auction XL allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.33% | 14 May 2008 |
| CVE-2008-2188 | Multiple cross-site scripting (XSS) vulnerabilities in EJ3 BlackBook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) bookCopyright and (2) ver parameters to (a) footer.php, and the (3) bookName, (4) bookMetaTags, and (5)… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.49% | 13 May 2008 |
| CVE-2008-2187 | Cross-site scripting (XSS) vulnerability in mjguest.php in Mjguest 6.7 GT Rev.01 allows remote attackers to inject arbitrary web script or HTML via the level parameter in a redirect action, possibly involving interface/redirect.htm.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.79% | 13 May 2008 |
| CVE-2008-2186 | Cross-site scripting (XSS) vulnerability in index.php in Chilek Content Management System (aka ChiCoMaS) 2.0.4 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 4.01% | 13 May 2008 |
| CVE-2008-2185 | Directory traversal vulnerability in index.php in SMartBlog (aka SMBlog) 1.3 allows remote attackers to include arbitrary local files via directory traversal sequences in the page parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.88% | 13 May 2008 |
| CVE-2008-2184 | Multiple SQL injection vulnerabilities in SMartBlog (aka SMBlog) 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) mois, (2) an, (3) jour, and (4) id parameters to index.php, and the (5) login parameter to gestion/logon.php,… | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 13 May 2008 |
| CVE-2008-2183 | SQL injection vulnerability in index.php in SMartBlog (aka SMBlog) 1.3 allows remote attackers to execute arbitrary SQL commands via the idt parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 13 May 2008 |
| CVE-2008-2181 | Multiple cross-site scripting (XSS) vulnerabilities in search.php in cpLinks 1.03 allow remote attackers to inject arbitrary web script or HTML via the (1) search_text and (2) search_category parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.57% | 13 May 2008 |
| CVE-2008-2180 | Multiple SQL injection vulnerabilities in cpLinks 1.03, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) admin_username parameter (aka the username field) to admin/index.php and the (2) search_text… | EXPLOIT ✓MEDIUM 6.8EPSS 0.98% | 13 May 2008 |
| CVE-2008-2177 | Multiple SQL injection vulnerabilities in phpDirectorySource 1.1.06, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to show.php and the (2) login parameter to admin.php. | EXPLOIT ✓MEDIUM 6.8EPSS 1.12% | 13 May 2008 |
| CVE-2008-2175 | SQL injection vulnerability in comments.php in Gamma Scripts BlogMe PHP 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 13 May 2008 |
| CVE-2008-2168 | Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page. | EXPLOIT ✓MEDIUM 4.3EPSS 54.9% | 13 May 2008 |
| CVE-2008-2167 | Cross-site scripting (XSS) vulnerability in ZyXEL ZyWALL 100 allows remote attackers to inject arbitrary web script or HTML via the Referer header, which is not properly handled in a 404 Error page. | EXPLOIT ✓MEDIUM 4.3EPSS 16.8% | 13 May 2008 |
| CVE-2008-0166 | OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic… | EXPLOIT ×3 ✓HIGH 7.5EPSS 70.7% | 13 May 2008 |
| CVE-2008-2162 | Cross-site scripting (XSS) vulnerability in SonicWall Email Security 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the Host header in a request to a non-existent web page, which is not properly sanitized in an error page. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 12 May 2008 |
| CVE-2008-2161 | Buffer overflow in TFTP Server SP 1.4 and 1.5 on Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a long TFTP error packet. | EXPLOIT ✓HIGH 10.0EPSS 65.3% | 12 May 2008 |
| CVE-2008-2138 | Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/portal/ by sending a request containing a trailing "%0A" (encoded line feed), then using the session ID… | EXPLOIT ✓MEDIUM 5.0EPSS 15.5% | 12 May 2008 |
| CVE-2008-2070 | The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 2.18% | 12 May 2008 |
| CVE-2008-1802 | Buffer overflow in the process_redirect_pdu (rdp.c) function in rdesktop 1.5.0 allows remote attackers to execute arbitrary code via a Remote Desktop Protocol (RDP) redirect request with modified length fields. | EXPLOIT ✓HIGH 9.3EPSS 13.0% | 12 May 2008 |
| CVE-2008-1801 | Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Remote Desktop Protocol (RDP) request with a small length field. | EXPLOIT ✓HIGH 9.3EPSS 13.1% | 12 May 2008 |
| CVE-2008-2135 | Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) contentname parameter to showdetails.php and the (2) article parameter to printer.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 9 May 2008 |
| CVE-2008-2132 | SQL injection vulnerability in step1.asp in Systementor PostcardMentor allows remote attackers to execute arbitrary SQL commands via the cat_fldAuto parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 9 May 2008 |
| CVE-2008-2130 | SQL injection vulnerability in poll_vote.php in iGaming CMS 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 9 May 2008 |
| CVE-2008-2129 | SQL injection vulnerability in index.php in Galleristic 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 9 May 2008 |
| CVE-2008-2128 | PHP remote file inclusion vulnerability in templates/header.php in CMS Faethon 2.2 Ultimate allows remote attackers to execute arbitrary PHP code via a URL in the mainpath parameter, a different vulnerability than CVE-2006-5588 and CVE-2006-3185. | EXPLOIT ✓HIGH 7.5EPSS 2.10% | 9 May 2008 |
| CVE-2008-2127 | Cross-site scripting (XSS) vulnerability in search.php in CMS Faethon 2.2 Ultimate allows remote attackers to inject arbitrary web script or HTML via the what parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 9 May 2008 |
| CVE-2008-2126 | Multiple cross-site scripting (XSS) vulnerabilities in Tux CMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to index.php and the (2) returnURL parameter to tux-login.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 9 May 2008 |
| CVE-2008-2125 | SQL injection vulnerability in viewalbums.php in Musicbox 2.3.6 and 2.3.7 allows remote attackers to execute arbitrary SQL commands via the artistId parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.98% | 9 May 2008 |
| CVE-2008-2124 | SQL injection vulnerability in modules/print.asp in fipsASP fipsCMS allows remote attackers to execute arbitrary SQL commands via the lg parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 9 May 2008 |
| CVE-2008-2123 | Cross-site scripting (XSS) vulnerability in WGate in SAP Internet Transaction Server (ITS) 6.20 allows remote attackers to inject arbitrary web script or HTML via (1) a "<>" sequence in the ~service parameter to wgate.dll, or (2) Javascript splicing in… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 2.25% | 9 May 2008 |
| CVE-2008-2118 | SQL injection vulnerability in info.php in Project Alumni 1.0.9 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 8 May 2008 |
| CVE-2008-2117 | Cross-site scripting (XSS) vulnerability in pages/news.page.inc in Project Alumni 1.0.9 allows remote attackers to inject arbitrary web script or HTML via the year parameter in a news action to index.php, a different vector than CVE-2007-6126. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 8 May 2008 |
| CVE-2008-2116 | Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to read arbitrary local files via a .. | EXPLOIT ✓MEDIUM 4.4EPSS 2.54% | 8 May 2008 |
| CVE-2008-2115 | Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) te and (2) dir parameters in a tempedit action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.49% | 8 May 2008 |
| CVE-2008-2114 | SQL injection vulnerability in emall/search.php in Pre Shopping Mall 1.1 allows remote attackers to execute arbitrary SQL commands via the search parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 8 May 2008 |
| CVE-2008-2113 | SQL injection vulnerability in annuaire.php in PHPEasyData 1.5.4 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 8 May 2008 |
| CVE-2008-2111 | Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in the Ynoifier COM object that trigger memory corruption. | EXPLOIT ✓HIGH 9.3EPSS 5.39% | 7 May 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.