Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,548 CVEs1,728 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 308 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-0390 | stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into online.db.txt via the X-Forwarded-For HTTP header in a stat action to index.php, and execute online.db.txt via a certain request to… | EXPLOIT ✓HIGH 7.5EPSS 2.32% | 23 January 2008 |
| CVE-2008-0388 | SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user parameter in a showprofile action to the default URI. | EXPLOIT ✓MEDIUM 6.8EPSS 3.49% | 23 January 2008 |
| CVE-2008-0384 | OpenBSD 4.2 allows local users to cause a denial of service (kernel panic) by calling the SIOCGIFRTLABEL IOCTL on an interface that does not have a route label, which triggers a NULL pointer dereference when the return value from the rtlabel_id2name… | EXPLOIT ✓MEDIUM 4.9EPSS 0.85% | 22 January 2008 |
| CVE-2008-0383 | Multiple SQL injection vulnerabilities in MyBB 1.2.10 and earlier allow remote moderators and administrators to execute arbitrary SQL commands via (1) the mergepost parameter in a do_mergeposts action, (2) rid parameter in an allreports action, or (3)… | EXPLOIT ✓HIGH 7.5EPSS 1.49% | 22 January 2008 |
| CVE-2008-0382 | Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 41.9% | 22 January 2008 |
| CVE-2008-0380 | Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property. | EXPLOIT ✓HIGH 10.0EPSS 12.7% | 22 January 2008 |
| CVE-2008-0379 | Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SelectedSession method,… | EXPLOIT ✓HIGH 9.3EPSS 8.56% | 22 January 2008 |
| CVE-2008-0376 | PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfile parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 31.5% | 22 January 2008 |
| CVE-2008-0372 | 8e6 R3000 Internet Filter 2.0.05.33, and other versions before 2.0.11, allows remote attackers to bypass intended restrictions via a fragmented HTTP request. | EXPLOIT ✓MEDIUM 5.0EPSS 3.22% | 22 January 2008 |
| CVE-2008-0371 | Multiple SQL injection vulnerabilities in aliTalk 1.9.1.1, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via (1) the mohit parameter to (a) inc/receivertwo.php; and allow remote attackers to… | EXPLOIT ✓MEDIUM 6.8EPSS 1.11% | 22 January 2008 |
| CVE-2008-0065 | Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles. | EXPLOIT ✓HIGH 10.0EPSS 61.3% | 22 January 2008 |
| CVE-2008-0365 | Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2)… | EXPLOIT ✓HIGH 7.2EPSS 0.97% | 18 January 2008 |
| CVE-2008-0364 | Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; on Windows allows remote attackers to cause a denial of service (application crash) via a long Unicode string… | EXPLOIT ✓MEDIUM 5.0EPSS 8.89% | 18 January 2008 |
| CVE-2007-5958 | X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different error messages depending on whether the filename exists. | EXPLOIT ✓MEDIUM 5.0EPSS 5.33% | 18 January 2008 |
| CVE-2008-0361 | Directory traversal vulnerability in agregar_info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 2.83% | 18 January 2008 |
| CVE-2008-0360 | Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (1) the blogid parameter to index.php, (2) the user parameter to action.php, or (3) the field parameter to… | EXPLOIT ✓HIGH 7.5EPSS 1.06% | 18 January 2008 |
| CVE-2008-0359 | Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin.php or (2) index.php in photo/. | EXPLOIT ✓MEDIUM 4.3EPSS 1.78% | 18 January 2008 |
| CVE-2008-0358 | SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.18% | 18 January 2008 |
| CVE-2008-0357 | Directory traversal vulnerability in pages/upload.php in Galaxyscripts Mini File Host 1.2.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 2.35% | 18 January 2008 |
| CVE-2008-0355 | SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action, a different vector than CVE-2007-2866. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 18 January 2008 |
| CVE-2008-0353 | SQL injection vulnerability in visualizza_tabelle.php in php-residence 0.7.2 and 1.0 allows remote attackers to execute arbitrary SQL commands via the cognome_cerca parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 18 January 2008 |
| CVE-2008-0352 | The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6 packet, possibly involving the Jumbo Payload hop-by-hop option (jumbogram). | EXPLOIT ✓HIGH 7.8EPSS 10.4% | 18 January 2008 |
| CVE-2008-0351 | admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php. | EXPLOIT ✓MEDIUM 5.0EPSS 2.33% | 18 January 2008 |
| CVE-2008-0350 | admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configuration changes. | EXPLOIT ✓HIGH 7.5EPSS 2.50% | 18 January 2008 |
| CVE-2008-0339 | Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB01. | EXPLOIT ✓HIGH 10.0EPSS 14.5% | 17 January 2008 |
| CVE-2008-0338 | Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary directories via a (1) .%2e (partially encoded dot dot) or (2) %2e%2e (encoded… | EXPLOIT ✓MEDIUM 5.0EPSS 2.81% | 17 January 2008 |
| CVE-2008-0337 | Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to execute arbitrary code via a long URI. | EXPLOIT ✓HIGH 7.5EPSS 5.36% | 17 January 2008 |
| CVE-2008-0334 | Cross-site scripting (XSS) vulnerability in pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote attackers to inject arbitrary web script or HTML via the L_PREF_NAME[855] parameter. | EXPLOIT ✓LOW 2.6EPSS 1.22% | 17 January 2008 |
| CVE-2008-0333 | Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 11.7% | 17 January 2008 |
| CVE-2008-0332 | Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.27% | 17 January 2008 |
| CVE-2008-0329 | LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_refuser.php in Admin/, which allows remote attackers to accept comments, delete comments, and delete articles via the id parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.10% | 17 January 2008 |
| CVE-2008-0328 | SQL injection vulnerability in page.php in FaScript FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 17 January 2008 |
| CVE-2008-0327 | SQL injection vulnerability in show.php in FaScript FaMp3 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 17 January 2008 |
| CVE-2008-0326 | SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to show.php. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 17 January 2008 |
| CVE-2008-0325 | SQL injection vulnerability in show.php in FaScript FaPersian Petition allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 17 January 2008 |
| CVE-2008-0324 | Cisco Systems VPN Client IPSec Driver (CVPNDRVA.sys) 5.0.02.0090 allows local users to cause a denial of service (crash) by calling the 0x80002038 IOCTL with a small size value, which triggers memory corruption. | EXPLOIT ✓MEDIUM 4.9EPSS 1.17% | 17 January 2008 |
| CVE-2007-6682 | Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifiers in the Connection parameter. | EXPLOIT ✓HIGH 7.5EPSS 15.1% | 17 January 2008 |
| CVE-2007-6681 | Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, and (3) Vplayer file. | EXPLOIT ✓HIGH 7.5EPSS 17.3% | 17 January 2008 |
| CVE-2008-0298 | KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a crafted web page, possibly involving a STYLE attribute of a DIV element. | EXPLOIT ✓MEDIUM 4.3EPSS 3.26% | 16 January 2008 |
| CVE-2008-0297 | PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its output. | EXPLOIT ✓MEDIUM 5.0EPSS 2.70% | 16 January 2008 |
| CVE-2008-0081 | Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different… | EXPLOIT ✓CRITICAL 9.8EPSS 57.9% | 16 January 2008 |
| CVE-2008-0296 | Heap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC Media Player 0.8.6d and earlier on Windows might allow remote RTSP servers to cause a denial of service (application crash) or execute arbitrary code via a long string. | EXPLOIT ✓HIGH 10.0EPSS 14.6% | 16 January 2008 |
| CVE-2008-0295 | Heap-based buffer overflow in modules/access/rtsp/real_sdpplin.c in the Xine library, as used in VideoLAN VLC Media Player 0.8.6d and earlier, allows user-assisted remote attackers to cause a denial of service (crash) or execute arbitrary code via long… | EXPLOIT ✓HIGH 8.5EPSS 11.1% | 16 January 2008 |
| CVE-2008-0291 | SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 16 January 2008 |
| CVE-2008-0290 | Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the selectskin parameter to an unspecified program, or (2) remote authenticated administrators to execute… | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 16 January 2008 |
| CVE-2008-0289 | PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remote attackers to execute arbitrary PHP code via a URL in the i parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.15% | 16 January 2008 |
| CVE-2008-0288 | Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands via the id, which is not properly handled in (1) classes/IADomain.php, (2) classes/IACollection.php, and (3) classes/IAUser.php, as… | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 16 January 2008 |
| CVE-2008-0287 | PHP remote file inclusion vulnerability in VisionBurst vcart 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php and (2) checkout.php. | EXPLOIT ✓MEDIUM 6.8EPSS 1.99% | 16 January 2008 |
| CVE-2008-0286 | SQL injection vulnerability in admin/login.php in Article Dashboard allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) password fields. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 16 January 2008 |
| CVE-2008-0283 | PHP remote file inclusion vulnerability in /aides/index.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.83% | 15 January 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.