Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,554 CVEs1,728 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 313 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-6493 | The IMWeb.IMWebControl.1 ActiveX control in IMWeb.dll 7.0.0.x, and possibly IMWebControl.dll, in iMesh 7.1.0.x and earlier allows remote attackers to execute arbitrary code via a certain argument to the SetHandler method. | EXPLOIT ×2 ✓HIGH 10.0EPSS 6.76% | 20 December 2007 |
| CVE-2007-6490 | Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a password via a certain changepass action to index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 0.88% | 20 December 2007 |
| CVE-2007-6489 | Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) gb_mail, (2) gb_name, and (3) gb_text parameters in a guestbook action to index.php, and… | EXPLOIT ✓HIGH 7.5EPSS 6.84% | 20 December 2007 |
| CVE-2007-6488 | Multiple PHP remote file inclusion vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the dir[classes] parameter to sitemap.xml.php or (2) the error parameter to errors.php. | EXPLOIT ✓MEDIUM 6.8EPSS 2.67% | 20 December 2007 |
| CVE-2007-6485 | Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute arbitrary PHP code via a URL in the fileOreonConf parameter to (1) MakeXML.php or (2) MakeXML4statusCounter.php in… | EXPLOIT ✓HIGH 7.5EPSS 10.8% | 20 December 2007 |
| CVE-2007-6483 | Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier versions, and Sentinel Keys Server 1.0.3 and possibly earlier versions, allows remote attackers to read arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 10.4% | 20 December 2007 |
| CVE-2007-6479 | Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double… | EXPLOIT ✓MEDIUM 4.9EPSS 1.57% | 20 December 2007 |
| CVE-2007-6478 | Stack-based buffer overflow in Rosoft Media Player 4.1.7, 4.1.8, and possibly earlier versions allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in a .M3U file. | EXPLOIT ✓MEDIUM 6.8EPSS 5.66% | 20 December 2007 |
| CVE-2007-6476 | GF-3XPLORER 2.4 allows remote attackers to obtain configuration information via a direct request to explorer/phpinfo.php, which calls the phpinfo function. | EXPLOIT ✓MEDIUM 5.0EPSS 2.67% | 20 December 2007 |
| CVE-2007-6475 | Multiple directory traversal vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.4EPSS 2.37% | 20 December 2007 |
| CVE-2007-6474 | Multiple cross-site scripting (XSS) vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to inject arbitrary web script or HTML via the newdir parameter to index_3x.php, and unspecified other vectors. | EXPLOIT ✓MEDIUM 4.3EPSS 1.52% | 20 December 2007 |
| CVE-2007-6473 | Heap-based buffer overflow in Texas Imperial Software WFTPD Pro Explorer 1.0 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command. | EXPLOIT ✓MEDIUM 5.8EPSS 3.11% | 20 December 2007 |
| CVE-2007-6472 | Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 allow (1) remote attackers to execute arbitrary SQL commands via the type parameter to search.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the… | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 20 December 2007 |
| CVE-2007-6335 | Integer overflow in libclamav in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MEW packed PE file, which triggers a heap-based buffer overflow. | EXPLOIT ✓HIGH 7.5EPSS 18.4% | 20 December 2007 |
| CVE-2007-6244 | Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote attackers to inject arbitrary web script or HTML via (1) a SWF file that uses the asfunction: protocol or (2) the… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 12.9% | 20 December 2007 |
| CVE-2007-5759 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ✓UnscoredEPSS — | 20 December 2007 |
| CVE-2007-6471 | Incomplete blacklist vulnerability in main.php in phPay 2.02.01 on Windows allows remote attackers to conduct directory traversal attacks and include and execute arbitrary local files via a ..\ (dot dot backslash) in the config parameter. | EXPLOIT ✓MEDIUM 5.8EPSS 2.30% | 20 December 2007 |
| CVE-2007-6470 | phpRPG 0.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read session ID values in files under tmp/, and then hijack sessions via PHPSESSID cookies. | EXPLOIT ✓MEDIUM 6.4EPSS 2.09% | 20 December 2007 |
| CVE-2007-6467 | SQL injection vulnerability in index.php in MKPortal 1.1 RC1 allows remote attackers to execute arbitrary SQL commands via the ida parameter in a gallery foto_show action. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 20 December 2007 |
| CVE-2007-6466 | Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the prod parameter in a details action, (2) the cat parameter in a browse list action, or (3) the group parameter… | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.18% | 20 December 2007 |
| CVE-2007-6464 | Multiple PHP remote file inclusion vulnerabilities in Form tools 1.5.0b allow remote attackers to execute arbitrary PHP code via a URL in the g_root_dir parameter to (1) admin_page_open.php and (2) client_page_open.php in global/templates/. | EXPLOIT ✓MEDIUM 6.8EPSS 2.07% | 20 December 2007 |
| CVE-2007-6462 | SQL injection vulnerability in fullnews.php in PHP Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 20 December 2007 |
| CVE-2007-6459 | Anon Proxy Server 0.100, and probably 0.101, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the host parameter to diagdns.php, and (2) the host parameter and possibly (3) the port parameter to diagconnect.php, a… | EXPLOIT ✓MEDIUM 6.8EPSS 2.87% | 20 December 2007 |
| CVE-2007-6458 | SQL injection vulnerability in shop/mainfile.php in 123tkShop 0.9.1 allows remote attackers to execute arbitrary SQL commands via a base64-encoded value of the admin parameter to shop/admin.php. | EXPLOIT ✓HIGH 7.5EPSS 2.03% | 20 December 2007 |
| CVE-2007-6457 | Stack-based buffer overflow in the webmail feature in SurgeMail 38k4 allows remote attackers to cause a denial of service (crash) via a long Host header. | EXPLOIT ✓MEDIUM 5.0EPSS 3.68% | 20 December 2007 |
| CVE-2007-6455 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Mambo 4.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Itemid parameter in a com_frontpage option and the (2) option parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 20 December 2007 |
| CVE-2007-6454 | Heap-based buffer overflow in the handshakeHTTP function in servhs.cpp in PeerCast 0.1217 and earlier, and SVN 344 and earlier, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long SOURCE request. | EXPLOIT ✓HIGH 10.0EPSS 16.8% | 20 December 2007 |
| CVE-2007-6453 | Directory traversal vulnerability in raidenhttpd-admin/workspace.php in RaidenHTTPD 2.0.19, when the WebAdmin function is enabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 10.0EPSS 5.19% | 20 December 2007 |
| CVE-2007-5863 | Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between the client and the server, using a modified distribution definition file with the "allow-external-scripts" option. | EXPLOIT ✓HIGH 9.3EPSS 23.0% | 19 December 2007 |
| CVE-2007-5849 | Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow. | EXPLOIT ✓HIGH 9.3EPSS 13.6% | 19 December 2007 |
| CVE-2007-3876 | Stack-based buffer overflow in SMB in Apple Mac OS X 10.4.11 allows local users to execute arbitrary code via (1) a long workgroup (-W) option to mount_smbfs or (2) an unspecified manipulation of the command line to smbutil. | EXPLOIT ✓MEDIUM 6.6EPSS 1.64% | 19 December 2007 |
| CVE-2007-5583 | Cisco IP Phone 7940 with firmware P0S3-08-7-00 allows remote attackers to cause a denial of service ("486 Busy" responses or device reboot) via a sequence of SIP INVITE transactions in which the Request-URI lacks a user name, a different vulnerability… | EXPLOIT ✓HIGH 7.8EPSS 5.99% | 18 December 2007 |
| CVE-2007-6414 | admin/administrator.php in Adult Script 1.6 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to bypass authentication and obtain administrative credentials via a direct request. | EXPLOIT ✓HIGH 7.5EPSS 4.22% | 17 December 2007 |
| CVE-2007-6405 | Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to download arbitrary CGI programs or scripts via a URI with an appended (1) '+' character, (2) '.' character, (3) %2e sequence (hex-encoded dot), or (4) hex-encoded… | EXPLOIT ✓MEDIUM 6.4EPSS 2.67% | 17 December 2007 |
| CVE-2007-6404 | Directory traversal vulnerability in Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URI. | EXPLOIT ✓MEDIUM 5.0EPSS 2.74% | 17 December 2007 |
| CVE-2007-6403 | Stack-based buffer overflow in Nullsoft Winamp 5.32 allows user-assisted remote attackers to execute arbitrary code via crafted unicode in a .mp4 file, with crafted tags, contained in a certain .rar archive, a related issue to CVE-2007-2498. | EXPLOIT ✓MEDIUM 6.8EPSS 3.44% | 17 December 2007 |
| CVE-2007-6402 | Stack-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote attackers to execute arbitrary code via a certain .mp4 file, possibly a related issue to CVE-2007-6401. | EXPLOIT ✓HIGH 9.3EPSS 5.80% | 17 December 2007 |
| CVE-2007-6401 | Stack-based buffer overflow in mplayer2.exe in Microsoft Windows Media Player (WMP) 6.4, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote attackers to execute arbitrary code via a certain .mp4 file, possibly a related issue to CVE-2007-6402. | EXPLOIT ✓HIGH 9.3EPSS 29.7% | 17 December 2007 |
| CVE-2007-6400 | Directory traversal vulnerability in download_file.php in PolDoc CMS (aka PDDMS) 0.96 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.83% | 17 December 2007 |
| CVE-2007-6399 | index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current user account by reading the password parameter value in the HTML source for the page generated by a profile action. | EXPLOIT ✓MEDIUM 6.5EPSS 2.07% | 17 December 2007 |
| CVE-2007-6398 | Flat PHP Board 1.2 and earlier allows remote attackers to bypass authentication and obtain limited access to an arbitrary user account via the fpb_username cookie. | EXPLOIT ✓MEDIUM 5.0EPSS 2.45% | 17 December 2007 |
| CVE-2007-6397 | Multiple directory traversal vulnerabilities in index.php in Flat PHP Board 1.2 and earlier allow remote attackers to (1) create arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.80% | 17 December 2007 |
| CVE-2007-6396 | Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and earlier allows remote attackers to inject arbitrary PHP code via the (1) username, (2) password, and (3) email parameters when registering a user account, which can be… | EXPLOIT ✓HIGH 7.5EPSS 2.41% | 17 December 2007 |
| CVE-2007-6395 | Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials via a direct request for the username php file for any user account in users/. | EXPLOIT ✓MEDIUM 5.0EPSS 6.24% | 17 December 2007 |
| CVE-2007-6394 | SQL injection vulnerability in index.php in Content Injector 1.53 allows remote attackers to execute arbitrary SQL commands via the id parameter in an expand action. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 17 December 2007 |
| CVE-2007-6393 | SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbitrary SQL commands via the id parameter in editalbum mode. | EXPLOIT ✓MEDIUM 6.5EPSS 0.90% | 17 December 2007 |
| CVE-2007-6392 | SQL injection vulnerability in DWdirectory 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameter to the /search URI. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 17 December 2007 |
| CVE-2007-6391 | SQL injection vulnerability in patch/comments.php in SH-News 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 17 December 2007 |
| CVE-2007-6387 | Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics AnswerWorks, and Intuit Clearly Bookkeeping, ProSeries, QuickBooks, Quicken, QuickTax, and TurboTax, allow remote… | EXPLOIT ✓HIGH 9.3EPSS 38.0% | 15 December 2007 |
| CVE-2007-6380 | Multiple SQL injection vulnerabilities in e-Xoops (exoops) 1.08, and 1.05 Rev 1 through 3, allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to (a) mylinks/ratelink.php, (b) adresses/ratefile.php, (c)… | EXPLOIT ×7 ✓HIGH 7.5EPSS 1.04% | 15 December 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.