Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,539 CVEs1,728 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 303 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-0829 | SQL injection vulnerability in jooget.php in the Joomlapixel Jooget! | EXPLOIT ✓HIGH 7.5EPSS 1.06% | 19 February 2008 |
| CVE-2008-0827 | SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 19 February 2008 |
| CVE-2008-0822 | Directory traversal vulnerability in index.php in Scribe 0.2 allows remote attackers to read arbitrary local files via a .. | EXPLOIT ✓LOW 3.6EPSS 2.12% | 19 February 2008 |
| CVE-2008-0821 | SQL injection vulnerability in admin/traffic/knowledge_searchm.php in OSI Codes Inc. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.94% | 19 February 2008 |
| CVE-2008-0819 | Directory traversal vulnerability in index.php in PlutoStatus Locator 1.0 pre alpha allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓LOW 3.6EPSS 2.27% | 19 February 2008 |
| CVE-2008-0818 | Multiple directory traversal vulnerabilities in freePHPgallery 0.6 allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.50% | 19 February 2008 |
| CVE-2008-0817 | SQL injection vulnerability in the com_filebase component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in a selectfolder action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 19 February 2008 |
| CVE-2008-0816 | SQL injection vulnerability in the com_sg component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the pid parameter in an order task. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 19 February 2008 |
| CVE-2008-0815 | SQL injection vulnerability in the com_mezun component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 19 February 2008 |
| CVE-2008-0814 | Directory traversal vulnerability in download.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.4EPSS 2.21% | 19 February 2008 |
| CVE-2008-0813 | Directory traversal vulnerability in Download.php in XPWeb 3.0.1, 3.3.2, and possibly other versions, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.67% | 19 February 2008 |
| CVE-2008-0812 | Directory traversal vulnerability in DMS/index.php in BanPro DMS 1.0 allows remote attackers to include and execute arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.4EPSS 2.29% | 19 February 2008 |
| CVE-2008-0811 | Multiple SQL injection vulnerabilities in AuraCMS 1.62 allow remote attackers to execute arbitrary SQL commands via (1) the kid parameter to (a) mod/dl.php or (b) mod/links.php, and (2) the query parameter to search.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 19 February 2008 |
| CVE-2008-0810 | SQL injection vulnerability in the com_scheduling module for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 19 February 2008 |
| CVE-2008-0805 | Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension from the event page, then accessing it via a direct request to the file in… | EXPLOIT ✓HIGH 9.3EPSS 5.19% | 19 February 2008 |
| CVE-2008-0804 | PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to execute arbitrary PHP code via a URL in the name parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.98% | 19 February 2008 |
| CVE-2007-6258 | Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header. | EXPLOIT ✓HIGH 7.5EPSS 41.5% | 19 February 2008 |
| CVE-2008-0803 | Multiple PHP remote file inclusion vulnerabilities in LookStrike Lan Manager 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the sys_conf[path][real] parameter to (1) modules\class\Table.php; (2) db_admins.php, (3) db_alert.php,… | EXPLOIT ✓HIGH 7.5EPSS 32.7% | 15 February 2008 |
| CVE-2008-0802 | SQL injection vulnerability in index.php in the MediaSlide (com_mediaslide) 0.5 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the albumnum parameter in a contact action. | EXPLOIT ✓HIGH 7.5EPSS 2.08% | 15 February 2008 |
| CVE-2008-0801 | SQL injection vulnerability in index.php in the PAXXGallery (com_paxxgallery) 0.2 component for Mambo and Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the iid parameter in a view action, and possibly (2) the userid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 15 February 2008 |
| CVE-2008-0800 | SQL injection vulnerability in index.php in the McQuiz (com_mcquiz) 0.9 Final component for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 15 February 2008 |
| CVE-2008-0799 | SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 15 February 2008 |
| CVE-2008-0798 | Multiple directory traversal vulnerabilities in artmedic webdesign weblog 1.0, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 2.36% | 15 February 2008 |
| CVE-2008-0796 | SQL injection vulnerability in threads.php in Nuboard 0.5 allows remote attackers to execute arbitrary SQL commands via the ssid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.92% | 15 February 2008 |
| CVE-2008-0795 | SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 15 February 2008 |
| CVE-2008-0794 | Directory traversal vulnerability in user/header.php in Affiliate Market 0.1 BETA allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.4EPSS 2.44% | 15 February 2008 |
| CVE-2008-0790 | Directory traversal vulnerability in ipdsserver.exe in Intermate WinIPDS 3.3 G52-33-021 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.32% | 15 February 2008 |
| CVE-2008-0787 | SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php. | EXPLOIT ✓MEDIUM 6.5EPSS 1.36% | 15 February 2008 |
| CVE-2008-0785 | Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote authenticated users to execute arbitrary SQL commands via the (1) graph_list parameter to graph_view.php, (2) leaf_id and id parameters to tree.php,… | EXPLOIT ×4 ✓HIGH 7.5EPSS 3.44% | 14 February 2008 |
| CVE-2008-0783 | Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to inject arbitrary web script or HTML via (1) the view_type parameter to graph.php; (2) the filter parameter to… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 5.25% | 14 February 2008 |
| CVE-2008-0782 | Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 14.9% | 14 February 2008 |
| CVE-2008-0778 | Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the (1) SetBgColor,… | EXPLOIT ✓HIGH 7.5EPSS 9.21% | 14 February 2008 |
| CVE-2008-0026 | SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2)… | EXPLOIT ✓MEDIUM 6.5EPSS 1.93% | 14 February 2008 |
| CVE-2008-0776 | SQL injection vulnerability in detail.php in iTechBids Gold 6.0 allows remote attackers to execute arbitrary SQL commands via the item_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.14% | 14 February 2008 |
| CVE-2008-0773 | SQL injection vulnerability in Phil Taylor Comments (com_comments, aka Review Script) 0.5.8.5g and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.06% | 14 February 2008 |
| CVE-2008-0772 | SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the sid parameter in a view task. | EXPLOIT ✓HIGH 7.5EPSS 1.06% | 14 February 2008 |
| CVE-2008-0770 | SQL injection vulnerability in arcade.php in ibProArcade 3.3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the g_display_order cookie parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.06% | 14 February 2008 |
| CVE-2008-0767 | ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain "number of URLs" field is consistent with the packet length, which allows remote attackers to cause a denial of service (daemon crash) via a large… | EXPLOIT ✓MEDIUM 5.0EPSS 7.71% | 13 February 2008 |
| CVE-2008-0764 | Format string vulnerability in the logging function in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier for Windows might allow remote attackers to execute arbitrary code via format string specifiers in a USEP command on TCP port 3114. | EXPLOIT ✓HIGH 10.0EPSS 7.40% | 13 February 2008 |
| CVE-2008-0763 | Stack-based buffer overflow in NPSpcSVR.exe in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier allows remote attackers to execute arbitrary code via a long argument in a LICENSE command on TCP port 3114. | EXPLOIT ✓HIGH 10.0EPSS 8.05% | 13 February 2008 |
| CVE-2008-0761 | SQL injection vulnerability in index.php in the Prince Clan Chess Club (com_pcchess) 0.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a players action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 13 February 2008 |
| CVE-2008-0760 | Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.0.4.0 and earlier, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URI. | EXPLOIT ✓MEDIUM 5.0EPSS 3.32% | 13 February 2008 |
| CVE-2008-0756 | The LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard 4.10.940 and earlier; allows remote attackers to cause a denial of… | EXPLOIT ✓MEDIUM 5.0EPSS 3.24% | 13 February 2008 |
| CVE-2008-0755 | Format string vulnerability in the ReportSysLogEvent function in the LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard… | EXPLOIT ✓HIGH 7.5EPSS 4.92% | 13 February 2008 |
| CVE-2008-0754 | Multiple SQL injection vulnerabilities in index.php in the Rapid Recipe (com_rapidrecipe) 1.6.5 component for Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a showuser action or (2) the category_id… | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 13 February 2008 |
| CVE-2008-0753 | SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 13 February 2008 |
| CVE-2008-0752 | SQL injection vulnerability in index.php in the Neogallery (com_neogallery) 1.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 13 February 2008 |
| CVE-2008-0751 | Cross-site scripting (XSS) vulnerability in the Freetag before 2.96 plugin for S9Y Serendipity, when using Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to plugin/tag/. | EXPLOIT ✓MEDIUM 4.3EPSS 2.22% | 13 February 2008 |
| CVE-2008-0749 | Cross-site scripting (XSS) vulnerability in index.php in Calimero.CMS 3.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a calimero_webpage action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 13 February 2008 |
| CVE-2008-0748 | Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 for Sony ImageStation allows remote attackers to execute arbitrary code via a long argument to the SetLogging… | EXPLOIT ×2 ✓HIGH 10.0EPSS 16.2% | 13 February 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.