SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,548 CVEs1,728 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 306 of 501

CVESummaryPriorityPublished
CVE-2008-0559Multiple directory traversal vulnerabilities in Nilson's Blogger 0.11 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.72%4 February 2008
CVE-2008-0557SQL injection vulnerability in index.php in the CatalogShop (com_catalogshop) 1.0b1 componenent for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.EXPLOIT ✓HIGH 7.5EPSS 1.14%4 February 2008
CVE-2007-6699Multiple buffer overflows in the AIM PicEditor 9.5.1.8 ActiveX control in YGPPicEdit.dll in AOL You've Got Pictures (YGP) Picture Editor allow remote attackers to cause a denial of service (browser crash) via a long string in the (1) DisplayName, (2)…EXPLOIT ✓MEDIUM 4.3EPSS 4.50%4 February 2008
CVE-2008-0552Cross-site scripting (XSS) vulnerability in index.php in eTicket 1.5.6-RC4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.EXPLOIT ✓MEDIUM 4.3EPSS 1.89%1 February 2008
CVE-2008-0551The NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1 and earlier in Namo Web Editor in Sejoong Namo ActiveSquare 6 allows remote attackers to execute arbitrary code via a URL in the argument to the Install method.EXPLOIT ✓HIGH 9.3EPSS 29.7%1 February 2008
CVE-2008-0550Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a certain HTTP request that leads to a buffer overflow, as demonstrated by a long User-Agent header.EXPLOIT ✓HIGH 10.0EPSS 53.8%1 February 2008
CVE-2008-0547Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably earlier 4.x and 3.x versions, allows remote attackers to inject arbitrary web script or HTML via the helpfield parameter.EXPLOIT ✓MEDIUM 4.3EPSS 3.73%1 February 2008
CVE-2008-0546Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idProduct and (2) options parameters to (a) ajax/ajax_optInventory.asp, or the (2) recid…EXPLOIT ✓HIGH 7.5EPSS 3.15%1 February 2008
CVE-2008-0545Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.29%1 February 2008
CVE-2008-0542Directory traversal vulnerability in thumbnail.php in Gerd Tentler Simple Forum 3.2 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.67%1 February 2008
CVE-2008-0541Multiple cross-site scripting (XSS) vulnerabilities in forum.php in Gerd Tentler Simple Forum 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) open and (2) date_show parameters.EXPLOIT ✓MEDIUM 4.3EPSS 1.44%1 February 2008
CVE-2008-0540Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote attackers to inject arbitrary web script or HTML via the query string to index.php in (1) user/ or (2) maint/.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.34%1 February 2008
CVE-2008-0539Cross-site scripting (XSS) vulnerability in dms/policy/rep_request.php in F5 BIG-IP Application Security Manager (ASM) 9.4.3 allows remote attackers to inject arbitrary web script or HTML via the report_type parameter.EXPLOIT ✓MEDIUM 4.3EPSS 7.21%1 February 2008
CVE-2008-0538Multiple SQL injection vulnerabilities in phpIP Management 4.3.2 allow remote attackers to execute arbitrary SQL commands via the (1) password parameter to login.php, the (2) id parameter to display.php, and unspecified other vectors.EXPLOIT ✓MEDIUM 6.8EPSS 1.16%1 February 2008
CVE-2007-6697Buffer overflow in the LWZReadByte function in IMG_gif.c in SDL_image before 1.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, a similar issue to CVE-2006-4484.EXPLOIT ✓HIGH 7.5EPSS 10.7%1 February 2008
CVE-2007-6696Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) an event description, (2) the query string to pref.php, and (3) the adv parameter to search.php.EXPLOIT ×2 ✓LOW 2.1EPSS 1.73%1 February 2008
CVE-2008-0521Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.91%31 January 2008
CVE-2008-0520Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) from_date or (2) to_date parameter to spy.php.EXPLOIT ✓HIGH 7.5EPSS 2.85%31 January 2008
CVE-2008-0519SQL injection vulnerability in index.php in the Atapin Jokes (com_jokes) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a CatView action.EXPLOIT ✓HIGH 7.5EPSS 1.01%31 January 2008
CVE-2008-0518SQL injection vulnerability in index.php in the Recipes (com_recipes) 1.00 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.EXPLOIT ✓HIGH 7.5EPSS 1.01%31 January 2008
CVE-2008-0517SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla! allows remote attackers to execute arbitrary SQL commands via the objid parameter in a contact showObject action.EXPLOIT ✓HIGH 7.5EPSS 1.01%31 January 2008
CVE-2008-0515SQL injection vulnerability in index.php in the musepoes (com_musepoes) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action.EXPLOIT ✓HIGH 7.5EPSS 0.97%31 January 2008
CVE-2008-0514SQL injection vulnerability in index.php in the Glossary (com_glossary) 2.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action.EXPLOIT ✓HIGH 7.5EPSS 0.97%31 January 2008
CVE-2008-0513Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓HIGH 7.8EPSS 3.50%31 January 2008
CVE-2008-0512SQL injection vulnerability in index.php in the fq (com_fq) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%31 January 2008
CVE-2008-0511SQL injection vulnerability in index.php in the MaMML (com_mamml) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%31 January 2008
CVE-2008-0510SQL injection vulnerability in index.php in the Newsletter (com_newsletter) component for Mambo 4.5 and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%31 January 2008
CVE-2008-0507SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 2.74%31 January 2008
CVE-2008-0506include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle,…EXPLOIT ✓MEDIUM 6.8EPSS 58.9%31 January 2008
CVE-2008-0504Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4)…EXPLOIT ✓MEDIUM 6.5EPSS 1.97%31 January 2008
CVE-2008-0503Eval injection vulnerability in admin/op/disp.php in Netwerk Smart Publisher 1.0.1 allows remote attackers to execute arbitrary PHP code via the filedata parameter.EXPLOIT ✓MEDIUM 6.8EPSS 23.2%31 January 2008
CVE-2008-0502PHP remote file inclusion vulnerability in templates/Official/part_userprofile.php in Connectix Boards 0.8.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the template_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.60%31 January 2008
CVE-2008-0501Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 5.8EPSS 1.85%30 January 2008
CVE-2008-0498SQL injection vulnerability in main_bigware_53.tpl.php in Bigware Shop 2.0 allows remote attackers to execute arbitrary SQL commands via the pollid parameter in a results action to main_bigware_53.php.EXPLOIT ✓HIGH 7.5EPSS 1.00%30 January 2008
CVE-2008-0497Cross-site scripting (XSS) vulnerability in action.php in Nucleus CMS 3.31 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, which is not quoted when processing PHP_SELF.EXPLOIT ✓MEDIUM 4.3EPSS 1.96%30 January 2008
CVE-2008-0496Cross-site scripting (XSS) vulnerability in index.php in AmpJuke 0.7.0 allows remote attackers to inject arbitrary web script or HTML via the limit parameter in a search action.EXPLOIT ✓MEDIUM 4.3EPSS 1.73%30 January 2008
CVE-2008-0493fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which triggers heap corruption.EXPLOIT ✓HIGH 9.3EPSS 8.68%30 January 2008
CVE-2008-0492Stack-based buffer overflow in the Persits.XUpload.2 ActiveX control in XUpload.ocx 3.0.0.4 and earlier in Persits XUpload 3.0 allows remote attackers to execute arbitrary code via a long argument to the AddFile method.EXPLOIT ×2 ✓MEDIUM 6.8EPSS 29.5%30 January 2008
CVE-2008-0491SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the album parameter.EXPLOIT ✓HIGH 7.5EPSS 5.55%30 January 2008
CVE-2008-0490SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 2.74%30 January 2008
CVE-2008-0489Directory traversal vulnerability in install.php in Clansphere 2007.4.4 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.72%30 January 2008
CVE-2008-0488Directory traversal vulnerability in tseekdir.cgi in VB Marketing allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the location parameter.EXPLOIT ✓HIGH 7.5EPSS 2.33%30 January 2008
CVE-2008-0487Multiple SQL injection vulnerabilities in login.asp in ASPired2Protect allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.EXPLOIT ✓HIGH 7.5EPSS 1.00%30 January 2008
CVE-2008-0481Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter in a save action.EXPLOIT ✓MEDIUM 5.0EPSS 3.88%29 January 2008
CVE-2008-0480Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter to (1) RTE_file_browser.asp or (2) file_browser.asp.EXPLOIT ✓MEDIUM 5.0EPSS 3.88%29 January 2008
CVE-2008-0479Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz NewsPad 1.02 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter.EXPLOIT ✓MEDIUM 5.0EPSS 3.88%29 January 2008
CVE-2008-0478Directory traversal vulnerability in index.php in SetCMS 3.6.5 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 1.85%29 January 2008
CVE-2008-0477Stack-based buffer overflow in the QMPUpgrade.Upgrade.1 ActiveX control in QMPUpgrade.dll 1.0.0.1 in Move Networks Upgrade Manager allows remote attackers to execute arbitrary code via a long first argument to the Upgrade method.EXPLOIT ✓HIGH 10.0EPSS 14.8%29 January 2008
CVE-2008-0474Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web script or HTML via the (1) showlink parameter to jsp/DiscoveryProfiles.jsp; the (2) attributeIDs, (3)…EXPLOITMEDIUM 4.3EPSS 1.45%29 January 2008
CVE-2008-0473RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors.EXPLOIT ✓MEDIUM 6.4EPSS 2.62%29 January 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.