SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,548 CVEs1,728 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026

25,049 results · page 309 of 501

CVESummaryPriorityPublished
CVE-2008-0282SQL injection vulnerability in welcome/inscription.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary SQL commands via the mail parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%15 January 2008
CVE-2008-0281SQL injection vulnerability in liste.php in ID-Commerce 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idFamille parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%15 January 2008
CVE-2008-0280SQL injection vulnerability in index.php in MTCMS 2.0 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the (1) a or (2) cid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.15%15 January 2008
CVE-2008-0279SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitrary SQL commands via the topic parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%15 January 2008
CVE-2008-0278SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a sm_window action.EXPLOIT ✓MEDIUM 6.0EPSS 1.64%15 January 2008
CVE-2008-0270SQL injection vulnerability in index.php in TaskFreak!EXPLOIT ✓MEDIUM 6.0EPSS 0.84%15 January 2008
CVE-2008-0268Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.51%15 January 2008
CVE-2008-0267Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) status, (2) sort, and (3) way parameters to search.php; and allow remote authenticated administrators to execute…EXPLOIT ×2 ✓HIGH 7.5EPSS 1.15%15 January 2008
CVE-2008-0266Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote attackers to change the administrative password and possibly perform other administrative tasks.EXPLOIT ✓LOW 2.6EPSS 0.44%15 January 2008
CVE-2008-0265Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP 9.4.3 allow remote attackers to inject arbitrary web script or HTML via the SearchString parameter to (1) list_system.jsp, (2)…EXPLOIT ✓MEDIUM 4.3EPSS 3.48%15 January 2008
CVE-2008-0262SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute arbitrary SQL commands via the articlecat parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97%15 January 2008
CVE-2008-0260minimal Gallery 0.8 allows remote attackers to obtain configuration information via a direct request to php_info.php, which calls the phpinfo function.EXPLOIT ✓MEDIUM 5.0EPSS 1.62%15 January 2008
CVE-2008-0259Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 6.4EPSS 2.26%15 January 2008
CVE-2008-0258Cross-site scripting (XSS) vulnerability in index.php in PHP Running Management (phpRunMan) before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.55%15 January 2008
CVE-2008-0256Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) Imgbig.asp, (b) thumb.asp, and (c) thumbricerca.asp and the (2) ricerca parameter to…EXPLOIT ✓HIGH 7.5EPSS 0.97%15 January 2008
CVE-2008-0255SQL injection vulnerability in archive.php in iGaming 1.5, and 1.3.1 and earlier, allows remote attackers to execute arbitrary SQL commands via the section parameter.EXPLOIT ✓HIGH 7.5EPSS 2.00%15 January 2008
CVE-2008-0254SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the userName parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.91%15 January 2008
CVE-2008-0253SQL injection vulnerability in full_text.php in Binn SBuilder allows remote attackers to execute arbitrary SQL commands via the nid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%15 January 2008
CVE-2008-0251Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown vectors.EXPLOIT ✓HIGH 10.0EPSS 3.54%12 January 2008
CVE-2008-0250Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with a long Project line.EXPLOIT ×2 ✓HIGH 9.3EPSS 16.9%12 January 2008
CVE-2008-0249PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the credentials in an error message if a call to /usr/bin/mysqldump fails.EXPLOIT ✓MEDIUM 5.0EPSS 2.59%12 January 2008
CVE-2008-0248Buffer overflow in an ActiveX control in ccpm_0237.dll for StreamAudio ChainCast ProxyManager allows remote attackers to execute arbitrary code via a long URL argument to the InternalTuneIn method.EXPLOIT ✓HIGH 9.3EPSS 10.7%12 January 2008
CVE-2008-0246admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action.EXPLOIT ✓HIGH 10.0EPSS 3.53%12 January 2008
CVE-2008-0245admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action.EXPLOIT ✓HIGH 7.5EPSS 2.33%12 January 2008
CVE-2008-0244SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other unspecified commands, which are executed when MaxDB invokes cons.exe.EXPLOIT ✓HIGH 10.0EPSS 80.3%12 January 2008
CVE-2008-0123Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter.EXPLOIT ✓MEDIUM 4.3EPSS 3.95%12 January 2008
CVE-2008-0240/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."EXPLOIT ✓MEDIUM 4.3EPSS 5.84%11 January 2008
CVE-2008-0239Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote attackers to inject arbitrary HTML or web script via the (1) cntry or lang parameters to /idm/login.jsp, (2)…EXPLOIT ×3 ✓MEDIUM 4.3EPSS 5.70%11 January 2008
CVE-2008-0237The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure SaveFile method.EXPLOIT ✓MEDIUM 6.8EPSS 20.5%11 January 2008
CVE-2008-0236An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary commands by invoking the DoCmd method.EXPLOIT ✓MEDIUM 5.8EPSS 17.4%11 January 2008
CVE-2008-0234Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404…EXPLOIT ×2 ✓HIGH 9.3EPSS 12.4%11 January 2008
CVE-2008-0233Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.EXPLOIT ✓HIGH 7.5EPSS 2.21%11 January 2008
CVE-2008-0232Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to index.php, or the (2) f or t parameters to forums/index.php.EXPLOIT ✓HIGH 7.5EPSS 0.97%11 January 2008
CVE-2008-0231Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange Cutout, (4) Lonely Maple, (5) Endless, (6) Classic Theme, and (7) Music Theme webpage templates allow remote attackers to include and…EXPLOIT ✓HIGH 7.5EPSS 2.51%11 January 2008
CVE-2008-0230PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via a URL in the php121dir parameter.EXPLOIT ✓HIGH 7.5EPSS 2.59%11 January 2008
CVE-2008-0226Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in…EXPLOIT ×3 ✓HIGH 7.5EPSS 91.6%10 January 2008
CVE-2008-0225Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstract attribute in an RTSP session, related to the rmff_dump_header function…EXPLOIT ✓MEDIUM 6.4EPSS 15.0%10 January 2008
CVE-2008-0224SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrary SQL commands via the Client-Ip parameter.EXPLOIT ✓HIGH 7.5EPSS 2.00%10 January 2008
CVE-2008-0222Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors.EXPLOIT ✓HIGH 7.5EPSS 7.70%10 January 2008
CVE-2008-0221Directory traversal vulnerability in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allows remote attackers to execute arbitrary programs via a ..\ (dot dot backslash) in the second…EXPLOIT ✓HIGH 9.3EPSS 5.73%10 January 2008
CVE-2008-0220Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allow remote attackers to execute arbitrary code via a long string in the (1) second or (2) fourth…EXPLOIT ×2 ✓HIGH 7.5EPSS 15.7%10 January 2008
CVE-2008-0219SQL injection vulnerability in soporte_horizontal_w.php in PHP Webquest 2.6 allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter, a different vector than CVE-2007-4920.EXPLOIT ✓HIGH 7.5EPSS 0.97%10 January 2008
CVE-2008-0218Cross-site scripting (XSS) vulnerability in admin/index.html in Merak IceWarp Mail Server allows remote attackers to inject arbitrary web script or HTML via the message parameter.EXPLOIT ✓MEDIUM 4.3EPSS 2.97%10 January 2008
CVE-2008-0210Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting.EXPLOIT ✓MEDIUM 6.4EPSS 2.13%10 January 2008
CVE-2008-0207Multiple cross-site scripting (XSS) vulnerabilities in PRO-Search 0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prot, (2) host, (3) path, (4) name, (5) ext, (6) size, (7) search_days, or (8) show_page…EXPLOIT ✓MEDIUM 4.3EPSS 1.91%10 January 2008
CVE-2008-0193Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows remote attackers to inject arbitrary web script or HTML via the backup parameter in a wp-db-backup.php action to…EXPLOIT ✓MEDIUM 4.3EPSS 3.97%10 January 2008
CVE-2008-0192Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the popuptitle parameter to (1) wp-admin/post.php or (2) wp-admin/page-new.php.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 5.07%10 January 2008
CVE-2008-0190Multiple cross-site scripting (XSS) vulnerabilities in templates/example_template.php in AwesomeTemplateEngine allow remote attackers to inject arbitrary web script or HTML via the (1) data[title], (2) data[message], (3) data[table][1][item], (4)…EXPLOIT ✓MEDIUM 4.3EPSS 1.77%10 January 2008
CVE-2008-0127The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long initial authentication packet.EXPLOIT ✓HIGH 8.8EPSS 8.56%10 January 2008
CVE-2008-0187SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the songid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%9 January 2008

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.