SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,493 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 294 of 501

CVESummaryPriorityPublished
CVE-2008-1983Cross-site scripting (XSS) vulnerability in Advanced Electron Forum (AEF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the beg parameter in a members action to index.php.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%27 April 2008
CVE-2008-1982SQL injection vulnerability in ss_load.php in the Spreadsheet (wpSS) 0.6 and earlier plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the ss_id parameter.EXPLOIT ✓HIGH 7.5EPSS 3.16%27 April 2008
CVE-2008-1979The Discovery Service (casdscvc) in CA ARCserve Backup 12.0.5454.0 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large integer value used in an increment to TCP port 41523, which triggers a buffer over-read.EXPLOIT ✓MEDIUM 5.0EPSS 3.63%27 April 2008
CVE-2008-1975SQL injection vulnerability in index.php in E-RESERV 2.1 allows remote attackers to execute arbitrary SQL commands via the ID_loc parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%27 April 2008
CVE-2008-1974Cross-site scripting (XSS) vulnerability in addevent.php in Horde Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and Groupware 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the url parameter.EXPLOIT ✓MEDIUM 4.3EPSS 4.88%27 April 2008
CVE-2008-1973Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long subtitle file.EXPLOIT ✓HIGH 9.3EPSS 5.76%27 April 2008
CVE-2008-1971phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and earlier, the ssbadmin cookie to shoutadmin.php.EXPLOIT ✓HIGH 7.5EPSS 2.21%27 April 2008
CVE-2008-1969Multiple cross-site scripting (XSS) vulnerabilities in Cezanne 6.5.1 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) LookUPId and (2) CbFun parameters to (a) CFLookUP.asp; (3) TitleParms, (4) WidgetsHeights, (5)…EXPLOIT ×3 ✓LOW 3.5EPSS 1.31%27 April 2008
CVE-2008-1968Multiple SQL injection vulnerabilities in Cezanne 7 allow remote authenticated users to execute arbitrary SQL commands via the FUNID parameter to (1) CFLookup.asp and (2) CznCommon/CznCustomContainer.asp.EXPLOIT ×2 ✓MEDIUM 6.0EPSS 0.83%27 April 2008
CVE-2008-1967Cross-site scripting (XSS) vulnerability in CFLogon/CFLogon.asp in Cezanne 6.5.1 and 7 allows remote attackers to inject arbitrary web script or HTML via the SleUserName parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.51%27 April 2008
CVE-2008-1965Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus Symphony and possibly other products, allows remote attackers to execute arbitrary code by injecting a…EXPLOIT ✓HIGH 9.3EPSS 10.7%25 April 2008
CVE-2008-1963PHP remote file inclusion vulnerability in includes/functions.php in Quate Grape Web Statistics 0.2a allows remote attackers to execute arbitrary PHP code via a URL in the location parameter.EXPLOIT ✓HIGH 7.5EPSS 39.0%25 April 2008
CVE-2008-1962Multiple directory traversal vulnerabilities in Aterr 0.9.1 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.85%25 April 2008
CVE-2008-1961SQL injection vulnerability in index.php in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to execute arbitrary SQL commands via the AMG_id parameter in a comments action.EXPLOIT ✓HIGH 7.5EPSS 0.97%25 April 2008
CVE-2008-1958Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with a .php extension.EXPLOIT ✓MEDIUM 6.5EPSS 3.30%25 April 2008
CVE-2008-1957SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands via the nb parameter in voir mode.EXPLOIT ✓HIGH 7.5EPSS 1.19%25 April 2008
CVE-2008-1956Cross-site scripting (XSS) vulnerability in index.php in Wikepage Opus 13 2007.2 allows remote attackers to inject arbitrary web script or HTML via the wiki parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%25 April 2008
CVE-2008-1955Cross-site scripting (XSS) vulnerability in rep.php in Martin BOUCHER MyBoard 1.0.12 allows remote attackers to inject arbitrary web script or HTML via the id parameter. information.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%25 April 2008
CVE-2008-1954SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.19%25 April 2008
CVE-2008-1939Multiple SQL injection vulnerabilities in W1L3D4 Philboard 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) topic parameters to (a) philboard_reply.asp, and the (3) forumid parameter to (b) philboard_newtopic.asp,…EXPLOIT ✓HIGH 7.5EPSS 0.97%25 April 2008
CVE-2008-1936SQL injection vulnerability in index.php in Classifieds Caffe allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in an add action.EXPLOIT ✓HIGH 7.5EPSS 1.00%25 April 2008
CVE-2008-1935SQL injection vulnerability in the Filiale 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the idFiliale parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%25 April 2008
CVE-2008-1934SQL injection vulnerability in commentaires.php in Crazy Goomba 1.2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%25 April 2008
CVE-2008-1933Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to overwrite arbitrary files via the SaveToFile method.EXPLOIT ✓MEDIUM 4.3EPSS 13.9%25 April 2008
CVE-2008-1769VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via a crafted Cinepak file that triggers an out-of-bounds array access and memory corruption.EXPLOIT ✓MEDIUM 6.8EPSS 7.16%25 April 2008
CVE-2008-1921SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote attackers to execute arbitrary SQL commands via the category_ID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.19%23 April 2008
CVE-2008-1920Heap-based buffer overflow in the boxelyRenderer module in the Personal Status Manager feature in ICQ 6.0 build 6043 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted personal status message.EXPLOIT ✓HIGH 7.5EPSS 5.80%23 April 2008
CVE-2008-1919SQL injection vulnerability in listtest.php in YourFreeWorld Apartment Search Script allows remote attackers to execute arbitrary SQL commands via the r parameter.EXPLOIT ✓HIGH 7.5EPSS 2.00%23 April 2008
CVE-2008-1918SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the database table prefix is known, allows remote authenticated users to execute arbitrary SQL commands via the submit_info[] parameter…EXPLOIT ×2 ✓MEDIUM 6.0EPSS 1.49%23 April 2008
CVE-2008-1917Multiple cross-site scripting (XSS) vulnerabilities in AMFPHP 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) class parameter to (a) methodTable.php, (b) code.php, and (c) details.php in browser/; and the (2) location…EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.21%23 April 2008
CVE-2008-1915SQL injection vulnerability in view.asp in DevWorx BlogWorx 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%23 April 2008
CVE-2008-1765Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remote attackers and physically proximate attackers to execute arbitrary code via a BMP file with an invalid image header.EXPLOIT ✓HIGH 9.3EPSS 20.0%23 April 2008
CVE-2008-1385Cross-site scripting (XSS) vulnerability in the Top Referrers (aka referrer) plugin in Serendipity (S9Y) before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.EXPLOIT ✓MEDIUM 4.3EPSS 4.50%23 April 2008
CVE-2008-1914Stack-based buffer overflow in the AntServer module (AntServer.exe) in BigAnt IM Server in BigAnt Messenger 2.2 allows remote attackers to execute arbitrary code via a long URI in a request to TCP port 6080.EXPLOIT ×5 ✓HIGH 10.0EPSS 73.7%22 April 2008
CVE-2008-1913SQL injection vulnerability in index.php in Lasernet CMS 1.5 and 1.11, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the new parameter in a new action.EXPLOIT ✓HIGH 7.5EPSS 1.04%22 April 2008
CVE-2008-1912Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long subtitle in a .SRT file.EXPLOIT ×2 ✓HIGH 9.3EPSS 11.7%22 April 2008
CVE-2008-1911SQL injection vulnerability in includes/system.php in 1024 CMS 1.4.2 beta and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a cookpass cookie.EXPLOIT ✓MEDIUM 6.8EPSS 0.95%22 April 2008
CVE-2008-1910Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 SP2 allows remote attackers to execute arbitrary code via a malformed opcode 0x52 request to TCP port 3050.EXPLOIT ✓HIGH 10.0EPSS 7.29%22 April 2008
CVE-2008-1909SQL injection vulnerability in comment.php in PHP Knowledge Base (PHPKB) 1.5 and 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.98%22 April 2008
CVE-2008-1908Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.83%22 April 2008
CVE-2008-1907Multiple SQL injection vulnerabilities in functions/display_page.func.php in cpCommerce 1.1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_product, (2) id_manufacturer, and (3) id_category parameters to unspecified components.EXPLOIT ✓HIGH 7.5EPSS 1.00%22 April 2008
CVE-2008-1906Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the year parameter in a view.year action.EXPLOIT ✓MEDIUM 4.3EPSS 1.71%22 April 2008
CVE-2008-1904Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session, which allows remote attackers to obtain access to the "admin area" via a modified this_cookie cookie.EXPLOIT ✓HIGH 7.5EPSS 2.19%22 April 2008
CVE-2008-1903PHP remote file inclusion vulnerability in news_show.php in Newanz NewsOffice 1.0 and 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsoffice_directory parameter.EXPLOIT ✓HIGH 7.5EPSS 39.2%22 April 2008
CVE-2008-1613SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and 7.0, allows remote attackers to execute arbitrary SQL commands via the LngId parameter.EXPLOIT ✓HIGH 7.5EPSS 7.53%22 April 2008
CVE-2008-1898A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid…EXPLOIT ×3 ✓HIGH 9.3EPSS 52.0%21 April 2008
CVE-2008-1436Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service…EXPLOIT ✓HIGH 9.0EPSS 36.8%21 April 2008
CVE-2008-1896Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Redirect parameter to login.asp and the (2) OrderBy parameter to member_send.asp.EXPLOIT ✓MEDIUM 4.3EPSS 1.72%18 April 2008
CVE-2008-1895Multiple SQL injection vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to events.asp, the (2) UserName parameter to getpassword.asp, and possibly an unspecified…EXPLOIT ✓HIGH 7.5EPSS 1.19%18 April 2008
CVE-2008-1893PHP remote file inclusion vulnerability in index.php in W2B Online Banking allows remote attackers to execute arbitrary PHP code via a URL in the ilang parameter.EXPLOIT ✓HIGH 7.5EPSS 2.25%18 April 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.