SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,539 CVEs1,728 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 302 of 501

CVESummaryPriorityPublished
CVE-2008-0943Multiple SQL injection vulnerabilities in Eagle Software Aeries Browser Interface (ABI) 3.7.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) FC parameter to Comments.asp, or the Term parameter to (2) Labels.asp or (3)…EXPLOIT ×3 ✓HIGH 7.5EPSS 1.01%25 February 2008
CVE-2008-0942SQL injection vulnerability in GradebookStuScores.asp in Eagle Software Aeries Browser Interface (ABI) 3.8.2.8 allows remote attackers to execute arbitrary SQL commands via the GrdBk parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%25 February 2008
CVE-2008-0939Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the photo parameter to index.php, used by the wppa_photo_name function; or…EXPLOIT ✓HIGH 7.5EPSS 4.25%25 February 2008
CVE-2008-0937SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter in a print action, a different vector than CVE-2007-1811.EXPLOIT ✓MEDIUM 6.8EPSS 0.87%25 February 2008
CVE-2008-0936SQL injection vulnerability in index.php in the Prayer List (prayerlist) 1.04 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.EXPLOIT ✓HIGH 7.5EPSS 0.96%25 February 2008
CVE-2008-0935Stack-based buffer overflow in the Novell iPrint Control ActiveX control in ienipp.ocx in Novell iPrint Client before 4.34 allows remote attackers to execute arbitrary code via a long argument to the ExecuteRequest method.EXPLOIT ✓HIGH 10.0EPSS 65.1%25 February 2008
CVE-2008-0934SQL injection vulnerability in modules.php in the NukeC 2.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id_catg parameter in a ViewCatg action.EXPLOIT ✓HIGH 7.5EPSS 0.93%25 February 2008
CVE-2008-0922SQL injection vulnerability in the Manuales 0.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewdownload action to modules.php.EXPLOIT ✓HIGH 7.5EPSS 0.93%22 February 2008
CVE-2008-0921SQL injection vulnerability in news.php in beContent 0.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%22 February 2008
CVE-2008-0920SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 allows remote authenticated users to execute arbitrary SQL commands via the portname parameter, which is not properly handled by a…EXPLOIT ✓MEDIUM 6.5EPSS 1.01%22 February 2008
CVE-2008-0919Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 and earlier allows remote attackers to inject arbitrary web script or HTML via the dest parameter.EXPLOIT ✓MEDIUM 4.3EPSS 3.75%22 February 2008
CVE-2008-0918SQL injection vulnerability in includes/count_dl_or_link.inc.php in the astatsPRO (com_astatspro) 1.0.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to getfile.php, a different vector than…EXPLOIT ✓HIGH 7.5EPSS 0.91%22 February 2008
CVE-2008-0916SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a viewcategory action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%22 February 2008
CVE-2008-0912Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10.0.1.3415 and probably other products, allow remote attackers to execute arbitrary code or cause a denial of…EXPLOIT ✓HIGH 10.0EPSS 15.6%22 February 2008
CVE-2008-0911SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL commands via the productid parameter.EXPLOIT ✓MEDIUM 6.5EPSS 0.86%22 February 2008
CVE-2008-0907SQL injection vulnerability in the Inhalt module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.95%22 February 2008
CVE-2008-0906SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parameter in a viewarticle operation.EXPLOIT ✓HIGH 7.5EPSS 0.97%22 February 2008
CVE-2008-0905Directory traversal vulnerability in globsy_edit.php in Globsy 1.0 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.67%22 February 2008
CVE-2008-0881SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the okulid parameter in an okullar action.EXPLOIT ✓HIGH 7.5EPSS 1.06%21 February 2008
CVE-2008-0880SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the page_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.06%21 February 2008
CVE-2008-0879SQL injection vulnerability in modules.php in the Web_Links module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewlink action.EXPLOIT ✓HIGH 7.5EPSS 1.15%21 February 2008
CVE-2008-0878SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.EXPLOIT ✓HIGH 7.5EPSS 1.01%21 February 2008
CVE-2008-0877Multiple cross-site scripting (XSS) vulnerabilities in Jinzora Media Jukebox 2.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) frontend, (2) set_frontend, (3) jz_path, (4) theme, and (5) set_theme parameters to (a)…EXPLOIT ×4 ✓MEDIUM 4.3EPSS 1.49%21 February 2008
CVE-2008-0874SQL injection vulnerability in index.php in the eEmpregos module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.EXPLOIT ✓HIGH 7.5EPSS 1.01%21 February 2008
CVE-2008-0873SQL injection vulnerability in index.php in the jlmZone Classifieds module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in an Adsview action.EXPLOIT ✓HIGH 7.5EPSS 0.97%21 February 2008
CVE-2008-0872Cross-site scripting (XSS) vulnerability in SmarterTools SmarterMail Enterprise 4.3 allows remote attackers to inject arbitrary web script or HTML via a STYLE attribute of an element in the Subject field of an e-mail message.EXPLOIT ✓MEDIUM 4.3EPSS 1.72%21 February 2008
CVE-2008-0871Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute arbitrary code via a (1) long password in an Authorization header to the HTTP service or a (2) large packet to the SMPP service.EXPLOIT ×2 ✓MEDIUM 6.8EPSS 32.8%21 February 2008
CVE-2008-0857SQL injection vulnerability in index.php in WoltLab Burning Board 3.0.3 PL 1 allows remote attackers to execute arbitrary SQL commands via the sortOrder parameter to the PMList page.EXPLOIT ✓HIGH 7.5EPSS 1.00%21 February 2008
CVE-2008-0856Multiple SQL injection vulnerabilities in e-Vision CMS 2.02 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) iframe.php and (2) print.php.EXPLOIT ✓HIGH 7.5EPSS 0.91%21 February 2008
CVE-2008-0855SQL injection vulnerability in the Facile Forms (com_facileforms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.95%21 February 2008
CVE-2008-0854SQL injection vulnerability in the com_salesrep component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the rid parameter in a showrep action to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.96%21 February 2008
CVE-2008-0853SQL injection vulnerability in the com_detail component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%21 February 2008
CVE-2008-0852freeSSHd 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a SSH2_MSG_NEWKEYS packet to TCP port 22, which triggers a NULL pointer dereference.EXPLOIT ✓MEDIUM 5.0EPSS 6.23%21 February 2008
CVE-2008-0851Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to inscription.php, (2) courseCode parameter to main/calendar/myagenda.php, (3) category…EXPLOIT ×3 ✓MEDIUM 4.3EPSS 3.96%21 February 2008
CVE-2008-0850Multiple SQL injection vulnerabilities in Dokeos 1.8.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to whoisonline.php, (2) tracking_list_coaches_column parameter to main/mySpace/index.php, (3) tutor_name parameter…EXPLOIT ×4 ✓HIGH 7.5EPSS 2.38%21 February 2008
CVE-2008-0847SQL injection vulnerability in print.php in the myTopics module for XOOPS allows remote attackers to execute arbitrary SQL commands via the articleid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%21 February 2008
CVE-2008-0846SQL injection vulnerability in index.php in the com_profile component for Joomla! allows remote attackers to execute arbitrary SQL commands via the oid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.03%20 February 2008
CVE-2008-0845SQL injection vulnerability in wp-people-popup.php in Dean Logan WP-People plugin 1.6.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the person parameter.EXPLOIT ✓HIGH 7.5EPSS 2.80%20 February 2008
CVE-2008-0844SQL injection vulnerability in index.php in the PccookBook (com_pccookbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%20 February 2008
CVE-2008-0843StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a direct request to admin.asp.EXPLOIT ✓MEDIUM 6.4EPSS 2.55%20 February 2008
CVE-2008-0842SQL injection vulnerability in index.php in the Classifier (com_clasifier) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%20 February 2008
CVE-2008-0841SQL injection vulnerability in index.php in the Giorgio Nordo Ricette (com_ricette) 1.0 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.93%20 February 2008
CVE-2008-0840Directory traversal vulnerability in view_member.php in Public Warehouse LightBlog 9.6 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 4.4EPSS 2.37%20 February 2008
CVE-2008-0839SQL injection vulnerability in refer.php in the astatsPRO (com_astatspro) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%20 February 2008
CVE-2008-0838Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface in Sophos ES1000 and ES4000 Email Security Appliance 2.1.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) error and (2) go parameters to…EXPLOIT ✓MEDIUM 4.3EPSS 4.19%20 February 2008
CVE-2008-0835SQL injection vulnerability in indexen.php in Simple CMS 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the area parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%20 February 2008
CVE-2008-0833SQL injection vulnerability in index.php in the com_galeria component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.EXPLOIT ✓HIGH 7.5EPSS 1.00%20 February 2008
CVE-2008-0832SQL injection vulnerability in index.php in the Kemas Antonius com_quran 1.1 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the surano parameter in a viewayat action.EXPLOIT ✓HIGH 7.5EPSS 1.20%20 February 2008
CVE-2008-0831Multiple SQL injection vulnerabilities in the Rapid Recipe (com_rapidrecipe) 1.6.5 and earlier component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) user_id or (2) category_id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.92%20 February 2008
CVE-2008-0830The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (crash) via a malformed dpap: URI, a different vulnerability than CVE-2008-0043.EXPLOIT ✓HIGH 7.5EPSS 2.24%19 February 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.