Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,539 CVEs1,728 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 304 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-0747 | Stack-based buffer overflow in COWON America jetAudio 7.0.5 and earlier allows user-assisted remote attackers to execute arbitrary code via a long URL in a .asx file, a different vulnerability than CVE-2007-5487. | EXPLOIT ×2 ✓HIGH 9.3EPSS 6.86% | 13 February 2008 |
| CVE-2008-0746 | SQL injection vulnerability in index.php in the Gallery (com_gallery) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 13 February 2008 |
| CVE-2008-0745 | Directory traversal vulnerability in aides/index.php in DomPHP 0.82 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.25% | 13 February 2008 |
| CVE-2008-0744 | SQL injection vulnerability in user_login.asp in PreProjects.com Pre Hotels & Resorts Management System allows remote attackers to execute arbitrary SQL commands via the login page. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 13 February 2008 |
| CVE-2008-0743 | PHP remote file inclusion vulnerability in members_help.php in Joovili 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the hlp parameter. | EXPLOIT ✓HIGH 10.0EPSS 3.43% | 13 February 2008 |
| CVE-2008-0742 | Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 13 February 2008 |
| CVE-2008-0739 | SQL injection vulnerability in admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and earlier 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the FedExAccount parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 13 February 2008 |
| CVE-2008-0738 | Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idcust parameter to (a) ajax_getTiers.asp and (b) ajax_getCust.asp in ajax/, and the (2)… | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 13 February 2008 |
| CVE-2008-0737 | SQL injection vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and other 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the helpfield parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.34% | 13 February 2008 |
| CVE-2008-0736 | admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a certain value of the FedExAccount parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 3.12% | 13 February 2008 |
| CVE-2008-0735 | SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the albums parameter. | EXPLOIT ✓HIGH 10.0EPSS 1.55% | 13 February 2008 |
| CVE-2008-0734 | SQL injection vulnerability in class_auth.php in Limbo CMS 1.0.4.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the cuid cookie parameter to admin.php. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 13 February 2008 |
| CVE-2008-0733 | SQL injection vulnerability in index.php in CS Team Counter Strike Portals allows remote attackers to execute arbitrary SQL commands via the id parameter, as demonstrated using the downloads page. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 13 February 2008 |
| CVE-2008-0108 | Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka… | EXPLOIT ×2 ✓HIGH 9.3EPSS 52.6% | 12 February 2008 |
| CVE-2008-0105 | Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File… | EXPLOIT ✓HIGH 9.3EPSS 43.8% | 12 February 2008 |
| CVE-2007-0216 | wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter… | EXPLOIT ✓HIGH 9.3EPSS 38.1% | 12 February 2008 |
| CVE-2008-0729 | Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion and device crash) via certain JavaScript code that constructs a long string and an array containing long string elements, possibly a… | EXPLOIT ✓HIGH 7.1EPSS 8.07% | 12 February 2008 |
| CVE-2008-0600 | The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows local users to gain root privileges via crafted arguments in a vmsplice system call, a different… | EXPLOIT ×2 ✓HIGH 7.2EPSS 3.54% | 12 February 2008 |
| CVE-2008-0010 | The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which allow local users to read from arbitrary kernel memory locations. | EXPLOIT ×2 ✓LOW 2.1EPSS 0.89% | 12 February 2008 |
| CVE-2008-0009 | The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations. | EXPLOIT ×2 ✓LOW 2.1EPSS 0.96% | 12 February 2008 |
| CVE-2008-0636 | (LPI) Managed Workplace Service Center 4.x, 5.x and 6.x allows remote attackers to obtain sensitive information via a direct request to About/SC_About.htm, which provides version and patch information. | EXPLOIT ✓MEDIUM 5.0EPSS 2.59% | 12 February 2008 |
| CVE-2007-5659 | Adobe Acrobat and Reader Buffer Overflow Vulnerability | KEVEXPLOIT ×2 ✓HIGH 7.8EPSS 87.4% | 12 February 2008 |
| CVE-2008-0724 | The Everything Development Engine in The Everything Development System Pre-1.0 and earlier stores passwords in cleartext in a database, which makes it easier for context-dependent attackers to obtain access to user accounts. | EXPLOIT ✓MEDIUM 5.0EPSS 2.40% | 12 February 2008 |
| CVE-2008-0723 | Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews 1.6.4, and other earlier 1.6.x versions, allows remote attackers to inject arbitrary web script or HTML via the hash parameter in an admin action to index.php, a different… | EXPLOIT ✓MEDIUM 4.3EPSS 1.44% | 12 February 2008 |
| CVE-2008-0722 | Cross-site scripting (XSS) vulnerability in index.php in Pagetool 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the search_term parameter in a pagetool_search action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.21% | 12 February 2008 |
| CVE-2008-0721 | SQL injection vulnerability in index.php in the Sermon (com_sermon) 0.2 component for Mambo allows remote attackers to execute arbitrary SQL commands via the gid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 12 February 2008 |
| CVE-2008-0719 | SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remote attackers to execute arbitrary SQL commands via the testimonial_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.88% | 12 February 2008 |
| CVE-2008-0714 | SQL injection vulnerability in users.php in Mihalism Multi Host allows remote attackers to execute arbitrary SQL commands via the username parameter in a lost_password_go action. | EXPLOIT ✓MEDIUM 6.8EPSS 0.95% | 12 February 2008 |
| CVE-2008-0703 | Multiple directory traversal vulnerabilities in sflog! | EXPLOIT ✓MEDIUM 5.0EPSS 2.76% | 12 February 2008 |
| CVE-2008-0702 | Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of service (daemon crash or hang) and possibly execute arbitrary code via a long argument to the (1) USER or (2) PASS command, different… | EXPLOIT ✓HIGH 9.3EPSS 7.71% | 12 February 2008 |
| CVE-2008-0700 | Cross-site scripting (XSS) vulnerability in search.php in Crux Software CruxCMS 3.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.20% | 12 February 2008 |
| CVE-2008-0695 | SQL injection vulnerability in index.php in BookmarkX script 2007 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a showtopic action. | EXPLOIT ✓HIGH 7.5EPSS 0.92% | 12 February 2008 |
| CVE-2008-0692 | SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary SQL commands via the item_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 12 February 2008 |
| CVE-2008-0691 | Multiple cross-site scripting (XSS) vulnerabilities in admin_panel.php in the Simon Elvery WP-Footnotes 2.2 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) wp_footnotes_current_settings[priority], (2)… | EXPLOIT ✓MEDIUM 4.3EPSS 3.59% | 12 February 2008 |
| CVE-2008-0690 | SQL injection vulnerability in index.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a viewcat action. | EXPLOIT ✓HIGH 7.5EPSS 9.05% | 12 February 2008 |
| CVE-2008-0689 | SQL injection vulnerability in index.php in the Marketplace (com_marketplace) 1.1.1 and 1.1.1-pl1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_category action. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.94% | 12 February 2008 |
| CVE-2008-0688 | Cross-site scripting (XSS) vulnerability in catalog.php in Smartscript Domain Trader 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a viewcategory action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 12 February 2008 |
| CVE-2008-0686 | SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 12 February 2008 |
| CVE-2008-0685 | SQL injection vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to execute arbitrary SQL commands via the CatID parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.96% | 12 February 2008 |
| CVE-2008-0684 | Cross-site scripting (XSS) vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to inject arbitrary web script or HTML via the CatID parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.45% | 12 February 2008 |
| CVE-2008-0683 | SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the newsletter parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.56% | 12 February 2008 |
| CVE-2008-0682 | SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.85% | 12 February 2008 |
| CVE-2008-0681 | SQL injection vulnerability in index.php in PHPShop 0.8.1 allows remote attackers to execute arbitrary SQL commands via the product_id parameter, as demonstrated by a shop/flypage action. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.99% | 12 February 2008 |
| CVE-2008-0680 | SNMPd in MikroTik RouterOS 3.2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP SET request. | EXPLOIT ✓HIGH 7.8EPSS 7.44% | 12 February 2008 |
| CVE-2008-0679 | Cross-site scripting (XSS) vulnerability in index.php in BlogPHP 2.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 12 February 2008 |
| CVE-2008-0678 | SQL injection vulnerability in index.php in BlogPHP 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a page action. | EXPLOIT ✓MEDIUM 6.8EPSS 0.94% | 12 February 2008 |
| CVE-2008-0677 | SQL injection vulnerability in blog.php in A-Blog 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a news action. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 12 February 2008 |
| CVE-2008-0676 | Cross-site scripting (XSS) vulnerability in search.php in A-Blog 2 allows remote attackers to inject arbitrary web script or HTML via the words parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.22% | 12 February 2008 |
| CVE-2008-0675 | SQL injection vulnerability in cms/index.pl in The Everything Development Engine in The Everything Development System Pre-1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the node_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 12 February 2008 |
| CVE-2008-0671 | Stack-based buffer overflow in the add_line_buffer function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attackers to execute arbitrary code via a long chat message, related to conversion from LF to CRLF. | EXPLOIT ✓HIGH 10.0EPSS 15.6% | 12 February 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.