SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-27 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,539 CVEs1,728 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 305 of 501

CVESummaryPriorityPublished
CVE-2008-0670SQL injection vulnerability in index.php in the Noticias (com_noticias) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detalhe action.EXPLOIT ✓HIGH 7.5EPSS 0.93%12 February 2008
CVE-2007-5333Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as…EXPLOIT ✓MEDIUM 5.0EPSS 62.6%12 February 2008
CVE-2008-0418Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addons, allows remote attackers to read arbitrary Javascript, image, and stylesheet files via the chrome:…EXPLOIT ✓MEDIUM 4.3EPSS 8.63%8 February 2008
CVE-2008-0661Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file with a long URI.EXPLOIT ×2 ✓MEDIUM 6.8EPSS 4.79%8 February 2008
CVE-2008-0660Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary…EXPLOIT ✓HIGH 9.3EPSS 37.8%8 February 2008
CVE-2008-0659Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used in MySpace MySpaceUploader.ocx 1.0.0.4, allows remote attackers to execute arbitrary code via a long Action property.EXPLOIT ✓HIGH 10.0EPSS 56.3%8 February 2008
CVE-2008-0177The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6…EXPLOIT ✓HIGH 7.8EPSS 15.5%7 February 2008
CVE-2008-0653SQL injection vulnerability in index.php in the Ynews (com_ynews) 1.0.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showYNews action.EXPLOIT ✓HIGH 7.5EPSS 0.93%7 February 2008
CVE-2008-0652SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in a selectfolder action.EXPLOIT ✓HIGH 7.5EPSS 0.93%7 February 2008
CVE-2008-0651SQL injection vulnerability in login.php in Pedro Santana Codice CMS allows remote attackers to execute arbitrary SQL commands via the username field.EXPLOIT ✓HIGH 7.5EPSS 0.90%7 February 2008
CVE-2008-0650SQL injection vulnerability in login.php in Simple OS CMS 0.1c beta allows remote attackers to execute arbitrary SQL commands via the username field.EXPLOIT ✓HIGH 7.5EPSS 0.90%7 February 2008
CVE-2008-0649SQL injection vulnerability in detail.php in Astanda Directory Project (ADP) 1.2 and 1.3 allows remote attackers to execute arbitrary SQL commands via the link_id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.93%7 February 2008
CVE-2008-0648Multiple PHP remote file inclusion vulnerabilities in OpenSiteAdmin 0.9.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) indexFooter.php; and (2) DatabaseManager.php, (3) FieldManager.php, (4)…EXPLOIT ✓MEDIUM 6.8EPSS 2.02%7 February 2008
CVE-2008-0647Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to…EXPLOIT ✓HIGH 10.0EPSS 7.30%7 February 2008
CVE-2008-0645Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 allow remote attackers to execute arbitrary PHP code via a URL in the site_path parameter to (1) config/conf-activation.php, (2) menu/item.php, and (3)…EXPLOIT ×4 ✓HIGH 7.5EPSS 34.3%7 February 2008
CVE-2008-0457Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP…EXPLOIT ×2 ✓HIGH 10.0EPSS 11.9%7 February 2008
CVE-2008-0634Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote attackers to execute arbitrary code via a long argument to the Install method, a different…EXPLOIT ✓HIGH 7.5EPSS 4.65%6 February 2008
CVE-2008-0633Buffer overflow in Anon Proxy Server 0.102 and earlier, when user authentication is enabled, allows remote attackers to cause a denial of service (exception) via a user name with a large number of quotes, which triggers the overflow during escaping.EXPLOIT ✓MEDIUM 6.0EPSS 1.93%6 February 2008
CVE-2008-0632Unrestricted file upload vulnerability in cp_upload_image.php in LightBlog 9.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the blog's root…EXPLOIT ✓HIGH 9.3EPSS 6.36%6 February 2008
CVE-2008-0631Multiple ActiveX controls in MailBee.dll in MailBee Objects 5.5 allow remote attackers to (1) overwrite arbitrary files via the SaveToDisk method, or (2) modify files via the AddStringToFile method.EXPLOIT ✓MEDIUM 4.3EPSS 3.56%6 February 2008
CVE-2008-0625Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo!EXPLOIT ✓MEDIUM 4.3EPSS 8.10%6 February 2008
CVE-2008-0624Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo!EXPLOIT ×4 ✓MEDIUM 4.3EPSS 7.60%6 February 2008
CVE-2008-0623Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo!EXPLOIT ×4 ✓MEDIUM 4.3EPSS 9.15%6 February 2008
CVE-2008-0621Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to execute arbitrary code via long arguments to the (1) 0x01, (2) 0x02, (3) 0x03, (4) 0x04, and (5) 0x05 LPD commands.EXPLOIT ×2 ✓HIGH 7.5EPSS 73.4%6 February 2008
CVE-2008-0619Buffer overflow in NeroMediaPlayer.exe in Nero Media Player 1.4.0.35 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (persistent crash) via a long URI in a .M3U file.EXPLOIT ✓HIGH 9.3EPSS 10.8%6 February 2008
CVE-2008-0616SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors.EXPLOIT ✓MEDIUM 6.5EPSS 4.25%6 February 2008
CVE-2008-0614SQL injection vulnerability in index.php in Photokorn Gallery 1.543 allows remote attackers to execute arbitrary SQL commands via the pic parameter in a showpic action.EXPLOIT ✓HIGH 7.5EPSS 0.93%6 February 2008
CVE-2008-0613Open redirect vulnerability in htdocs/user.php in XOOPS 2.0.18 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the xoops_redirect parameter.EXPLOIT ✓MEDIUM 5.0EPSS 2.04%6 February 2008
CVE-2008-0612Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.78%6 February 2008
CVE-2008-0611SQL injection vulnerability in rmgs/images.php in the RMSOFT Gallery System 2.0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.93%6 February 2008
CVE-2008-0610Stack-based buffer overflow in the ClientConnection::NegotiateProtocolVersion function in vncviewer/ClientConnection.cpp in vncviewer for UltraVNC 1.0.2 and 1.0.4 before 01252008, when in LISTENING mode or when using the DSM plugin, allows remote…EXPLOIT ✓HIGH 9.3EPSS 38.8%6 February 2008
CVE-2008-0609Directory traversal vulnerability in index.php in DivideConcept VHD Web Pack 2.0 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.37%6 February 2008
CVE-2008-0606SQL injection vulnerability in index.php in the Shambo2 (com_shambo2) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%6 February 2008
CVE-2008-0605Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.49%6 February 2008
CVE-2008-0603SQL injection vulnerability in index.php in the amazOOP Awesom!EXPLOIT ✓HIGH 7.5EPSS 0.93%6 February 2008
CVE-2008-0602Directory traversal vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the class_name parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.97%6 February 2008
CVE-2008-0601SQL injection vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter.EXPLOIT ✓HIGH 7.5EPSS 0.93%6 February 2008
CVE-2008-0590Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long opendir command.EXPLOIT ✓HIGH 9.0EPSS 22.2%5 February 2008
CVE-2008-0485Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV file with a crafted stsc atom tag.EXPLOIT ✓HIGH 9.3EPSS 8.88%5 February 2008
CVE-2008-0579SQL injection vulnerability in index.php in the buslicense (com_buslicense) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in a list action.EXPLOIT ✓HIGH 7.5EPSS 1.14%5 February 2008
CVE-2008-0574Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.01.02 allows remote attackers to inject arbitrary web script or HTML via the sort parameter in a whoisonline action.EXPLOIT ✓MEDIUM 4.3EPSS 1.51%5 February 2008
CVE-2008-0573IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafted IPSECDRV_IOCTL IOCTL request.EXPLOIT ✓HIGH 7.2EPSS 0.84%5 February 2008
CVE-2008-0572Multiple PHP remote file inclusion vulnerabilities in Mindmeld 1.2.0.10 allow remote attackers to execute arbitrary PHP code via a URL in the MM_GLOBALS[home] parameter to (1) acweb/admin_index.php; and (2) ask.inc.php, (3) learn.inc.php, (4)…EXPLOIT ✓MEDIUM 6.8EPSS 21.5%5 February 2008
CVE-2008-0567Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) PPS/File.php,…EXPLOIT ✓HIGH 7.5EPSS 34.3%5 February 2008
CVE-2008-0566PHP remote file inclusion vulnerability in includes/smarty.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full_path_to_public_program parameter.EXPLOIT ✓MEDIUM 6.8EPSS 23.5%5 February 2008
CVE-2008-0565SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.06%5 February 2008
CVE-2007-6700Cross-site scripting (XSS) vulnerability in cgi-bin/bgplg in the web interface for the BGPD daemon in OpenBSD 4.1 allows remote attackers to inject arbitrary web script or HTML via the cmd parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.69%5 February 2008
CVE-2008-0178Cross-site scripting (XSS) vulnerability in the Enterprise Admin Session Monitoring component in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the User-Agent HTTP header.EXPLOIT ✓MEDIUM 4.3EPSS 2.01%5 February 2008
CVE-2008-0562SQL injection vulnerability in index.php in the Restaurant (com_restaurant) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.EXPLOIT ✓HIGH 7.5EPSS 1.10%4 February 2008
CVE-2008-0561SQL injection vulnerability in index.php in the Arthur Konze AkoGallery (com_akogallery) 2.5 beta component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.EXPLOIT ✓HIGH 7.5EPSS 1.10%4 February 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.