Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,554 CVEs1,728 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 312 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-6565 | Multiple SQL injection vulnerabilities in Blakord Portal 1.3.A Beta and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to an arbitrary component. | EXPLOIT ✓HIGH 7.5EPSS 2.30% | 28 December 2007 |
| CVE-2007-6564 | Cross-site scripting (XSS) vulnerability in admin.php in Limbo CMS 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the com_option parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.72% | 28 December 2007 |
| CVE-2007-6561 | Multiple stack-based buffer overflows in PDFLib allow user-assisted remote attackers to execute arbitrary code via a long filename argument to the PDF_load_image function that results in an overflow in the pdc_fsearch_fopen function, and possibly other… | EXPLOIT ✓MEDIUM 5.7EPSS 6.67% | 28 December 2007 |
| CVE-2007-6560 | Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1) the newconfname parameter to profiles.php or (2) the conf parameter to index.php. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.96% | 28 December 2007 |
| CVE-2007-6559 | Multiple SQL injection vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to execute arbitrary SQL commands via (1) the from parameter to index.php or (2) the page parameter to update.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.20% | 28 December 2007 |
| CVE-2007-6558 | TotalPlayer 3.0 allows user-assisted remote attackers to cause a denial of service (application crash) via a large .m3u file. | EXPLOIT ✓MEDIUM 4.3EPSS 5.69% | 28 December 2007 |
| CVE-2007-6557 | Multiple SQL injection vulnerabilities in MeGaCheatZ 1.1 allow remote attackers to execute arbitrary SQL commands via the ItemID parameter to (1) comments.php, (2) view.php, (3) siteadmin/ViewItem.php, and unspecified other vectors. | EXPLOIT ✓HIGH 7.5EPSS 2.25% | 28 December 2007 |
| CVE-2007-6556 | Multiple SQL injection vulnerabilities in websihirbazi 5.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to default.asp in a news page action or (2) the pageid parameter to default.asp. | EXPLOIT ✓HIGH 7.5EPSS 2.07% | 28 December 2007 |
| CVE-2007-6555 | PHP remote file inclusion vulnerability in modules/mod_pxt_latest.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter. | EXPLOIT ✓HIGH 9.3EPSS 5.88% | 28 December 2007 |
| CVE-2007-6554 | Multiple directory traversal vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 7.38% | 28 December 2007 |
| CVE-2007-6553 | Multiple PHP remote file inclusion vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONF[app_root] parameter to (1) tcuser.class.php, (2) absencecount.inc.php, (3) avatar.inc.php,… | EXPLOIT ✓MEDIUM 6.8EPSS 3.69% | 28 December 2007 |
| CVE-2007-6552 | Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.0EPSS 1.64% | 28 December 2007 |
| CVE-2007-6551 | SQL injection vulnerability in showMsg.php in MailMachine Pro 2.2.4, and other versions before 2.2.6, allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 28 December 2007 |
| CVE-2007-6550 | form.php in PMOS Help Desk 2.4 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct eval injection attacks and execute arbitrary PHP code via the options array parameter. | EXPLOIT ✓HIGH 7.5EPSS 6.84% | 28 December 2007 |
| CVE-2007-6548 | Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary PHP code via the (1) header and (2) footer parameters to modules/system/admin.php in a meta-generator action, (3)… | EXPLOIT ✓HIGH 7.5EPSS 7.77% | 28 December 2007 |
| CVE-2007-6547 | RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session. | EXPLOIT ✓MEDIUM 6.8EPSS 2.41% | 28 December 2007 |
| CVE-2007-6546 | RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id. | EXPLOIT ✓MEDIUM 6.4EPSS 2.70% | 28 December 2007 |
| CVE-2007-6545 | Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) the subject parameter to modules/news/submit.php; (2) the PATH_INFO to modules/news/index.php, possibly… | EXPLOIT ✓MEDIUM 4.3EPSS 4.11% | 28 December 2007 |
| CVE-2007-6544 | Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter to (1) brokenfile.php, (2) visit.php, or (3) ratefile.php in modules/mydownloads/; or (4) ratelink.php, (5)… | EXPLOIT ×2 ✓HIGH 7.5EPSS 4.26% | 28 December 2007 |
| CVE-2007-6543 | SQL injection vulnerability in suggest-link.php in eSyndiCat Link Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 28 December 2007 |
| CVE-2007-6542 | PHP remote file inclusion vulnerability in admin/frontpage_right.php in Arcadem LE 2.04 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage parameter. | EXPLOIT ✓HIGH 7.5EPSS 5.99% | 27 December 2007 |
| CVE-2007-6539 | PHP local file inclusion vulnerability in index.php in IDevspot iSupport 1.8 allows remote attackers to include local files via the include_file parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.13% | 27 December 2007 |
| CVE-2007-6538 | SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.84% | 27 December 2007 |
| CVE-2007-6537 | Stack-based buffer overflow in the zfile_gunzip function in zfile.c in WinUAE 1.4.4 and earlier allows user-assisted remote attackers to execute arbitrary code via a long filename in a gzipped archive, such as a (1) gz, (2) adz, (3) roz, or (4) hdz… | EXPLOIT ✓MEDIUM 6.8EPSS 6.34% | 27 December 2007 |
| CVE-2007-6533 | Buffer overflow in Zoom Player 6.00 beta 2 and earlier allows user-assisted remote attackers to execute arbitrary code via an HTTP link to a PLS file in a crafted ZPL file, which causes an overflow in Unicode handling when generating an error message. | EXPLOIT ✓HIGH 7.5EPSS 12.3% | 27 December 2007 |
| CVE-2007-6530 | Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote attackers to execute arbitrary code via a long… | EXPLOIT ×2 ✓HIGH 9.3EPSS 36.8% | 27 December 2007 |
| CVE-2007-6528 | Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a .. | EXPLOITMEDIUM 5.0EPSS 9.27% | 27 December 2007 |
| CVE-2007-4474 | Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an… | EXPLOIT ×4 ✓HIGH 9.3EPSS 44.2% | 27 December 2007 |
| CVE-2007-6518 | Multiple SQL injection vulnerabilities in search.php in WoltLab Burning Board (wBB) Lite 1.0.2 pl3e allow remote attackers to execute arbitrary SQL commands via the (1) showposts, (2) sortby, and (3) sortorder parameters. | EXPLOIT ✓HIGH 7.5EPSS 2.26% | 24 December 2007 |
| CVE-2007-6516 | Buffer overflow in RavWare Software MAS Flic ActiveX Control (masflc.ocx) 1.0.0.1 allows remote attackers to execute arbitrary code via a long FileName property. | EXPLOIT ✓MEDIUM 6.8EPSS 3.72% | 21 December 2007 |
| CVE-2007-6515 | support/dispatch.cgi in SiteScape Forum allows remote attackers to execute arbitrary TCL code via code separator characters in the query string. | EXPLOIT ×2 ✓HIGH 7.5EPSS 7.93% | 21 December 2007 |
| CVE-2007-6514 | Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by… | EXPLOIT ✓MEDIUM 4.3EPSS 38.0% | 21 December 2007 |
| CVE-2007-6513 | HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method. | EXPLOIT ✓MEDIUM 4.3EPSS 2.32% | 21 December 2007 |
| CVE-2007-6510 | Multiple stack-based buffer overflows in ProWizard 4 PC (prowiz) 1.62 and earlier allow remote attackers to execute arbitrary code via a crafted file to the (1) AMOS-MusicBank, (2) FuzzacPacker, and (3) QuadraComposer rippers; and (4) have an unknown… | EXPLOIT ✓MEDIUM 6.8EPSS 3.59% | 21 December 2007 |
| CVE-2007-6509 | Unspecified vulnerability in Appian Enterprise Business Process Management (BPM) Suite 5.6 SP1 allows remote attackers to cause a denial of service via a crafted packet to port 5400/tcp. | EXPLOIT ✓HIGH 7.8EPSS 55.2% | 21 December 2007 |
| CVE-2007-6508 | Directory traversal vulnerability in view.php in xeCMS 1.0 allows remote attackers to read arbitrary files via a ..%2F (dot dot slash) in the list parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.89% | 21 December 2007 |
| CVE-2007-4567 | The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, which allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic)… | EXPLOIT ✓HIGH 7.8EPSS 14.3% | 21 December 2007 |
| CVE-2007-6506 | The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method,… | EXPLOIT ✓HIGH 9.3EPSS 16.3% | 20 December 2007 |
| CVE-2007-6341 | Net/DNS/RR/A.pm in Net::DNS 0.60 build 654, as used in packages such as SpamAssassin and OTRS, allows remote attackers to cause a denial of service (program "croak") via a crafted DNS response. | EXPLOIT ✓MEDIUM 5.0EPSS 9.55% | 20 December 2007 |
| CVE-2007-6504 | Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the headers of arbitrary hosts via an unspecified parameter. | EXPLOIT ✓MEDIUM 5.5EPSS 2.19% | 20 December 2007 |
| CVE-2007-6503 | Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arbitrary plan via a request to hosting/importhostingplans.asp; or (2) change an arbitrary plan via a request to… | EXPLOIT ✓MEDIUM 5.5EPSS 2.24% | 20 December 2007 |
| CVE-2007-6502 | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel parameters to fp2000/NEWSRVR.asp, which discloses usernames; and (2) certain XML HTTP requests to… | EXPLOIT ✓MEDIUM 5.5EPSS 2.75% | 20 December 2007 |
| CVE-2007-6501 | Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type" via a request to adminsettings/choosetranstype.asp. | EXPLOIT ✓MEDIUM 5.5EPSS 2.41% | 20 December 2007 |
| CVE-2007-6500 | Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to delete "gateway information" via a request to OpenApi/GatewayVariables.asp. | EXPLOIT ✓MEDIUM 4.9EPSS 4.48% | 20 December 2007 |
| CVE-2007-6499 | Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage extensions of an arbitrary account via a request to fp2002/UNINSTAL.asp with a "host id (IIS) value." | EXPLOIT ✓MEDIUM 5.5EPSS 2.53% | 20 December 2007 |
| CVE-2007-6498 | Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) email and (2) loginname parameters to Hosting/Addreseller.asp, (3) the sortfield… | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 20 December 2007 |
| CVE-2007-6497 | Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp with modified loginname and email parameters; and (2) allows remote authenticated users to change a… | EXPLOIT ✓HIGH 7.5EPSS 2.96% | 20 December 2007 |
| CVE-2007-6496 | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp with the loginname and password parameters set, when preceded by certain requests to hosting/default.asp and… | EXPLOIT ✓MEDIUM 6.8EPSS 2.68% | 20 December 2007 |
| CVE-2007-6495 | inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1) db, (2) www, (3) Special, and (4) log at arbitrary locations under the web root via a modified Dirroot… | EXPLOIT ✓MEDIUM 6.5EPSS 4.37% | 20 December 2007 |
| CVE-2007-6494 | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username in the reseller parameter, followed by a request to AdminSettings/displays.asp with the DecideAction… | EXPLOIT ✓HIGH 10.0EPSS 11.8% | 20 December 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.