SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,539 CVEs1,728 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 303 of 501

CVESummaryPriorityPublished
CVE-2008-0829SQL injection vulnerability in jooget.php in the Joomlapixel Jooget!EXPLOIT ✓HIGH 7.5EPSS 1.06%19 February 2008
CVE-2008-0827SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%19 February 2008
CVE-2008-0822Directory traversal vulnerability in index.php in Scribe 0.2 allows remote attackers to read arbitrary local files via a ..EXPLOIT ✓LOW 3.6EPSS 2.12%19 February 2008
CVE-2008-0821SQL injection vulnerability in admin/traffic/knowledge_searchm.php in OSI Codes Inc.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.94%19 February 2008
CVE-2008-0819Directory traversal vulnerability in index.php in PlutoStatus Locator 1.0 pre alpha allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓LOW 3.6EPSS 2.27%19 February 2008
CVE-2008-0818Multiple directory traversal vulnerabilities in freePHPgallery 0.6 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.50%19 February 2008
CVE-2008-0817SQL injection vulnerability in the com_filebase component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in a selectfolder action.EXPLOIT ✓HIGH 7.5EPSS 1.00%19 February 2008
CVE-2008-0816SQL injection vulnerability in the com_sg component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the pid parameter in an order task.EXPLOIT ✓HIGH 7.5EPSS 0.96%19 February 2008
CVE-2008-0815SQL injection vulnerability in the com_mezun component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task.EXPLOIT ✓HIGH 7.5EPSS 0.96%19 February 2008
CVE-2008-0814Directory traversal vulnerability in download.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 6.4EPSS 2.21%19 February 2008
CVE-2008-0813Directory traversal vulnerability in Download.php in XPWeb 3.0.1, 3.3.2, and possibly other versions, allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.67%19 February 2008
CVE-2008-0812Directory traversal vulnerability in DMS/index.php in BanPro DMS 1.0 allows remote attackers to include and execute arbitrary files via a ..EXPLOIT ✓MEDIUM 6.4EPSS 2.29%19 February 2008
CVE-2008-0811Multiple SQL injection vulnerabilities in AuraCMS 1.62 allow remote attackers to execute arbitrary SQL commands via (1) the kid parameter to (a) mod/dl.php or (b) mod/links.php, and (2) the query parameter to search.php.EXPLOIT ✓HIGH 7.5EPSS 1.00%19 February 2008
CVE-2008-0810SQL injection vulnerability in the com_scheduling module for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.96%19 February 2008
CVE-2008-0805Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension from the event page, then accessing it via a direct request to the file in…EXPLOIT ✓HIGH 9.3EPSS 5.19%19 February 2008
CVE-2008-0804PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to execute arbitrary PHP code via a URL in the name parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.98%19 February 2008
CVE-2007-6258Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header.EXPLOIT ✓HIGH 7.5EPSS 41.5%19 February 2008
CVE-2008-0803Multiple PHP remote file inclusion vulnerabilities in LookStrike Lan Manager 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the sys_conf[path][real] parameter to (1) modules\class\Table.php; (2) db_admins.php, (3) db_alert.php,…EXPLOIT ✓HIGH 7.5EPSS 32.7%15 February 2008
CVE-2008-0802SQL injection vulnerability in index.php in the MediaSlide (com_mediaslide) 0.5 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the albumnum parameter in a contact action.EXPLOIT ✓HIGH 7.5EPSS 2.08%15 February 2008
CVE-2008-0801SQL injection vulnerability in index.php in the PAXXGallery (com_paxxgallery) 0.2 component for Mambo and Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the iid parameter in a view action, and possibly (2) the userid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%15 February 2008
CVE-2008-0800SQL injection vulnerability in index.php in the McQuiz (com_mcquiz) 0.9 Final component for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.EXPLOIT ✓HIGH 7.5EPSS 1.00%15 February 2008
CVE-2008-0799SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.EXPLOIT ✓HIGH 7.5EPSS 1.00%15 February 2008
CVE-2008-0798Multiple directory traversal vulnerabilities in artmedic webdesign weblog 1.0, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 4.3EPSS 2.36%15 February 2008
CVE-2008-0796SQL injection vulnerability in threads.php in Nuboard 0.5 allows remote attackers to execute arbitrary SQL commands via the ssid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.92%15 February 2008
CVE-2008-0795SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action.EXPLOIT ✓HIGH 7.5EPSS 0.97%15 February 2008
CVE-2008-0794Directory traversal vulnerability in user/header.php in Affiliate Market 0.1 BETA allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.4EPSS 2.44%15 February 2008
CVE-2008-0790Directory traversal vulnerability in ipdsserver.exe in Intermate WinIPDS 3.3 G52-33-021 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 3.32%15 February 2008
CVE-2008-0787SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php.EXPLOIT ✓MEDIUM 6.5EPSS 1.36%15 February 2008
CVE-2008-0785Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote authenticated users to execute arbitrary SQL commands via the (1) graph_list parameter to graph_view.php, (2) leaf_id and id parameters to tree.php,…EXPLOIT ×4 ✓HIGH 7.5EPSS 3.44%14 February 2008
CVE-2008-0783Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to inject arbitrary web script or HTML via (1) the view_type parameter to graph.php; (2) the filter parameter to…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 5.25%14 February 2008
CVE-2008-0782Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 14.9%14 February 2008
CVE-2008-0778Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the (1) SetBgColor,…EXPLOIT ✓HIGH 7.5EPSS 9.21%14 February 2008
CVE-2008-0026SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2)…EXPLOIT ✓MEDIUM 6.5EPSS 1.93%14 February 2008
CVE-2008-0776SQL injection vulnerability in detail.php in iTechBids Gold 6.0 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.14%14 February 2008
CVE-2008-0773SQL injection vulnerability in Phil Taylor Comments (com_comments, aka Review Script) 0.5.8.5g and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.06%14 February 2008
CVE-2008-0772SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the sid parameter in a view task.EXPLOIT ✓HIGH 7.5EPSS 1.06%14 February 2008
CVE-2008-0770SQL injection vulnerability in arcade.php in ibProArcade 3.3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the g_display_order cookie parameter.EXPLOIT ✓HIGH 7.5EPSS 1.06%14 February 2008
CVE-2008-0767ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain "number of URLs" field is consistent with the packet length, which allows remote attackers to cause a denial of service (daemon crash) via a large…EXPLOIT ✓MEDIUM 5.0EPSS 7.71%13 February 2008
CVE-2008-0764Format string vulnerability in the logging function in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier for Windows might allow remote attackers to execute arbitrary code via format string specifiers in a USEP command on TCP port 3114.EXPLOIT ✓HIGH 10.0EPSS 7.40%13 February 2008
CVE-2008-0763Stack-based buffer overflow in NPSpcSVR.exe in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier allows remote attackers to execute arbitrary code via a long argument in a LICENSE command on TCP port 3114.EXPLOIT ✓HIGH 10.0EPSS 8.05%13 February 2008
CVE-2008-0761SQL injection vulnerability in index.php in the Prince Clan Chess Club (com_pcchess) 0.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a players action.EXPLOIT ✓HIGH 7.5EPSS 1.00%13 February 2008
CVE-2008-0760Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.0.4.0 and earlier, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URI.EXPLOIT ✓MEDIUM 5.0EPSS 3.32%13 February 2008
CVE-2008-0756The LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard 4.10.940 and earlier; allows remote attackers to cause a denial of…EXPLOIT ✓MEDIUM 5.0EPSS 3.24%13 February 2008
CVE-2008-0755Format string vulnerability in the ReportSysLogEvent function in the LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard…EXPLOIT ✓HIGH 7.5EPSS 4.92%13 February 2008
CVE-2008-0754Multiple SQL injection vulnerabilities in index.php in the Rapid Recipe (com_rapidrecipe) 1.6.5 component for Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a showuser action or (2) the category_id…EXPLOIT ✓HIGH 7.5EPSS 0.96%13 February 2008
CVE-2008-0753SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter.EXPLOIT ✓HIGH 7.5EPSS 0.96%13 February 2008
CVE-2008-0752SQL injection vulnerability in index.php in the Neogallery (com_neogallery) 1.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show action.EXPLOIT ✓HIGH 7.5EPSS 1.00%13 February 2008
CVE-2008-0751Cross-site scripting (XSS) vulnerability in the Freetag before 2.96 plugin for S9Y Serendipity, when using Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to plugin/tag/.EXPLOIT ✓MEDIUM 4.3EPSS 2.22%13 February 2008
CVE-2008-0749Cross-site scripting (XSS) vulnerability in index.php in Calimero.CMS 3.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a calimero_webpage action.EXPLOIT ✓MEDIUM 4.3EPSS 1.45%13 February 2008
CVE-2008-0748Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 for Sony ImageStation allows remote attackers to execute arbitrary code via a long argument to the SetLogging…EXPLOIT ×2 ✓HIGH 10.0EPSS 16.2%13 February 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.