Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,841 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
17,392 results · page 280 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-4388 | The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly validate downloaded files, which allows remote attackers to execute arbitrary code via the installAppMgr method and… | EXPLOIT ✓HIGH 9.3EPSS 37.7% | 20 January 2009 |
| CVE-2009-0174 | Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in the HREF attribute of a REF element in a .asx file. | EXPLOIT ×4 ✓HIGH 9.3EPSS 11.7% | 20 January 2009 |
| CVE-2009-0133 | Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564. | EXPLOIT ×7 ✓HIGH 10.0EPSS 67.0% | 15 January 2009 |
| CVE-1999-1593 | Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch registration that causes WINS to change the domain controller to point to a malicious server. | HIGH 7.6EPSS 18.1% | 15 January 2009 |
| CVE-2003-1567 | The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or… | HIGH 7.5EPSS 25.2% | 15 January 2009 |
| CVE-2003-1566 | Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection. | EXPLOIT ✓MEDIUM 5.0EPSS 28.1% | 15 January 2009 |
| CVE-2009-0119 | Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .chm file. | EXPLOIT ✓HIGH 10.0EPSS 36.7% | 14 January 2009 |
| CVE-2008-4835 | SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets"… | CRITICAL 9.8EPSS 44.9% | 14 January 2009 |
| CVE-2008-4834 | Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans… | HIGH 10.0EPSS 45.8% | 14 January 2009 |
| CVE-2008-5457 | Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity,… | EXPLOIT ×2 ✓HIGH 10.0EPSS 61.3% | 14 January 2009 |
| CVE-2008-5448 | Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2008-5444 and… | HIGH 10.0EPSS 40.5% | 14 January 2009 |
| CVE-2008-5444 | Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2008-5448 and… | EXPLOIT ✓HIGH 10.0EPSS 60.6% | 14 January 2009 |
| CVE-2008-5440 | Unspecified vulnerability in the TimesTen Data Server component in Oracle Database 7.0.5.0.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | HIGH 7.5EPSS 11.9% | 14 January 2009 |
| CVE-2008-3979 | Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. | EXPLOIT ✓MEDIUM 5.5EPSS 32.4% | 14 January 2009 |
| CVE-2008-5517 | The web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related to (1) git_snapshot and (2) git_object. | EXPLOITHIGH 7.5EPSS 11.9% | 13 January 2009 |
| CVE-2008-5887 | phplist before 2.10.8 allows remote attackers to include files via unknown vectors, related to a "local file include vulnerability." | MEDIUM 5.0EPSS 11.3% | 12 January 2009 |
| CVE-2009-0103 | Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) apps_path[plug] parameter to plugin/gateway/gnokii/init.php, the (2) apps_path[themes] parameter to… | EXPLOIT ✓HIGH 7.5EPSS 10.1% | 9 January 2009 |
| CVE-2009-0043 | The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, which allows remote attackers to execute arbitrary commands via unspecified vectors. | EXPLOIT ✓HIGH 10.0EPSS 53.3% | 8 January 2009 |
| CVE-2008-0067 | Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) long string parameters to the OpenView5.exe CGI program; (2) a long string parameter to the… | EXPLOIT ✓HIGH 10.0EPSS 63.4% | 8 January 2009 |
| CVE-2009-0065 | Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.28-git8 allows remote attackers to have an unknown impact via an FWD-TSN (aka FORWARD-TSN) chunk with a large… | EXPLOIT ✓HIGH 10.0EPSS 16.7% | 7 January 2009 |
| CVE-2008-5828 | Microsoft Windows Live Messenger Client 8.5.1 and earlier, when MSN Protocol Version 15 (MSNP15) is used over a NAT session, allows remote attackers to discover intranet IP addresses and port numbers by reading the (1) IPv4InternalAddrsAndPorts, (2)… | MEDIUM 5.0EPSS 14.3% | 2 January 2009 |
| CVE-2008-5793 | Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a)… | EXPLOIT ✓MEDIUM 6.8EPSS 24.4% | 31 December 2008 |
| CVE-2008-5790 | Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) add.php… | EXPLOIT ✓HIGH 7.5EPSS 36.4% | 31 December 2008 |
| CVE-2008-5789 | Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) mosConfig_absolute_path parameter to (a)… | EXPLOIT ✓HIGH 7.5EPSS 45.0% | 31 December 2008 |
| CVE-2008-5764 | PHP remote file inclusion vulnerability in calendar.php in WorkSimple 1.2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter. | EXPLOIT ✓HIGH 9.3EPSS 45.4% | 30 December 2008 |
| CVE-2008-5763 | PHP remote file inclusion vulnerability in slogin_lib.inc.php in Simple Text-File Login Script (SiTeFiLo) 1.0.6 allows remote attackers to execute arbitrary PHP code via a URL in the slogin_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 39.2% | 30 December 2008 |
| CVE-2008-5750 | Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI. | EXPLOIT ✓MEDIUM 6.8EPSS 21.4% | 29 December 2008 |
| CVE-2008-5748 | Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) module parameters. | EXPLOIT ✓HIGH 8.1EPSS 10.4% | 29 December 2008 |
| CVE-2008-5745 | Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260, allows remote attackers to cause a denial of service (application crash) via a crafted (1) WAV, (2) SND, or (3)… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 21.4% | 29 December 2008 |
| CVE-2008-5732 | Unrestricted file upload vulnerability in lib/image_upload.php in KafooeyBlog 1.55b allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file. | EXPLOIT ✓HIGH 7.5EPSS 13.1% | 26 December 2008 |
| CVE-2008-5722 | Buffer overflow in SAWStudio 3.9i allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long SAWSTUDIO PREFERENCES STRUCT value in a .prf (preferences) file. | EXPLOIT ✓HIGH 10.0EPSS 14.9% | 26 December 2008 |
| CVE-2008-5711 | Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary code via a long FileMask property value. | EXPLOIT ×3 ✓HIGH 9.3EPSS 32.7% | 24 December 2008 |
| CVE-2008-5695 | wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary… | EXPLOIT ✓HIGH 8.5EPSS 12.0% | 19 December 2008 |
| CVE-2008-5692 | Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with… | EXPLOIT ✓MEDIUM 5.0EPSS 12.6% | 19 December 2008 |
| CVE-2008-5666 | WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequence of FTP sessions that include an invalid "NLST -1" command. | EXPLOIT ×2 ✓LOW 3.5EPSS 20.6% | 19 December 2008 |
| CVE-2008-5664 | Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows remote attackers to execute arbitrary code via a crafted playlist (PLA) file. | EXPLOIT ×2 ✓HIGH 9.3EPSS 36.2% | 19 December 2008 |
| CVE-2008-5499 | Unspecified vulnerability in Adobe Flash Player for Linux 10.0.12.36, and 9.0.151.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file. | EXPLOIT ✓HIGH 9.3EPSS 79.4% | 18 December 2008 |
| CVE-2008-5626 | XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument to the NLST command, as demonstrated by a -1 argument. | EXPLOIT ×2 ✓MEDIUM 4.0EPSS 35.9% | 17 December 2008 |
| CVE-2008-5619 | html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that… | EXPLOIT ×2 ✓HIGH 10.0EPSS 58.6% | 17 December 2008 |
| CVE-2008-5081 | The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause a denial of service (crash) via a crafted mDNS packet with a source port of 0, which triggers an… | EXPLOIT ✓MEDIUM 5.0EPSS 59.2% | 17 December 2008 |
| CVE-2008-5587 | Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 12.9% | 16 December 2008 |
| CVE-2008-5556 | The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks… | MEDIUM 4.3EPSS 11.2% | 12 December 2008 |
| CVE-2008-5555 | Microsoft Internet Explorer 8.0 Beta 2 relies on the XDomainRequestAllowed HTTP header to authorize data exchange between domains, which allows remote attackers to bypass the product's XSS Filter protection mechanism, and conduct XSS and cross-domain… | MEDIUM 4.3EPSS 12.5% | 12 December 2008 |
| CVE-2008-5554 | The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not properly handle some HTTP headers that appear after a CRLF sequence in a URI, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS or redirection attacks,… | MEDIUM 4.3EPSS 14.5% | 12 December 2008 |
| CVE-2008-5553 | The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 disables itself upon encountering a certain X-XSS-Protection HTTP header, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting this header… | MEDIUM 4.3EPSS 11.6% | 12 December 2008 |
| CVE-2008-5552 | The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks via a CRLF sequence in conjunction with a crafted Content-Type header, as demonstrated by a header with a… | MEDIUM 4.3EPSS 11.6% | 12 December 2008 |
| CVE-2008-5551 | The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS… | EXPLOIT ✓MEDIUM 4.3EPSS 14.0% | 12 December 2008 |
| CVE-2008-5539 | RISING Antivirus 21.06.31.00 and possibly 20.61.42.00, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the… | HIGH 9.3EPSS 10.3% | 12 December 2008 |
| CVE-2008-5492 | Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX Control allows remote attackers to execute arbitrary code via a long first argument to the OpenPDF method. | EXPLOIT ×3 ✓HIGH 9.3EPSS 35.3% | 12 December 2008 |
| CVE-2008-5424 | The MimeOleClearDirtyTree function in InetComm.dll in Microsoft Outlook Express 6.00.2900.5512 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;"… | MEDIUM 4.3EPSS 12.3% | 11 December 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.