Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,539 CVEs1,726 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 301 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-6704 | Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass 4100 SSL VPN 5.4.1 through 5.5.2 and 6.0 through 6.0.1, when pre-logon sequences are enabled, allow remote attackers to inject arbitrary web script or HTML via the query string to (1)… | EXPLOIT ×2 ✓LOW 2.6EPSS 5.92% | 5 March 2008 |
| CVE-2008-1145 | Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that support backslash (\) path separators or case-insensitive file names, allows remote attackers to access… | EXPLOIT ✓MEDIUM 5.0EPSS 27.8% | 4 March 2008 |
| CVE-2008-1141 | Memory leak in DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (kernel memory consumption) via a series of DLMFENC_IOCTL requests to \\.\DLKPFSD_Device that allocate "link list structures." | EXPLOIT ×2 ✓MEDIUM 4.9EPSS 0.91% | 4 March 2008 |
| CVE-2008-1140 | DLMFDISK.sys 1.2.0.27 in DESlock+ 3.2.6 and earlier allows local users to gain privileges via a certain DLKFDISK_IOCTL request to \\.\DLKFDisk_Control that overwrites a data structure associated with a mounted pseudo-filesystem, aka the "ring0 SYSTEM"… | EXPLOIT ✓HIGH 7.2EPSS 0.83% | 4 March 2008 |
| CVE-2008-1139 | DESlock+ 3.2.6 and earlier, when DLMFENC.sys 1.0.0.26 and DLMFDISK.sys 1.2.0.27 are present, allows local users to gain privileges via a certain DLMFENC_IOCTL request to \\.\DLKPFSD_Device that overwrites a pointer, aka the "ring0 link list zero SYSTEM"… | EXPLOIT ✓HIGH 7.2EPSS 0.88% | 4 March 2008 |
| CVE-2008-1138 | DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (system crash) via a certain ZERO_MEM DLMFENC_IOCTL request to \\.\DLKPFSD_Device, aka the "ring0 link list zero" vulnerability. | EXPLOIT ✓MEDIUM 4.9EPSS 0.87% | 4 March 2008 |
| CVE-2008-1137 | SQL injection vulnerability in the Garys Cookbook (com_garyscookbook) 1.1.1 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 4 March 2008 |
| CVE-2008-1136 | The Utils::runScripts function in src/utils.cpp in vdccm 0.92 through 0.10.0 in SynCE (SynCE-dccm) allows remote attackers to execute arbitrary commands via shell metacharacters in a certain string to TCP port 5679. | EXPLOIT ✓HIGH 9.3EPSS 6.78% | 4 March 2008 |
| CVE-2008-1134 | OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 supports authentication with a cookie that lacks a shared secret, which allows remote attackers to login as an arbitrary user via a modified cookie. | EXPLOIT ✓MEDIUM 6.4EPSS 2.19% | 4 March 2008 |
| CVE-2007-6702 | goform/QuickStart_c0 on the GoAhead Web Server on the FS4104-AW (aka rooter) VDSL device contains a password in the typepassword field, which allows remote attackers to obtain this password by reading the HTML source, a different vulnerability than… | EXPLOIT ✓MEDIUM 5.0EPSS 2.60% | 4 March 2008 |
| CVE-2008-1129 | Cross-site scripting (XSS) vulnerability in admin/users/self.php in XRMS CRM allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.46% | 4 March 2008 |
| CVE-2008-1128 | PHP remote file inclusion vulnerability in tourney/index.php in phpMyTourney 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.98% | 3 March 2008 |
| CVE-2008-1127 | Format string vulnerability in the cryactio function in Crysis 1.1.1.5879 allows remote authenticated users to execute arbitrary code via format string specifiers in the user name, which is triggered when the game character is killed. | EXPLOIT ✓MEDIUM 6.0EPSS 2.99% | 3 March 2008 |
| CVE-2008-1126 | PHP remote file inclusion vulnerability in main.php in Barryvan Compo Manager 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the pageURL parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 23.6% | 3 March 2008 |
| CVE-2008-1125 | Multiple directory traversal vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.08% | 3 March 2008 |
| CVE-2008-1124 | Multiple PHP remote file inclusion vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absoluteurl parameter to (1) components/xmlparser/loadparser.php; (2) admin.php, (3)… | EXPLOIT ✓MEDIUM 6.8EPSS 21.5% | 3 March 2008 |
| CVE-2008-1123 | Multiple PHP remote file inclusion vulnerabilities in SiteBuilder Elite 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the CarpPath parameter to (1) files/carprss.php and (2) files/amazon-bestsellers.php. | EXPLOIT ✓MEDIUM 6.8EPSS 1.84% | 3 March 2008 |
| CVE-2008-1122 | SQL injection vulnerability in the downloads module in Koobi Pro 5.7 allows remote attackers to execute arbitrary SQL commands via the categ parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 3 March 2008 |
| CVE-2008-1121 | SQL injection vulnerability in index.php in eazyPortal 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the session_vars cookie. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 3 March 2008 |
| CVE-2008-1119 | Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 8.10% | 3 March 2008 |
| CVE-2008-1116 | Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner allows remote attackers to force the download and execution of arbitrary code by setting the BaseURL property and invoking the… | EXPLOIT ✓HIGH 9.3EPSS 10.2% | 3 March 2008 |
| CVE-2008-1110 | Buffer overflow in demuxers/demux_asf.c (aka the ASF demuxer) in the xineplug_dmx_asf.so plugin in xine-lib before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted ASF header. | EXPLOIT ✓MEDIUM 6.8EPSS 10.4% | 29 February 2008 |
| CVE-2007-6016 | Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Server in Symantec Backup Exec for Windows Server (BEWS) 11d 11.0.6235 and 11.0.7170, and 12.0 12.0.1364,… | EXPLOIT ×2 ✓HIGH 9.3EPSS 50.4% | 29 February 2008 |
| CVE-2008-1077 | SQL injection vulnerability in index.php in the Simpleboard (com_simpleboard) 1.0.3 Stable component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a view action. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 29 February 2008 |
| CVE-2008-1074 | PHP remote file inclusion vulnerability in lib/head_auth.php in GROUP-E 1.6.41 allows remote attackers to execute arbitrary PHP code via a URL in the CFG[PREPEND_FILE] parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 36.9% | 29 February 2008 |
| CVE-2008-1069 | Multiple PHP remote file inclusion vulnerabilities in Quantum Game Library 0.7.2c allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[gameroot] parameter to (1) server_request.php and (2) qlib/smarty.inc.php. | EXPLOIT ✓MEDIUM 6.8EPSS 28.9% | 28 February 2008 |
| CVE-2008-1068 | Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the site_path parameter to (1) Vert/index.php, (2) Noir/index.php, and (3) Bleu/index.php in… | EXPLOIT ✓MEDIUM 6.8EPSS 1.84% | 28 February 2008 |
| CVE-2008-1067 | Multiple PHP remote file inclusion vulnerabilities in phpQLAdmin 2.2.7 allow remote attackers to execute arbitrary PHP code via a URL in the _SESSION[path] parameter to (1) ezmlm.php and (2) tools/update_translations.php. | EXPLOIT ✓MEDIUM 6.8EPSS 21.7% | 28 February 2008 |
| CVE-2008-0411 | Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator. | EXPLOIT ✓MEDIUM 6.8EPSS 14.5% | 28 February 2008 |
| CVE-2008-1061 | Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to (a) warning.php, (b) notice.php, and (c) inset.php in… | EXPLOIT ✓MEDIUM 4.3EPSS 7.40% | 28 February 2008 |
| CVE-2008-1060 | Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via the text parameter. | EXPLOIT ✓HIGH 7.5EPSS 44.2% | 28 February 2008 |
| CVE-2008-1059 | PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the libpath parameter. | EXPLOIT ✓HIGH 7.5EPSS 48.3% | 28 February 2008 |
| CVE-2008-1055 | Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string… | EXPLOIT ✓HIGH 7.5EPSS 7.95% | 27 February 2008 |
| CVE-2008-1054 | Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlier, and beta 39a, allows remote attackers to cause a denial of service (daemon crash) and possibly execute… | EXPLOIT ✓MEDIUM 6.4EPSS 7.36% | 27 February 2008 |
| CVE-2008-1053 | Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the artid parameter in a (1) viewarticle or (2) printpage action to modules.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 27 February 2008 |
| CVE-2008-1052 | The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL pointer dereference when memory… | EXPLOIT ✓MEDIUM 6.4EPSS 6.80% | 27 February 2008 |
| CVE-2008-1051 | PHP remote file inclusion vulnerability in include/body_comm.inc.php in phpProfiles 4.5.2 BETA allows remote attackers to execute arbitrary PHP code via a URL in the content parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 21.4% | 27 February 2008 |
| CVE-2008-1050 | SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 27 February 2008 |
| CVE-2008-1046 | PHP remote file inclusion vulnerability in footer.php in Quinsonnas Mail Checker 1.55 allows remote attackers to execute arbitrary PHP code via a URL in the op[footer_body] parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 21.4% | 27 February 2008 |
| CVE-2008-1045 | Cross-site scripting (XSS) vulnerability in the file tree navigation function in system/workplace/views/explorer/tree_files.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the resource parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 27 February 2008 |
| CVE-2008-1044 | Stack-based buffer overflow in the Quantum Streaming Player (Quantum Streaming IE Player) ActiveX control (aka QSP2IE.QSP2IE) in qsp2ie07076007.dll 7.7.6.7 and qsp2ie07074039.dll 7.7.4.39 in Move Media Player allows remote attackers to execute arbitrary… | EXPLOIT ✓HIGH 7.5EPSS 4.84% | 27 February 2008 |
| CVE-2008-1043 | PHP remote file inclusion vulnerability in templates/default/header.inc.php in Linux Web Shop (LWS) php User Base 1.3 BETA allows remote attackers to execute arbitrary PHP code via a URL in the menu parameter. | EXPLOIT ✓HIGH 7.5EPSS 48.6% | 27 February 2008 |
| CVE-2008-1042 | Directory traversal vulnerability in include/body.inc.php in Linux Web Shop (LWS) php Download Manager 1.0 and 1.1 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 4.23% | 27 February 2008 |
| CVE-2008-1039 | SQL injection vulnerability in question.asp in PORAR WEBBOARD allows remote attackers to execute arbitrary SQL commands via the QID parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 27 February 2008 |
| CVE-2008-1038 | PHP remote file inclusion vulnerability in mod/mod.extmanager.php in DBHcms 1.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the extmanager_install parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.98% | 27 February 2008 |
| CVE-2008-1037 | Cross-site scripting (XSS) vulnerability in the file listing function in the web management interface in Packeteer PacketShaper and PolicyCenter 8.2.2 allows remote attackers to inject arbitrary web script or HTML via the FILELIST parameter to an… | EXPLOIT ✓MEDIUM 4.3EPSS 1.48% | 27 February 2008 |
| CVE-2008-0984 | The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file. | EXPLOIT ✓HIGH 9.3EPSS 15.3% | 26 February 2008 |
| CVE-2008-0982 | Spyce - Python Server Pages (PSP) 2.1.3 allows remote attackers to obtain sensitive information via a direct request for spyce/examples/automaton.spy, which reveals the path in an error message. | EXPLOIT ✓MEDIUM 5.8EPSS 1.76% | 25 February 2008 |
| CVE-2008-0980 | Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to inject arbitrary web script or HTML via (1) the url or type parameter to docs/examples/redirect.spy; (2) the x parameter to… | EXPLOIT ×5 ✓MEDIUM 4.3EPSS 1.48% | 25 February 2008 |
| CVE-2008-0944 | Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote attackers to cause a denial of service (NULL dereference and application crash) via a version field containing zero. | EXPLOIT ✓MEDIUM 5.0EPSS 11.5% | 25 February 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.