SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,520 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 298 of 501

CVESummaryPriorityPublished
CVE-2008-1499Cross-site scripting (XSS) vulnerability in frontend/x/manpage.html in cPanel 11.18.3 and 11.21.0-BETA allows remote attackers to inject arbitrary web script or HTML via the query string.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%25 March 2008
CVE-2008-1498Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitrary code via a long first argument to the LIST command.EXPLOIT ✓HIGH 9.0EPSS 7.56%25 March 2008
CVE-2008-1496Multiple SQL injection vulnerabilities in PEEL, possibly 3.x and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to (a) membre.php, and the (2) timestamp parameter to (b) the details action in…EXPLOIT ✓HIGH 7.5EPSS 1.15%25 March 2008
CVE-2008-1495Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote authenticated administrators to upload and execute arbitrary PHP files via a modified content type in an ajout action, as demonstrated by…EXPLOIT ✓MEDIUM 6.5EPSS 2.00%25 March 2008
CVE-2008-1493Directory traversal vulnerability in login.php in Cuteflow Bin 1.5.0 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.46%25 March 2008
CVE-2008-1492Multiple directory traversal vulnerabilities in CoronaMatrix phpAddressBook 2.11 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 3.16%25 March 2008
CVE-2008-1491Stack-based buffer overflow in the DPC Proxy server (DpcProxy.exe) in ASUS Remote Console (aka ARC or ASMB3) 2.0.0.19 and 2.0.0.24 allows remote attackers to execute arbitrary code via a long string to TCP port 623.EXPLOIT ×2 ✓HIGH 10.0EPSS 70.1%25 March 2008
CVE-2008-1489Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MP4 RDRF box that triggers a heap-based buffer overflow, a…EXPLOIT ✓MEDIUM 6.8EPSS 11.8%25 March 2008
CVE-2008-1160ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.EXPLOIT ✓CRITICAL 9.8EPSS 14.8%25 March 2008
CVE-2008-1488Stack-based buffer overflow in apc.c in Alternative PHP Cache (APC) 3.0.11 through 3.0.16 allows remote attackers to execute arbitrary code via a long filename.EXPLOIT ✓MEDIUM 6.8EPSS 7.81%24 March 2008
CVE-2008-1484The password reset feature in PunBB 1.2.16 and earlier uses predictable random numbers based on the system time, which allows remote authenticated users to determine the new password via a brute force attack on a seed that is based on the approximate…EXPLOIT ✓LOW 3.5EPSS 4.52%24 March 2008
CVE-2008-1482Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary code via (1) a crafted .FLV file, which triggers an overflow in demuxers/demux_flv.c; (2) a crafted…EXPLOIT ✓MEDIUM 6.8EPSS 9.54%24 March 2008
CVE-2008-1481Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.1.2 allows remote attackers to inject arbitrary web script or HTML via the board parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%24 March 2008
CVE-2008-1480rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC request.EXPLOIT ✓MEDIUM 4.3EPSS 6.21%24 March 2008
CVE-2008-1479Cross-site scripting (XSS) vulnerability in index.php in cyberfrogs.net cfnetgs 0.24 allows remote attackers to inject arbitrary web script or HTML via the directory parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.20%24 March 2008
CVE-2008-1478Home FTP Server 1.4.5.89 allows remote attackers to cause a denial of service (crash) by opening a FTP passive mode connection, then closing the original FTP connection.EXPLOIT ✓MEDIUM 5.0EPSS 2.88%24 March 2008
CVE-2008-1472Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows…EXPLOIT ×2 ✓HIGH 9.3EPSS 39.0%24 March 2008
CVE-2008-1471The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system crash or kernel panic), overwrite memory, or execute arbitrary code via a crafted IOCTL request that triggers an…EXPLOIT ✓HIGH 7.2EPSS 1.13%24 March 2008
CVE-2008-1470Incomplete blacklist vulnerability in IISWebAgentIF.dll in the WebID RSA Authentication Agent 5.3, and possibly earlier, allows remote attackers to conduct cross-site scripting (XSS) attacks via the postdata parameter, due to an incomplete fix for…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.52%24 March 2008
CVE-2008-0125Cross-site scripting (XSS) vulnerability in phpstats.php in Michael Wagner phpstats 0.1 alpha allows remote attackers to inject arbitrary web script or HTML via the baseDir parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.47%24 March 2008
CVE-2008-0073Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter.EXPLOIT ✓MEDIUM 6.8EPSS 9.25%24 March 2008
CVE-2008-1467CenterIM 4.22.3 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URI, related to "received URLs in the message window." NOTE: this issue has been disputed due to the user-assisted nature,…EXPLOIT ✓MEDIUM 6.8EPSS 4.28%24 March 2008
CVE-2008-1466Multiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_default parameter to (1) add_user.php, (2) create_forum.php, (3) create_user.php, (4) delete_notes.php, (5)…EXPLOIT ×9 ✓HIGH 7.5EPSS 2.23%24 March 2008
CVE-2008-1465SQL injection vulnerability in the Detodas Restaurante (com_restaurante) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php, a different product than…EXPLOIT ✓HIGH 9.3EPSS 1.41%24 March 2008
CVE-2008-1463Cross-site scripting (XSS) vulnerability in the management GUI in Imperva SecureSphere MX Management Server 5.0 allows remote attackers to inject arbitrary web script or HTML via an invalid or prohibited request to a web server protected by…EXPLOIT ✓MEDIUM 4.3EPSS 1.58%24 March 2008
CVE-2008-1462SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL commands via the artid parameter in a viewarticle action.EXPLOIT ✓MEDIUM 6.8EPSS 0.91%24 March 2008
CVE-2008-1461Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the command line.EXPLOIT ✓HIGH 7.6EPSS 11.3%24 March 2008
CVE-2008-1460SQL injection vulnerability in the Joovideo (com_joovideo) 1.0 and 1.2.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.EXPLOIT ✓HIGH 7.5EPSS 2.00%24 March 2008
CVE-2008-1459SQL injection vulnerability in the Alberghi (com_alberghi) 2.1.3 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%24 March 2008
CVE-2008-1458Cross-site scripting (XSS) vulnerability in index.php in CS-Cart 1.3.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a products search action.EXPLOIT ✓MEDIUM 4.3EPSS 1.51%24 March 2008
CVE-2008-1289Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6.1, AsteriskNOW 1.0.x before 1.0.2, Appliance Developer Kit before 1.4 revision 109386, and…EXPLOIT ✓HIGH 7.5EPSS 11.5%24 March 2008
CVE-2008-1430SQL injection vulnerability in links.asp in ASPapp allows remote attackers to execute arbitrary SQL commands via the CatId parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.93%20 March 2008
CVE-2008-1427SQL injection vulnerability in the Joobi Acajoom (com_acajoom) 1.1.5 and 1.2.5 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mailingid parameter in a mailing view action to index.php.EXPLOIT ✓HIGH 7.5EPSS 2.08%20 March 2008
CVE-2008-1426SQL injection vulnerability in album.asp in KAPhotoservice allows remote attackers to execute arbitrary SQL commands via the albumid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%20 March 2008
CVE-2008-1425SQL injection vulnerability in index.php in the gallery module in Easy-Clanpage 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a kate action.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97%20 March 2008
CVE-2008-1416Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) converter.inc.php, (2) messages.inc.php, and (3) settings.inc.php in includes/.EXPLOIT ✓MEDIUM 6.8EPSS 37.7%20 March 2008
CVE-2008-1415Directory traversal vulnerability in index.php in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to read arbitrary files via "../..//" (modified dot dot) sequences in the tab parameter.EXPLOIT ✓MEDIUM 5.0EPSS 2.76%20 March 2008
CVE-2008-1414Cross-site scripting (XSS) vulnerability in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the tab parameter to (1) index.php, as demonstrated using mixed case and encoded whitespace…EXPLOIT ✓MEDIUM 4.3EPSS 1.78%20 March 2008
CVE-2008-1413Cross-site scripting (XSS) vulnerability in search.php in SNewsCMS Rus 2.1 through 2.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.46%20 March 2008
CVE-2008-1411The PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to cause a denial of service (crash) via an incomplete TFTP request, which triggers a NULL pointer dereference.EXPLOIT ✓MEDIUM 5.0EPSS 7.58%20 March 2008
CVE-2008-1410Directory traversal vulnerability in the PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to read arbitrary files via directory traversal sequences to the TFTP service.EXPLOIT ✓MEDIUM 4.3EPSS 5.57%20 March 2008
CVE-2008-1409Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the theme parameter to (1) index.php, (2) editpassword.php, and…EXPLOIT ✓HIGH 7.5EPSS 2.42%20 March 2008
CVE-2008-1408SQL injection vulnerability in includes/functions/banners-external.php in phpBP 2 RC3 (2.204) FIX 4 allows remote attackers to execute arbitrary SQL commands via the id parameter in a banner_out action.EXPLOIT ✓HIGH 7.5EPSS 1.23%20 March 2008
CVE-2008-1407SQL injection vulnerability in index.php in the WebChat 1.60 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the roomid parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.91%20 March 2008
CVE-2008-1406SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the lid parameter in an ImprAnn action.EXPLOIT ✓MEDIUM 6.8EPSS 0.91%20 March 2008
CVE-2008-1405PHP remote file inclusion vulnerability in code/display.php in fuzzylime (cms) 3.01 allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter.EXPLOIT ✓MEDIUM 6.8EPSS 37.7%20 March 2008
CVE-2008-1404SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the kid parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.91%20 March 2008
CVE-2008-1403Stack-based buffer overflow in the TFTP server in BootManage TFTPD 1.99 and earlier in BootManage Administrator 7.1 and earlier allows remote attackers to execute arbitrary code via a request with a long filename.EXPLOIT ✓MEDIUM 6.8EPSS 3.59%20 March 2008
CVE-2008-1402MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to cause a (1) denial of service (exception and crash) via a UDP packet to the SNMP Trap Service (MgWTrap3.exe) or (2) denial of service (device freeze or memory…EXPLOIT ✓HIGH 7.1EPSS 2.58%20 March 2008
CVE-2008-1401Format string vulnerability in the Net Inspector HTTP server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to execute arbitrary code via format string specifiers in the URI, which is recorded in a log file.EXPLOIT ✓MEDIUM 4.3EPSS 3.17%20 March 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.