Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,548 CVEs1,728 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 27 September 2026
25,049 results · page 310 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-0186 | Cross-site scripting (XSS) vulnerability in index.php in NetRisk 1.9.7 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to CVE-2008-0144. | EXPLOIT ✓MEDIUM 4.3EPSS 1.52% | 9 January 2008 |
| CVE-2008-0185 | SQL injection vulnerability in index.php in NetRisk 1.9.7 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the pid parameter in a profile page (possibly profile.php). | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 9 January 2008 |
| CVE-2008-0184 | Absolute path traversal vulnerability in index.php in Sys-Hotel on Line System allows remote attackers to read arbitrary files via an encoded "/" ("%2F") in the file parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 2.13% | 9 January 2008 |
| CVE-2007-5762 | NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by opening the \\.\nicm device and providing crafted kernel addresses via IOCTLs with the METHOD_NEITHER buffering mode. | EXPLOIT ✓HIGH 7.2EPSS 0.88% | 9 January 2008 |
| CVE-2008-0159 | SQL injection vulnerability in index.php in eggBlog 3.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the eggblogpassword parameter in a cookie. | EXPLOIT ✓MEDIUM 6.8EPSS 1.89% | 9 January 2008 |
| CVE-2008-0158 | Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.15% | 9 January 2008 |
| CVE-2008-0157 | SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_temp_id parameter in a cookie. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 9 January 2008 |
| CVE-2008-0155 | Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitrary web script or HTML via the c parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.08% | 9 January 2008 |
| CVE-2008-0154 | SQL injection vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to execute arbitrary SQL commands the c parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 9 January 2008 |
| CVE-2008-0153 | telnetd.exe in Pragma TelnetServer 7.0.4.589 allows remote attackers to cause a denial of service (process crash and resource exhaustion) via a crafted TELOPT PRAGMA LOGON telnet option, which triggers a NULL pointer dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 13.1% | 9 January 2008 |
| CVE-2008-0151 | Heap-based buffer overflow in Foxit WAC Server 2.1.0.910, 2.0 Build 3503, and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Telnet request with long options. | EXPLOIT ✓HIGH 10.0EPSS 8.51% | 9 January 2008 |
| CVE-2008-0149 | TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls the phpinfo function. | EXPLOIT ✓MEDIUM 5.0EPSS 7.54% | 9 January 2008 |
| CVE-2008-0148 | TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request. | EXPLOIT ✓HIGH 10.0EPSS 5.79% | 9 January 2008 |
| CVE-2008-0147 | SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter and possibly (2) username parameter in a Members action. | EXPLOIT ✓MEDIUM 6.8EPSS 0.91% | 9 January 2008 |
| CVE-2008-0146 | Cross-site scripting (XSS) vulnerability in the error page in W3-mSQL allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the top-level URI. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 8 January 2008 |
| CVE-2008-0144 | PHP remote file inclusion vulnerability in index.php in NetRisk 1.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 44.8% | 8 January 2008 |
| CVE-2008-0143 | PHP remote file inclusion vulnerability in common/db.php in samPHPweb, possibly 4.2.2 and others, as provided with SAM Broadcaster, allows remote attackers to execute arbitrary PHP code via a URL in the commonpath parameter. | EXPLOIT ✓HIGH 7.5EPSS 6.31% | 8 January 2008 |
| CVE-2008-0142 | Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL commands via the user_name parameter to actions.php, and unspecified other vectors. | EXPLOIT ✓MEDIUM 6.8EPSS 0.84% | 8 January 2008 |
| CVE-2008-0141 | actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to obtain access to any account via a lostpass action. | EXPLOIT ✓HIGH 7.5EPSS 4.31% | 8 January 2008 |
| CVE-2008-0140 | Directory traversal vulnerability in error.php in Uebimiau Webmail 2.7.10 and 2.7.2 allows remote authenticated users to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.4EPSS 2.30% | 8 January 2008 |
| CVE-2008-0139 | Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the template parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 22.2% | 8 January 2008 |
| CVE-2008-0138 | PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 4.78% | 8 January 2008 |
| CVE-2008-0137 | PHP remote file inclusion vulnerability in config.inc.php in SNETWORKS PHP CLASSIFIEDS 5.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.40% | 8 January 2008 |
| CVE-2008-0135 | Snitz Forums 2000 3.4.06 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum/snitz_forums_2000.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 2.45% | 8 January 2008 |
| CVE-2008-0133 | Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to cat_main.php and the (2) cat parameter to forum.php in a liste action. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 8 January 2008 |
| CVE-2008-0132 | Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message window and waiting for the administrator to click in this window before terminating the sshd.exe process, which allows remote attackers… | EXPLOIT ✓MEDIUM 5.0EPSS 9.00% | 8 January 2008 |
| CVE-2008-0129 | SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attackers to execute arbitrary SQL commands via the album_name parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.94% | 8 January 2008 |
| CVE-2007-6673 | Cross-site scripting (XSS) vulnerability in Makale Scripti allows remote attackers to inject arbitrary web script or HTML via the ara parameter to the default URI under Ara/ in a search action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.49% | 8 January 2008 |
| CVE-2007-6671 | SQL injection vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to execute arbitrary SQL commands via the Password parameter, a different product than CVE-2006-6021. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 8 January 2008 |
| CVE-2008-0100 | Stack-based buffer overflow in the Scene::errorf function in Scene.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via a long string in a .WRL file. | EXPLOIT ✓HIGH 7.5EPSS 7.56% | 8 January 2008 |
| CVE-2008-0099 | Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors. | EXPLOIT ✓MEDIUM 6.8EPSS 0.85% | 8 January 2008 |
| CVE-2008-0096 | Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to execute arbitrary code via a (1) a long username, which triggers an overflow in the log function; or (2) a long password. | EXPLOIT ✓HIGH 7.5EPSS 9.24% | 8 January 2008 |
| CVE-2008-0095 | The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revision 95946, and Appliance s800i 1.0.x before 1.0.3.4 allows remote… | EXPLOITMEDIUM 5.0EPSS 25.4% | 8 January 2008 |
| CVE-2008-0094 | Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary local files via a .. | EXPLOIT ×2 ✓MEDIUM 6.4EPSS 3.23% | 8 January 2008 |
| CVE-2007-6670 | SQL injection vulnerability in search.php in PHCDownload 1.1.0 allows remote attackers to execute arbitrary SQL commands via the string parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 8 January 2008 |
| CVE-2007-6669 | Cross-site scripting (XSS) vulnerability in search.php in PHCDownload 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the string parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 8 January 2008 |
| CVE-2007-6668 | admin/uploadgames.php in MySpace Content Zone (MCZ) 3.x does not require administrative privileges, which allows remote attackers to perform unrestricted file uploads, as demonstrated by uploading (1) a .php file and (2) a .php%00.jpeg file. | EXPLOIT ✓HIGH 7.5EPSS 6.36% | 8 January 2008 |
| CVE-2007-6667 | SQL injection vulnerability in faq.php in MyPHP Forum 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.96% | 4 January 2008 |
| CVE-2007-6666 | SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the albumnr parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.04% | 4 January 2008 |
| CVE-2007-6665 | SQL injection vulnerability in admin/login.asp in Netchemia oneSCHOOL allows remote attackers to execute arbitrary SQL commands via the txtLoginID parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.03% | 4 January 2008 |
| CVE-2007-6664 | SQL injection vulnerability in index.php in WebPortal CMS 0.6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.31% | 4 January 2008 |
| CVE-2007-6663 | SQL injection vulnerability in (1) Puarcade.php and (2) PUarcade.html.php in Pragmatic Utopia PU Arcade (com_puarcade) 2.0.3, 2.1.2, and 2.1.3 Beta component for Joomla! allows remote attackers to execute arbitrary SQL commands via the fid parameter to… | EXPLOIT ✓HIGH 7.5EPSS 2.05% | 4 January 2008 |
| CVE-2007-6658 | SQL injection vulnerability in admin.php/vars.php in CustomCMS (CCMS) 3.1 Demo allows remote attackers to execute arbitrary SQL commands via the p parameter in the Console page. | EXPLOIT ✓HIGH 7.5EPSS 1.17% | 4 January 2008 |
| CVE-2007-6657 | PHP remote file inclusion vulnerability in source/includes/load_forum.php in Mihalism Multi Forum Host 3.0.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mfh_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 6.03% | 4 January 2008 |
| CVE-2007-6656 | SQL injection vulnerability in content_css.php in the TinyMCE module for CMS Made Simple 1.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the templateid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.23% | 4 January 2008 |
| CVE-2007-6655 | PHP remote file inclusion vulnerability in includes/function.php in Kontakt Formular 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.76% | 4 January 2008 |
| CVE-2007-6654 | Buffer overflow in a certain ActiveX control in Macrovision InstallShield Update Service Web Agent 5.1.100.47363 allows remote attackers to execute arbitrary code via a long string in the ProductCode argument (second argument) to the DownloadAndExecute… | EXPLOIT ✓HIGH 9.3EPSS 5.55% | 4 January 2008 |
| CVE-2007-6653 | Directory traversal vulnerability in download.php in Mihalism Multi Host 2.0.7 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.26% | 4 January 2008 |
| CVE-2007-6652 | cpie.php in XCMS 1.83 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct direct static code injection attacks and execute arbitrary code via the testo_0 parameter in a cpie admin action to… | EXPLOIT ✓HIGH 7.5EPSS 4.15% | 4 January 2008 |
| CVE-2007-6651 | Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive information (script source code) via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.74% | 4 January 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.