SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,493 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 293 of 501

CVESummaryPriorityPublished
CVE-2008-2110Unrestricted file upload vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request.EXPLOIT ✓HIGH 7.5EPSS 2.43%7 May 2008
CVE-2008-2106Call of Duty 4 (CoD4) 1.5 and earlier allows remote authenticated users to cause a denial of service (crash) via a type 7 stats packet, which triggers a memcpy with a negative value.EXPLOIT ✓MEDIUM 6.8EPSS 7.66%7 May 2008
CVE-2008-2096SQL injection vulnerability in BackLinkSpider allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to a site-specific component name such as link.php or backlinkspider.php.EXPLOIT ✓MEDIUM 6.8EPSS 1.08%7 May 2008
CVE-2008-2095SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.10%6 May 2008
CVE-2008-2094SQL injection vulnerability in article.php in the Article module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.98%6 May 2008
CVE-2008-2093SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a userProfile action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%6 May 2008
CVE-2008-2092Linksys SPA-2102 Phone Adapter 3.3.6 allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death").EXPLOIT ✓HIGH 7.8EPSS 3.94%6 May 2008
CVE-2008-2091Directory traversal vulnerability in ipn.php in KubeLabs Kubelance 1.6.4 allows remote attackers to include and execute arbitrary local files via the i parameter.EXPLOIT ✓HIGH 7.5EPSS 2.29%6 May 2008
CVE-2008-2088SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in the news module to admin.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%6 May 2008
CVE-2008-2087SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different vector than CVE-2005-3817.EXPLOIT ✓MEDIUM 6.8EPSS 1.38%6 May 2008
CVE-2008-2005The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to cause a denial of service (NULL pointer dereference and service shutdown) and possibly execute arbitrary…EXPLOIT ✓MEDIUM 5.0EPSS 16.3%6 May 2008
CVE-2008-2084SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to execute arbitrary SQL commands via the topic_id parameter in a listarticles action.EXPLOIT ✓HIGH 7.5EPSS 1.99%5 May 2008
CVE-2008-2083SQL injection vulnerability in directory.php in Prozilla Hosting Index, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.EXPLOIT ✓MEDIUM 6.8EPSS 1.12%5 May 2008
CVE-2008-2082Cross-site scripting (XSS) vulnerability in index.php in Siteman 2.0.x2 allows remote attackers to inject arbitrary web script or HTML via the module parameter, which leaks the path in an error message.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.47%5 May 2008
CVE-2008-2081Directory traversal vulnerability in index.php in Siteman 2.0.x2 allows remote authenticated administrators to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 9.0EPSS 3.04%5 May 2008
CVE-2008-2076Directory traversal vulnerability in admin.php in ActualScripts ActualAnalyzer Lite 2.78 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 6.29%5 May 2008
CVE-2008-2074Multiple PHP remote file inclusion vulnerabilities Harris Yusuf Arifin Harris Wap Chat 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the sysFileDir parameter to (1) eng.writeMsg.php, (2)…EXPLOIT ✓HIGH 7.5EPSS 2.31%5 May 2008
CVE-2008-2073Directory traversal vulnerability in include/global.inc.php in Virtual Design Studio vlbook 1.21 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.84%5 May 2008
CVE-2008-2072Cross-site scripting (XSS) vulnerability in index.php in Virtual Design Studio vlbook 1.21 allows remote attackers to inject arbitrary web script or HTML via the l parameter, a different vector than CVE-2006-3260.EXPLOIT ✓MEDIUM 4.3EPSS 1.72%5 May 2008
CVE-2008-2069Buffer overflow in Novell GroupWise 7 allows remote attackers to cause a denial of service or execute arbitrary code via a long argument in a mailto: URI.EXPLOIT ✓HIGH 9.3EPSS 33.4%2 May 2008
CVE-2008-2065SQL injection vulnerability in jokes.php in YourFreeWorld Jokes Site Script allows remote attackers to execute arbitrary SQL commands via the catagorie parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%2 May 2008
CVE-2008-2063SQL injection vulnerability in browse.videos.php in Joovili 3.1 allows remote attackers to execute arbitrary SQL commands via the category parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%2 May 2008
CVE-2008-2048Cross-site scripting (XSS) vulnerability in hpz/admin/Default.asp in Angelo-Emlak 1.0 allows remote attackers to inject arbitrary web script or HTML via the sayfa parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.57%1 May 2008
CVE-2008-2047Multiple SQL injection vulnerabilities in Angelo-Emlak 1.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) hpz/profil.asp and (2) hpz/prodetail.asp.EXPLOIT ✓HIGH 7.5EPSS 1.00%1 May 2008
CVE-2008-2046Cross-site scripting (XSS) vulnerability in index.php in Softpedia SiteXS CMS 0.1.1 Pre-Alpha allows remote attackers to inject arbitrary web script or HTML via the user parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%1 May 2008
CVE-2008-2045Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full path in the URL parameter to modules/Feeds/Feed.php, which places the contents into a related cache file…EXPLOIT ✓MEDIUM 5.0EPSS 5.21%1 May 2008
CVE-2008-2044includes/library.php in netOffice Dwins 1.3 p2 compares the demoSession variable to the 'true' string literal instead of the true boolean literal, which allows remote attackers to bypass authentication and execute arbitrary code by setting this variable…EXPLOIT ✓HIGH 7.5EPSS 11.4%1 May 2008
CVE-2008-2040Stack-based buffer overflow in the HTTP::getAuthUserPass function (core/common/http.cpp) in Peercast 0.1218 and gnome-peercast allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Basic Authentication…EXPLOIT ✓HIGH 7.5EPSS 14.9%30 April 2008
CVE-2008-2037Multiple cross-site scripting (XSS) vulnerabilities in EditeurScripts EsContacts 1.0 allow remote authenticated users to inject arbitrary web script or HTML via the msg parameter to (1) login.php, (2) importer.php, (3) add_groupe.php, (4) contacts.php,…EXPLOIT ×6 ✓LOW 3.5EPSS 1.45%30 April 2008
CVE-2008-2036SQL injection vulnerability in index.php in dream4 Koobi Pro 6.25 allows remote attackers to execute arbitrary SQL commands via the poll_id parameter in a poll action.EXPLOIT ✓HIGH 7.5EPSS 1.19%30 April 2008
CVE-2008-2032The FTP service in Acritum Femitter Server 1.03 allows remote attackers to cause a denial of service (crash) by sending multiple crafted RETR commands.EXPLOIT ×2 ✓MEDIUM 5.0EPSS 2.96%30 April 2008
CVE-2008-2031VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a crafted LIST command, which triggers a NULL pointer dereference.EXPLOIT ✓MEDIUM 5.0EPSS 46.3%30 April 2008
CVE-2008-2030Cross-site scripting (XSS) vulnerability in installControl.php3 in F5 FirePass 4100 SSL VPN 5.4.2-5.5.2 and 6.0-6.2 allows remote attackers to inject arbitrary web script or HTML via the query string.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%30 April 2008
CVE-2008-2029Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary SQL commands via the xtr parameter in a userinfo…EXPLOIT ✓MEDIUM 6.8EPSS 1.00%30 April 2008
CVE-2008-2028miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via a direct request to the glang parameter in a registernew action to index.php, which leaks the path in an error message.EXPLOIT ✓MEDIUM 4.3EPSS 2.23%30 April 2008
CVE-2008-2024Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the glang[] parameter in a registernew action.EXPLOIT ✓MEDIUM 4.3EPSS 1.55%30 April 2008
CVE-2008-2023Multiple SQL injection vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) invisible and (2) timeoffset parameters to profile/controlpanel.asp and the (3) attachmentid parameter to…EXPLOIT ✓HIGH 7.5EPSS 1.00%30 April 2008
CVE-2008-2022Mulatiple cross-site scripting (XSS) vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) toid parameter to send-private-message.asp and the (2) redirect parameter to admin/impersonate.asp.EXPLOIT ✓MEDIUM 4.3EPSS 3.47%30 April 2008
CVE-2008-2018The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings delimited by '{' and '}' characters, which allows remote authenticated users to obtain sensitive information via a comment containing a…EXPLOIT ✓MEDIUM 4.0EPSS 2.16%30 April 2008
CVE-2008-2015Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) CompactSave and (2) SaveSession method in…EXPLOIT ✓HIGH 9.3EPSS 8.33%30 April 2008
CVE-2008-2013SQL injection vulnerability in index.php in the pnFlashGames 1.5 through 2.5 module for PostNuke, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a display action.EXPLOIT ✓MEDIUM 6.8EPSS 1.04%30 April 2008
CVE-2008-2012SQL injection vulnerability in index.php in the PostSchedule 1.0 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the eid parameter in an event action.EXPLOIT ✓HIGH 7.5EPSS 1.10%30 April 2008
CVE-2008-1996licq before 1.3.6 allows remote attackers to cause a denial of service (file-descriptor exhaustion and application crash) via a large number of connections.EXPLOIT ✓MEDIUM 5.0EPSS 11.2%28 April 2008
CVE-2008-1993Acidcat CMS 3.4.1 does not restrict access to the FCKEditor component, which allows remote attackers to upload arbitrary files.EXPLOIT ✓HIGH 7.5EPSS 2.83%27 April 2008
CVE-2008-1992Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3) default_mail_jmail.asp, which allows remote attackers to bypass restrictions and relay email messages with modified From, FromName,…EXPLOIT ✓HIGH 7.5EPSS 2.97%27 April 2008
CVE-2008-1991Cross-site scripting (XSS) vulnerability in admin_colors_swatch.asp in Acidcat CMS 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the field parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.78%27 April 2008
CVE-2008-1990Multiple SQL injection vulnerabilities in Acidcat CMS 3.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) cID parameter to default.asp and the (2) username parameter to main_login2.asp.EXPLOIT ✓HIGH 7.5EPSS 1.19%27 April 2008
CVE-2008-1989PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the e107path parameter.EXPLOIT ✓HIGH 10.0EPSS 3.57%27 April 2008
CVE-2008-1986Cross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attackers to inject arbitrary web script or HTML via the jours parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%27 April 2008
CVE-2008-1985Cross-site scripting (XSS) vulnerability in base.php in DigitalHive 2.0 RC2 allows remote attackers to inject arbitrary web script or HTML via the mt parameter, possibly related to membres.php.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.46%27 April 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.