Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,520 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 299 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-1400 | Directory traversal vulnerability in the Net Inspector HTTP Server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) or "../" (dot dot slash) in the URI. | EXPLOIT ✓MEDIUM 5.0EPSS 2.92% | 20 March 2008 |
| CVE-2008-1398 | SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header. | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 20 March 2008 |
| CVE-2007-4592 | Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, and 7.0.1.1_iFix01 allow remote attackers to inject arbitrary web script or HTML via the (1) contextid,… | EXPLOIT ✓MEDIUM 4.3EPSS 4.50% | 20 March 2008 |
| CVE-2008-1000 | Directory traversal vulnerability in ContentServer.py in the Wiki Server in Apple Mac OS X 10.5.2 (aka Leopard) allows remote authenticated users to write arbitrary files via ".." sequences in file attachments. | EXPLOIT ✓HIGH 8.5EPSS 3.13% | 18 March 2008 |
| CVE-2008-1371 | Absolute path traversal vulnerability in install/index.php in Drake CMS 0.4.11 RC8 allows remote attackers to read and execute arbitrary files via a full pathname in the d_root parameter. | EXPLOIT ✓LOW 3.6EPSS 1.70% | 18 March 2008 |
| CVE-2008-1370 | PHP remote file inclusion vulnerability in index.php in wildmary Yap Blog 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.80% | 18 March 2008 |
| CVE-2008-1365 | Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long… | EXPLOIT ×2 ✓MEDIUM 6.4EPSS 51.1% | 17 March 2008 |
| CVE-2008-1358 | Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary code via a FETCH command with a long BODY. | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 57.1% | 17 March 2008 |
| CVE-2008-1357 | Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used in ePolicy Orchestrator 4.0.0 build 1015, allows remote attackers to cause a denial of service (crash)… | EXPLOIT ✓MEDIUM 5.4EPSS 6.20% | 17 March 2008 |
| CVE-2008-1355 | Cross-site scripting (XSS) vulnerability in index.php in Jeebles Technology Jeebles Directory 2.9.60 allows remote attackers to inject arbitrary web script or HTML via the path parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 17 March 2008 |
| CVE-2008-1354 | SQL injection vulnerability in MyIssuesView.asp in Advanced Data Solutions Virtual Support Office-XP (VSO-XP) allows remote attackers to execute arbitrary SQL commands via the Issue_ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 17 March 2008 |
| CVE-2008-1353 | zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum commands with a special device node such as /dev/urandom or /dev/zero. | EXPLOIT ✓MEDIUM 4.3EPSS 5.69% | 17 March 2008 |
| CVE-2008-1351 | SQL injection vulnerability in the Tutorials 2.1b module for XOOPS allows remote attackers to execute arbitrary SQL commands via the tid parameter to printpage.php, which is accessible directly or through a printpage action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 17 March 2008 |
| CVE-2008-1350 | SQL injection vulnerability in kb.php in Fully Modded phpBB (phpbbfm) 80220 allows remote attackers to execute arbitrary SQL commands via the k parameter in an article action. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 17 March 2008 |
| CVE-2008-1349 | SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.23% | 17 March 2008 |
| CVE-2008-1348 | Cross-site scripting (XSS) vulnerability in index.php in the eWebsite eWeather (Weather) module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the chart parameter to modules.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 17 March 2008 |
| CVE-2008-1347 | Multiple cross-site scripting (XSS) vulnerabilities in staticpages/easygallery/index.php in MyioSoft EasyGallery 5.0tr and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) the q parameter in an about… | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 17 March 2008 |
| CVE-2008-1346 | SQL injection vulnerability in staticpages/easygallery/index.php in MyioSoft EasyGallery 5.0tr and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 17 March 2008 |
| CVE-2008-1345 | Cross-site scripting (XSS) vulnerability in plugins/calendar/calendar_backend.php in MyioSoft EasyCalendar 4.0tr and earlier allows remote attackers to inject arbitrary web script or HTML via the day parameter in a dayview action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 17 March 2008 |
| CVE-2008-1344 | Multiple SQL injection vulnerabilities in MyioSoft EasyCalendar 4.0tr and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in a dayview action to plugins/calendar/calendar_backend.php and the (2) page parameter… | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 17 March 2008 |
| CVE-2008-1343 | Directory traversal vulnerability in (1) pkgadd and (2) pkgrm in SCO UnixWare 7.1.4 allows local users to gain privileges via unknown vectors. | EXPLOIT ✓MEDIUM 4.9EPSS 0.76% | 17 March 2008 |
| CVE-2008-1118 | Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted log entries, and possibly avoid… | EXPLOIT ✓HIGH 7.5EPSS 2.94% | 14 March 2008 |
| CVE-2008-1117 | Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, allows remote attackers to upload files to arbitrary locations via a destination… | EXPLOIT ×3 ✓HIGH 10.0EPSS 69.5% | 14 March 2008 |
| CVE-2008-0533 | Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary… | EXPLOIT ✓MEDIUM 4.3EPSS 28.8% | 14 March 2008 |
| CVE-2008-0532 | Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to execute arbitrary code via a long argument… | EXPLOIT ✓HIGH 10.0EPSS 57.1% | 14 March 2008 |
| CVE-2008-1336 | SQL injection vulnerability in Koobi CMS 4.2.3 through 4.3.0 allows remote attackers to execute arbitrary SQL commands via the categ parameter in a links action to index.php, a different vector than CVE-2008-1122. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 13 March 2008 |
| CVE-2008-1327 | Gallarific does not require authentication for (1) users.php and (2) index.php, which allows remote attackers to add and edit tasks via a direct request. | EXPLOIT ✓HIGH 7.5EPSS 3.07% | 13 March 2008 |
| CVE-2008-1326 | Cross-site scripting (XSS) vulnerability in search.php in Gallarific allows remote attackers to inject arbitrary web script or HTML via the query parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 13 March 2008 |
| CVE-2008-1325 | Multiple directory traversal vulnerabilities in index.php in Uberghey CMS 0.3.1 allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.39% | 13 March 2008 |
| CVE-2008-1324 | Multiple directory traversal vulnerabilities in index.php in Travelsized CMS 0.4.1 allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.30% | 13 March 2008 |
| CVE-2008-1322 | The File Check Utility (fcheck.exe) in ASG-Sentry Network Manager 7.0.0 and earlier allows remote attackers to cause a denial of service (CPU consumption) or overwrite arbitrary files via a query string that specifies the -b option, probably due to an… | EXPLOIT ✓HIGH 7.8EPSS 9.99% | 13 March 2008 |
| CVE-2008-1321 | The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote attackers to cause a denial of service (service termination) via the exit command to TCP port 6162, or have other impacts via other… | EXPLOIT ✓MEDIUM 5.0EPSS 8.38% | 13 March 2008 |
| CVE-2008-1320 | Multiple buffer overflows in ASG-Sentry Network Manager 7.0.0 and earlier allow remote attackers to execute arbitrary code or cause a denial of service (crash) via (1) a long request to FxIAList on TCP port 6162, or (2) an SNMP request with a long… | EXPLOIT ✓HIGH 10.0EPSS 16.3% | 13 March 2008 |
| CVE-2008-1319 | Untrusted search path and argument injection vulnerability in the VersantD service in Versant Object Database 7.0.1.3 and earlier, as used in Borland CaliberRM and probably other products, allows remote attackers to execute arbitrary commands via a… | EXPLOIT ✓HIGH 9.3EPSS 4.80% | 13 March 2008 |
| CVE-2008-1316 | SQL injection vulnerability in qtf_ind_search_ov.php in QT-cute QuickTalk Forum 1.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 13 March 2008 |
| CVE-2008-1315 | SQL injection vulnerability in the ZClassifieds module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat parameter to modules.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 13 March 2008 |
| CVE-2008-1314 | SQL injection vulnerability in the Johannes Hass gaestebuch 2.2 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action to modules.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 12 March 2008 |
| CVE-2008-1313 | Multiple SQL injection vulnerabilities in index.php in Bloo 1.00 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) post_id, (2) post_category_id, (3) post_year_month, and (4) static_page_id parameters; and unspecified… | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 12 March 2008 |
| CVE-2008-1311 | The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.0 and earlier allows remote attackers to cause a denial of service (daemon hang) by uploading a file named (1) '|' (pipe), (2) '"' (quotation mark), or (3) "<>" (less than, greater than); or… | EXPLOIT ✓MEDIUM 5.0EPSS 49.2% | 12 March 2008 |
| CVE-2008-1309 | The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5 before build 6.0.12.1675, and RealPlayer 11 before 11.0.3 build 6.0.14.806 does not properly manage memory for the (1)… | EXPLOIT ×2 ✓HIGH 9.3EPSS 46.0% | 12 March 2008 |
| CVE-2008-1308 | SQL injection vulnerability in the Sudirman Angriawan NukeC30 3.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id_catg parameter in a ViewCatg action to modules.php. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 12 March 2008 |
| CVE-2008-1307 | Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 2007.12.29.29 allows remote attackers to execute arbitrary code via a long argument to the SetUninstallName method. | EXPLOIT ✓HIGH 10.0EPSS 15.0% | 12 March 2008 |
| CVE-2008-1305 | SQL injection vulnerability in filebase.php in the Filebase mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 12 March 2008 |
| CVE-2008-1304 | Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) inviteemail parameter in an invite action to wp-admin/users.php and the (2) to parameter in a sent action to… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 5.00% | 12 March 2008 |
| CVE-2008-1303 | The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon crash) via a missing parameter to the (1) dm-FaultFile, (2) dm-LazyCheck, (3) dm-ResolvedFile, (4) dm-OpenFile, (5)… | EXPLOIT ✓MEDIUM 5.0EPSS 7.58% | 12 March 2008 |
| CVE-2008-1301 | Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote authenticated administrators to read arbitrary files via a full pathname in the filePath.0… | EXPLOIT ✓MEDIUM 4.0EPSS 2.25% | 12 March 2008 |
| CVE-2008-1300 | Cross-site scripting (XSS) vulnerability in the Logfile Viewer Settings function in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote attackers to inject arbitrary web script or HTML… | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 12 March 2008 |
| CVE-2008-1298 | SQL injection vulnerability in Hadith module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat parameter in a viewcat action to modules.php. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 12 March 2008 |
| CVE-2008-1297 | SQL injection vulnerability in index.php in the eWriting (com_ewriting) 1.2.1 module for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 12 March 2008 |
| CVE-2008-1296 | Multiple cross-site scripting (XSS) vulnerabilities in EncapsGallery 1.11.2 allow remote attackers to inject arbitrary web script or HTML via the file parameter to (1) watermark.php and (2) catalog_watermark.php in core/. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.47% | 12 March 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.