SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,520 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 296 of 501

CVESummaryPriorityPublished
CVE-2008-1776PHP remote file inclusion vulnerability in modules/basicfog/basicfogfactory.class.php in PhpBlock A8.4 allows remote attackers to execute arbitrary PHP code via a URL in the PATH_TO_CODE parameter.EXPLOIT ✓MEDIUM 6.8EPSS 26.6%14 April 2008
CVE-2008-1774SQL injection vulnerability in editlink.php in Pligg 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%14 April 2008
CVE-2008-1773PHP remote file inclusion vulnerability in includes/header.inc.php in Dragoon 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.EXPLOIT ✓MEDIUM 6.8EPSS 26.6%14 April 2008
CVE-2008-1772iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sensitive information.EXPLOIT ✓MEDIUM 5.0EPSS 2.48%14 April 2008
CVE-2008-0927dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with (1) multiple Connection headers or (2) a Connection header with multiple comma-separated values.EXPLOIT ✓MEDIUM 5.0EPSS 70.0%14 April 2008
CVE-2008-1763SQL injection vulnerability in _blogadata/include/sond_result.php in Blogator-script 0.95 allows remote attackers to execute arbitrary SQL commands via the id_art parameter.EXPLOIT ✓HIGH 7.5EPSS 1.20%12 April 2008
CVE-2008-1762Opera before 9.27 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted scaled image pattern in an HTML CANVAS element, which triggers memory corruption.EXPLOIT ✓HIGH 9.3EPSS 7.60%12 April 2008
CVE-2008-1760Multiple PHP remote file inclusion vulnerabilities in Blogator-script before 1.01 allow remote attackers to execute arbitrary PHP code via a URL in the incl_page parameter in (1) struct_admin.php, (2) struct_admin_blog.php, and (3) struct_main.php in…EXPLOIT ✓MEDIUM 6.8EPSS 2.27%12 April 2008
CVE-2008-1759SQL injection vulnerability in the jeuxflash module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php, a different vector than CVE-2007-4922.EXPLOIT ✓HIGH 7.5EPSS 1.00%12 April 2008
CVE-2008-1758SQL injection vulnerability in the ConcoursPhoto module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the C_ID parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%12 April 2008
CVE-2008-1757Cross-site scripting (XSS) vulnerability in index.php in the ConcoursPhoto module for KwsPHP 1.0 allows remote attackers to inject arbitrary web script or HTML via the VIEW parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.46%12 April 2008
CVE-2008-1755Directory traversal vulnerability in the showSource function in showSource.php in World of Phaos 4.0.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file parameter.EXPLOIT ✓MEDIUM 5.0EPSS 2.67%11 April 2008
CVE-2008-1751Multiple directory traversal vulnerabilities in index.php in Ksemail allow remote attackers to read arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 4.08%11 April 2008
CVE-2008-1750SQL injection vulnerability in Integry Systems LiveCart 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to the /category URI.EXPLOIT ✓HIGH 7.5EPSS 1.19%11 April 2008
CVE-2008-1733SQL injection vulnerability in puarcade.class.php 2.2 and earlier in the Pragmatic Utopia PU Arcade (com_puarcade) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the gid parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.00%11 April 2008
CVE-2008-1732SQL injection vulnerability in showpredictionsformatch.php in Prediction Football 1.x allows remote attackers to execute arbitrary SQL commands via the matchid parameter in a dupa action.EXPLOIT ✓HIGH 7.5EPSS 0.97%11 April 2008
CVE-2008-1730Directory traversal vulnerability in download.html in ARWScripts Gallery Script Lite (aka gallery-script-lite or Free Photo Gallery Site Script), as of 20080411, allows remote attackers to read arbitrary local files via directory traversal sequences in…EXPLOIT ✓MEDIUM 5.0EPSS 2.92%11 April 2008
CVE-2008-1727KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin accounts.EXPLOIT ✓HIGH 7.5EPSS 6.85%11 April 2008
CVE-2008-1726Multiple SQL injection vulnerabilities in KnowledgeQuest 2.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kqid parameter to (a) articletext.php and (b) articletextonly.php and the (2) username…EXPLOIT ✓MEDIUM 6.8EPSS 1.58%11 April 2008
CVE-2008-1725The IBizEBank.FIProfile.1 ActiveX control in fiprofile20.ocx in IBiz E-Banking Integrator (formerly IBiz OFX Integrator) 2.0.2932 exposes the unsafe WriteOFXDataFile method, which allows remote attackers to overwrite arbitrary files via a full pathname…EXPLOIT ✓HIGH 9.0EPSS 2.90%11 April 2008
CVE-2008-1724Stack-based buffer overflow in the IActiveXTransfer.FileTransfer method in the SecureTransport FileTransfer ActiveX control in vcst_en.dll 1.0.0.5 in Tumbleweed SecureTransport Server before 4.6.1 Hotfix 20 allows remote attackers to execute arbitrary…EXPLOIT ×2 ✓HIGH 9.3EPSS 35.1%11 April 2008
CVE-2008-1721Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.EXPLOIT ✓HIGH 7.5EPSS 22.6%10 April 2008
CVE-2008-1715SQL injection vulnerability in content/user.php in AuraCMS 2.2.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.91%9 April 2008
CVE-2008-1714SQL injection vulnerability in show.php in FaScript FaPhoto 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.91%9 April 2008
CVE-2008-1713MailServer.exe in NoticeWare Email Server 4.6.1.0 allows remote attackers to cause a denial of service (application crash) via a long string to IMAP port (143/tcp).EXPLOIT ✓MEDIUM 5.0EPSS 2.62%9 April 2008
CVE-2008-1712PHP remote file inclusion vulnerability in includes/functions_weblog.php in mxBB mx_blogs 2.0.0 beta allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.27%9 April 2008
CVE-2007-6019Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.EXPLOIT ✓HIGH 9.3EPSS 59.8%9 April 2008
CVE-2008-1711Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.EXPLOIT ✓MEDIUM 5.0EPSS 2.43%9 April 2008
CVE-2008-1709Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with a long malformed Project line beginning with a 'Project("{}") =' sequence, probably a different vector…EXPLOIT ×2 ✓HIGH 9.3EPSS 13.0%9 April 2008
CVE-2008-1087Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF image file with crafted filename parameters, aka "GDI Stack Overflow…EXPLOIT ×2 ✓HIGH 9.3EPSS 56.6%8 April 2008
CVE-2008-1084Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP1, and Server 2008 allows local users to execute arbitrary code via unknown vectors related to improper input validation.EXPLOIT ×2 ✓HIGH 7.2EPSS 6.75%8 April 2008
CVE-2008-1083Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a…EXPLOIT ×3 ✓HIGH 8.1EPSS 57.1%8 April 2008
CVE-2008-1702Absolute path traversal vulnerability in dload.php in the my_gallery 2.3 plugin for e107 allows remote attackers to obtain sensitive information via a full pathname in the file parameter.EXPLOIT ✓MEDIUM 4.3EPSS 5.72%8 April 2008
CVE-2008-1697Stack-based buffer overflow in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51, and earlier allows remote attackers to execute arbitrary code via a long URI in an HTTP request processed by ovas.exe, as demonstrated by a certain…EXPLOIT ×2 ✓HIGH 10.0EPSS 74.3%8 April 2008
CVE-2008-1696Directory traversal vulnerability in makepost.php in DaZPHPNews 0.1-1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓LOW 3.7EPSS 2.26%8 April 2008
CVE-2007-4620Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0, as used in multiple CA products including Anti-Virus for the Enterprise 7.1 through r11.1 and Threat Manager…EXPLOIT ✓HIGH 9.0EPSS 52.3%7 April 2008
CVE-2008-1690WebContainer.exe 1.0.0.336 and earlier in SLMail Pro 6.3.1.0 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a long URI in HTTP requests to TCP port 801.EXPLOIT ✓HIGH 10.0EPSS 5.72%7 April 2008
CVE-2008-0310Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append to arbitrary files via ".." sequences in an unspecified environment variable, probably PKGINST.EXPLOIT ✓MEDIUM 6.9EPSS 1.01%7 April 2008
CVE-2008-1602Stack-based buffer overflow in Orbit downloader 2.6.3 and 2.6.4 allows remote attackers to execute arbitrary code via a long download URL, which is not properly handled during Unicode conversion for a balloon notification after a download has failed.EXPLOIT ✓HIGH 10.0EPSS 67.5%6 April 2008
CVE-2008-0311Stack-based buffer overflow in the PGMWebHandler::parse_request function in the StarTeam Multicast Service component (STMulticastService) 6.4 in Borland CaliberRM 2006 allows remote attackers to execute arbitrary code via a large HTTP request.EXPLOIT ✓HIGH 9.3EPSS 31.0%6 April 2008
CVE-2008-1682PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1.0.2 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter.EXPLOIT ✓MEDIUM 6.8EPSS 26.6%4 April 2008
CVE-2008-1680PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain configuration information via a direct request to maintenance/index.php, which reveals settings such as magic_quotes_gpc.EXPLOIT ✓MEDIUM 5.0EPSS 2.23%4 April 2008
CVE-2008-1331cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other versions, allows remote attackers to execute arbitrary commands and "obtain OXO resources" via shell metacharacters…EXPLOIT ✓HIGH 10.0EPSS 8.78%2 April 2008
CVE-2008-1651Directory traversal vulnerability in admin/login.php in EasyNews 4.0 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 3.12%2 April 2008
CVE-2008-1650SQL injection vulnerability in dynamicpages/index.php in EasyNews 4.0 allows remote attackers to execute arbitrary SQL commands via the read parameter in an edp_Help_Internal_News action.EXPLOIT ✓HIGH 7.5EPSS 1.31%2 April 2008
CVE-2008-1649Cross-site scripting (XSS) vulnerability in staticpages/easypublish/index.php in EasyNews 4.0 allows remote attackers to inject arbitrary web script or HTML via the read parameter in an edp_pupublish action.EXPLOIT ✓MEDIUM 4.3EPSS 1.90%2 April 2008
CVE-2008-1647The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0, and earlier in ChilkatHttp ActiveX expose the unsafe SaveLastError method, which allows remote attackers to overwrite arbitrary files.EXPLOIT ×2 ✓HIGH 9.3EPSS 7.01%2 April 2008
CVE-2008-1646SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the dl_id parameter.EXPLOIT ✓HIGH 7.5EPSS 2.74%2 April 2008
CVE-2008-1645Directory traversal vulnerability in body.php in phpSpamManager (phpSM) 0.53 beta allows remote attackers to read arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.29%2 April 2008
CVE-2008-1641SQL injection vulnerability in default.asp in EfesTECH Video 5.0 allows remote attackers to execute arbitrary SQL commands via the catID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%2 April 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.