SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,493 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 295 of 501

CVESummaryPriorityPublished
CVE-2008-1889SQL injection vulnerability in viewcat.php in XplodPHP AutoTutorials 2.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%18 April 2008
CVE-2008-1888Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor.EXPLOIT ✓MEDIUM 4.3EPSS 8.02%18 April 2008
CVE-2008-1886The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for a KeyCode that blocks unauthorized use of the control, which allows remote attackers to bypass this protection mechanism by…EXPLOIT ✓HIGH 7.5EPSS 6.66%18 April 2008
CVE-2008-1885Directory traversal vulnerability in the NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download allows remote attackers to download arbitrary code onto a client system via a ..EXPLOIT ✓MEDIUM 6.8EPSS 4.07%18 April 2008
CVE-2008-1881Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a long subtitle in an SSA file.EXPLOIT ×2 ✓MEDIUM 6.8EPSS 11.8%17 April 2008
CVE-2008-1878Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long NSF title.EXPLOIT ✓HIGH 7.5EPSS 15.0%17 April 2008
CVE-2008-1876PHP remote file inclusion vulnerability in index.php in VisualPic 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the _CONFIG[files][functions_page] parameter.EXPLOIT ✓MEDIUM 6.8EPSS 27.6%17 April 2008
CVE-2008-1875SQL injection vulnerability in index.php in Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 allows remote attackers to execute arbitrary SQL commands via the photo_id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%17 April 2008
CVE-2008-1874SQL injection vulnerability in account/user/mail.html in Xpoze Pro 3.05 and earlier allows remote authenticated users to execute arbitrary SQL commands via the reed parameter.EXPLOIT ✓MEDIUM 6.5EPSS 0.86%17 April 2008
CVE-2008-1873Cross-site scripting (XSS) vulnerability in the private message feature in Nuke ET 3.2 and 3.4, when using Internet Explorer, allows remote authenticated users to inject arbitrary web script or HTML via a CSS property in the STYLE attribute of a DIV…EXPLOIT ✓MEDIUM 4.3EPSS 1.50%17 April 2008
CVE-2008-1872SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary SQL commands via the arcmonth parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%17 April 2008
CVE-2008-1871SQL injection vulnerability in links.php in Scriptsagent.com Links Directory 1.1 allows remote authenticated users to execute arbitrary SQL commands via the cat_id parameter in a list action.EXPLOIT ✓MEDIUM 6.5EPSS 0.92%17 April 2008
CVE-2008-1870SQL injection vulnerability in getdata.php in PIGMy-SQL 1.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%17 April 2008
CVE-2008-1869SQL injection vulnerability in Site Sift Listings allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.04%17 April 2008
CVE-2008-1868admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database backup dump, and obtain the resulting blogPM.sql file that contains sensitive information.EXPLOIT ✓HIGH 7.5EPSS 2.61%17 April 2008
CVE-2008-1867SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL commands via the categorie parameter to index.php, possibly related to include/requetesIndex.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%17 April 2008
CVE-2008-1866admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically…EXPLOIT ✓HIGH 9.0EPSS 5.22%17 April 2008
CVE-2008-1864SQL injection vulnerability in project.php in Prozilla Freelancers allows remote attackers to execute arbitrary SQL commands via the project parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%17 April 2008
CVE-2008-1863SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 2.08%17 April 2008
CVE-2008-1862ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which allows remote attackers to bypass this check via (1) POST or (2) COOKIE variables, a different vector than CVE-2006-4488.EXPLOIT ✓MEDIUM 6.8EPSS 3.05%17 April 2008
CVE-2008-1861Directory traversal vulnerability in modules/threadstop/threadstop.php in ExBB Italia 0.22 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 5.1EPSS 1.92%17 April 2008
CVE-2008-1860Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Config.php via the default parameter.EXPLOIT ✓HIGH 9.3EPSS 3.05%17 April 2008
CVE-2008-0320Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an OLE file with a crafted DocumentSummaryInformation stream.EXPLOIT ✓HIGH 9.3EPSS 56.9%17 April 2008
CVE-2008-1859SQL injection vulnerability in events.php in iScripts SocialWare allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.EXPLOIT ✓HIGH 7.5EPSS 1.04%16 April 2008
CVE-2008-1858SQL injection vulnerability in index.php in 724Networks 724CMS 4.01 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97%16 April 2008
CVE-2008-1857Multiple directory traversal vulnerabilities in viewsource.php in Make our Life Easy (Mole) 2.1.0 allow remote attackers to read arbitrary files via directory traversal sequences in the (1) dirn and (2) fname parameters.EXPLOIT ✓MEDIUM 6.8EPSS 1.92%16 April 2008
CVE-2008-1856plugins/maps/db_handler.php in LinPHA 1.3.3 and earlier does not require authentication for a settings action that modifies the configuration file, which allows remote attackers to conduct directory traversal attacks and execute arbitrary local files by…EXPLOIT ✓MEDIUM 5.1EPSS 2.69%16 April 2008
CVE-2008-1855FrameworkService.exe in McAfee Common Management Agent (CMA) 3.6.0.574 Patch 3 and earlier, as used by ePolicy Orchestrator (ePO) and ProtectionPilot (PrP), allows remote attackers to corrupt memory and cause a denial of service (CMA Framework service…EXPLOIT ✓MEDIUM 5.0EPSS 7.58%16 April 2008
CVE-2008-1854Unspecified vulnerability in SmarterMail Web Server (SMWebSvr.exe) in SmarterMail 5.0.2999 allows remote attackers to cause a denial of service (service termination) via a long HTTP (1) GET, (2) HEAD, (3) PUT, (4) POST, or (5) TRACE request.EXPLOIT ✓MEDIUM 5.0EPSS 2.65%16 April 2008
CVE-2008-0068Directory traversal vulnerability in OpenView5.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to read arbitrary files via directory traversal sequences in the Action parameter.EXPLOIT ✓MEDIUM 5.0EPSS 5.09%16 April 2008
CVE-2008-1849Directory traversal vulnerability in index.php in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 and earlier allows remote attackers to list arbitrary directories via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.67%16 April 2008
CVE-2008-1848Cross-site scripting (XSS) vulnerability in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter in a show_error action to index.php.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%16 April 2008
CVE-2008-1847SQL injection vulnerability in view.php in CoronaMatrix phpAddressBook 2.11 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%16 April 2008
CVE-2008-1844SQL injection vulnerability in cat.php in W2B phpHotResources allows remote attackers to execute arbitrary SQL commands via the kind parameter.EXPLOIT ✓HIGH 7.5EPSS 1.15%16 April 2008
CVE-2008-1843SQL injection vulnerability in browse.php in W2B DatingClub (aka Dating Club) allows remote attackers to execute arbitrary SQL commands via the age_to parameter in a browsebyCat action.EXPLOIT ✓HIGH 7.5EPSS 1.15%16 April 2008
CVE-2008-1842Integer signedness error in ovspmd.exe in HP OpenView Network Node Manager (OV NNM) 8.01, and 7.53 and earlier, allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a long request to TCP port 8886 that begins…EXPLOIT ✓HIGH 10.0EPSS 12.2%16 April 2008
CVE-2008-1838SQL injection vulnerability in BosClassifieds Classified Ads System 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%16 April 2008
CVE-2008-1800Multiple cross-site scripting (XSS) vulnerabilities in index.php in DivXDB 2002 0.94b allow remote attackers to inject arbitrary web script or HTML via the (1) choice, (2) _page_, (3) zone_admin, (4) general_search, and (5) import parameters.EXPLOIT ✓MEDIUM 4.3EPSS 1.19%15 April 2008
CVE-2008-1799Directory traversal vulnerability in thumbnails.php in sabros.us 1.75 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.67%15 April 2008
CVE-2008-1798Directory traversal vulnerability in forum/kietu/libs/calendrier.php in Dragoon 0.1 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.29%15 April 2008
CVE-2008-1795Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Academic Suite 7.x and earlier, and possibly some 8.0 versions, allow remote attackers to inject arbitrary web script or HTML via (1) the searchText parameter in a Course action to…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.95%15 April 2008
CVE-2008-1791SQL injection vulnerability in ladder.php in My Gaming Ladder 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the ladderid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%15 April 2008
CVE-2008-1790Unrestricted file upload vulnerability in iScripts SocialWare allows remote authenticated administrators to upload arbitrary files via a crafted logo file in the "Manage Settings" functionality.EXPLOIT ✓MEDIUM 6.5EPSS 1.08%15 April 2008
CVE-2008-1789SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.91%15 April 2008
CVE-2008-1788SQL injection vulnerability in directory.php in Prozilla Entertainers 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.EXPLOIT ✓HIGH 7.5EPSS 0.93%15 April 2008
CVE-2008-1787Multiple cross-site scripting (XSS) vulnerabilities in index.php in Poplar Gedcom Viewer 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) text and (2) ul parameters.EXPLOIT ✓MEDIUM 4.3EPSS 1.47%15 April 2008
CVE-2008-1785delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary users via a modified s parameter.EXPLOIT ✓MEDIUM 5.5EPSS 1.97%15 April 2008
CVE-2008-1784Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2) editu.php, and (3) uidx.php in siteadmin/.EXPLOIT ✓HIGH 7.5EPSS 2.52%15 April 2008
CVE-2008-1783Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/DeleteUser.php.EXPLOIT ✓MEDIUM 6.4EPSS 2.27%15 April 2008
CVE-2008-1782phpdemo/viewsource.php in Advanced Software Engineering ChartDirector 4.1 allows remote attackers to read sensitive files via the file parameter.EXPLOIT ✓MEDIUM 5.0EPSS 2.44%15 April 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.