Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,554 CVEs1,728 in CISA KEV17,265 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 314 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-6379 | BadBlue 2.72b and earlier allows remote attackers to obtain sensitive information via an invalid browse parameter, which reveals the installation path in an error message. | EXPLOIT ✓MEDIUM 5.0EPSS 3.28% | 15 December 2007 |
| CVE-2007-6378 | Directory traversal vulnerability in upload.dll in BadBlue 2.72b and earlier allows remote attackers to create or overwrite arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 3.21% | 15 December 2007 |
| CVE-2007-6377 | Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attackers to execute arbitrary code via a long query string. | EXPLOIT ×3 ✓HIGH 7.5EPSS 66.4% | 15 December 2007 |
| CVE-2007-6376 | Directory traversal vulnerability in autohtml.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.59% | 15 December 2007 |
| CVE-2007-6375 | Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to wiki/list_pages.php and the (2) highlight parameter to search/index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 15 December 2007 |
| CVE-2007-6374 | Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) users/register.php or (2) search/index.php, or an editcomments action in (3)… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 2.21% | 15 December 2007 |
| CVE-2007-6369 | Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 7.52% | 15 December 2007 |
| CVE-2007-6368 | Directory traversal vulnerability in index.php in ezContents 1.4.5 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.82% | 15 December 2007 |
| CVE-2007-6367 | Multiple cross-site scripting (XSS) vulnerabilities in the guestbook in SineCMS 2.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username (user) or (2) comment (commento) field, different vectors than… | EXPLOIT ✓MEDIUM 4.3EPSS 4.25% | 15 December 2007 |
| CVE-2007-6366 | Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to mods/Calendar/index.php, accessed through a Calendar info action to mods.php; the id parameter to… | EXPLOIT ✓HIGH 7.5EPSS 2.36% | 15 December 2007 |
| CVE-2007-6362 | SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an inline page action. | EXPLOIT ✓HIGH 7.5EPSS 2.07% | 15 December 2007 |
| CVE-2007-6359 | The cs_validate_page function in bsd/kern/ubc_subr.c in the xnu kernel 1228.0 and earlier in Apple Mac OS X 10.5.1 allows local users to cause a denial of service (failed assertion and system crash) via a crafted signed Mach-O binary that causes the… | EXPLOIT ✓MEDIUM 4.9EPSS 1.01% | 15 December 2007 |
| CVE-2007-6347 | PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Shop Evaluation 3.3.2, and (4) Shop Free 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the root_folder_path… | EXPLOIT ✓MEDIUM 6.8EPSS 7.06% | 13 December 2007 |
| CVE-2007-6344 | Directory traversal vulnerability in modules/cms/index.php in Mcms Easy Web Make 1.3, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 6.09% | 13 December 2007 |
| CVE-2007-6204 | Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote attackers to execute arbitrary code via unspecified long arguments to (1) ovlogin.exe, (2) OpenView5.exe, (3) snmpviewer.exe, and (4)… | EXPLOIT ×2 ✓HIGH 10.0EPSS 69.6% | 13 December 2007 |
| CVE-2007-6015 | Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled, allows remote attackers to execute arbitrary code via a GETDC mailslot request composed of a long GETDC string… | EXPLOIT ✓HIGH 9.3EPSS 27.5% | 13 December 2007 |
| CVE-2007-6333 | The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, allows remote attackers to read arbitrary registry values via the… | EXPLOIT ✓MEDIUM 5.8EPSS 8.68% | 13 December 2007 |
| CVE-2007-6332 | The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, on Microsoft Windows before Vista allows remote attackers to create… | EXPLOIT ✓HIGH 9.3EPSS 8.43% | 13 December 2007 |
| CVE-2007-6331 | Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier allows remote attackers to… | EXPLOIT ✓HIGH 9.3EPSS 30.1% | 13 December 2007 |
| CVE-2007-6327 | Buffer overflow in a certain ActiveX control in Online Media Technologies AVSMJPEGFILE.DLL 1.1.1.102 allows remote attackers to execute arbitrary code via a long first argument to the CreateStill method. | EXPLOIT ✓HIGH 7.5EPSS 11.4% | 13 December 2007 |
| CVE-2007-6326 | Sergey Lyubka Simple HTTPD (shttpd) 1.3 on Windows allows remote attackers to cause a denial of service via a request that includes an MS-DOS device name, as demonstrated by the /aux URI. | EXPLOIT ✓MEDIUM 5.0EPSS 7.25% | 13 December 2007 |
| CVE-2007-6325 | PHP remote file inclusion vulnerability in adminbereich/designconfig.php in Fastpublish CMS 1.9999 allows remote attackers to execute arbitrary PHP code via a URL in the config[fsBase] parameter, a different vector than CVE-2006-2726. | EXPLOIT ✓MEDIUM 6.8EPSS 10.6% | 13 December 2007 |
| CVE-2007-6324 | PHP remote file inclusion vulnerability in head.php in CityWriter 0.9.7 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 5.27% | 13 December 2007 |
| CVE-2007-6323 | Multiple directory traversal vulnerabilities in MMS Gallery PHP 1.0 allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 8.83% | 13 December 2007 |
| CVE-2007-6322 | Directory traversal vulnerability in filedownload.php in xml2owl 0.1.1 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 7.50% | 13 December 2007 |
| CVE-2007-6321 | Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versions, when using Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via style sheets containing expression commands. | EXPLOIT ✓MEDIUM 4.3EPSS 5.44% | 12 December 2007 |
| CVE-2007-6318 | SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the s parameter, when DB_CHARSET is set to (1) Big5, (2) GBK, or possibly other character set encodings… | EXPLOIT ✓MEDIUM 6.8EPSS 9.16% | 12 December 2007 |
| CVE-2007-6317 | Multiple directory traversal vulnerabilities in BarracudaDrive Web Server before 3.8 allow (1) remote attackers to read arbitrary files via certain ..\ (dot dot backslash) sequences in the URL path, or (2) remote authenticated users to delete arbitrary… | EXPLOIT ✓MEDIUM 5.5EPSS 6.04% | 12 December 2007 |
| CVE-2007-6316 | Cross-site scripting (XSS) vulnerability in BarracudaDrive Web Server before 3.8 allows remote attackers to inject arbitrary web script or HTML via the URI path in an HTTP GET request, which is activated by administrators viewing log files via the Trace… | EXPLOIT ✓MEDIUM 4.3EPSS 3.63% | 12 December 2007 |
| CVE-2007-6315 | Group Chat in BarracudaDrive Web Server before 3.8 allows remote authenticated users to cause a denial of service (crash) via a HTTP request to /eh/chat.ehintf/C. that does not contain a Connection ID, which results in a NULL pointer dereference. | EXPLOIT ✓MEDIUM 4.0EPSS 7.13% | 12 December 2007 |
| CVE-2007-6314 | BarracudaDrive Web Server before 3.8 allows remote attackers to read the source code for web scripts by appending a (1) + (plus), (2) . | EXPLOIT ✓MEDIUM 5.0EPSS 7.21% | 12 December 2007 |
| CVE-2007-3901 | Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted SAMI file. | EXPLOIT ×2 ✓HIGH 8.5EPSS 45.9% | 12 December 2007 |
| CVE-2007-3039 | Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to… | EXPLOIT ×4 ✓HIGH 9.0EPSS 69.1% | 12 December 2007 |
| CVE-2007-6311 | SQL injection vulnerability in (1) index.php, and possibly (2) admin/index.php, in Falt4Extreme RC4 10.9.2007 allows remote attackers to execute arbitrary SQL commands via the nav_ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.86% | 11 December 2007 |
| CVE-2007-6310 | Multiple cross-site scripting (XSS) vulnerabilities in Falt4Extreme RC4 10.9.2007 allow remote attackers to inject arbitrary web script or HTML via the handler parameter to (1) index.php and possibly (2) admin/index.php, and (3) the topic parameter to… | EXPLOIT ✓MEDIUM 4.3EPSS 4.62% | 11 December 2007 |
| CVE-2007-6309 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in webSPELL 4.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the galleryID parameter in a usergallery upload action; or the (2) upID, (3) tag, (4) month, (5)… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 4.16% | 11 December 2007 |
| CVE-2007-6307 | Multiple cross-site scripting (XSS) vulnerabilities in clickstats.php in wwwstats 3.21 allow remote attackers to inject arbitrary web script or HTML via (1) the link parameter or (2) the User-Agent HTTP header. | EXPLOIT ✓MEDIUM 4.3EPSS 4.14% | 11 December 2007 |
| CVE-2007-6301 | Cross-site scripting (XSS) vulnerability in compose.php in OpenNewsletter 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.73% | 10 December 2007 |
| CVE-2007-6297 | Multiple cross-site scripting (XSS) vulnerabilities in PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script or HTML via the (1) LIMIT parameter to chat/deluser.php3, the (2) Link parameter to chat/edituser.php3, or the (3) LastCheck or… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.52% | 10 December 2007 |
| CVE-2007-6292 | SQL injection vulnerability in leggi_commenti.asp in MWOpen 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 10 December 2007 |
| CVE-2007-6290 | Multiple directory traversal vulnerabilities in js/get_js.php in SERWeb 2.0.0 dev1 and earlier allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 6.54% | 10 December 2007 |
| CVE-2007-6289 | Multiple PHP remote file inclusion vulnerabilities in SerWeb 2.0.0 dev1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SERWEB[configdir] parameter to load_lang.php, (2) _SERWEB[functionsdir] parameter to… | EXPLOIT ✓MEDIUM 6.8EPSS 2.02% | 10 December 2007 |
| CVE-2007-6276 | The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows remote attackers to cause a denial of service (divide-by-zero error and daemon crash) via a crafted load balancing packet to UDP… | EXPLOIT ✓HIGH 7.8EPSS 9.15% | 7 December 2007 |
| CVE-2007-6275 | SQL injection vulnerability in modules/adresses/ratefile.php in bcoos 1.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the lid parameter, a different vector than CVE-2007-6266. | EXPLOIT ✓HIGH 7.5EPSS 0.91% | 7 December 2007 |
| CVE-2007-6273 | Multiple format string vulnerabilities in the configuration file in SonicWALL GLobal VPN Client 3.1.556 and 4.0.0.810 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in the (1) Hostname tag or the (2) name… | EXPLOIT ✓HIGH 9.3EPSS 6.20% | 7 December 2007 |
| CVE-2007-6272 | Multiple SQL injection vulnerabilities in index.php in Joomla! | EXPLOIT ×2 ✓HIGH 7.5EPSS 0.97% | 7 December 2007 |
| CVE-2007-6271 | Absolute News Manager.NET 5.1 allows remote attackers to obtain sensitive information via a direct request to getpath.aspx, which reveals the installation path in an error message. | EXPLOIT ✓MEDIUM 5.0EPSS 2.67% | 7 December 2007 |
| CVE-2007-6270 | Multiple cross-site scripting (XSS) vulnerabilities in Absolute News Manager.NET 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) rmore parameter to xlaabsolutenm.aspx and the (2) template parameter to pages/default.aspx. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 2.33% | 7 December 2007 |
| CVE-2007-6269 | Multiple SQL injection vulnerabilities in xlaabsolutenm.aspx in Absolute News Manager.NET 5.1 allow remote attackers to execute arbitrary SQL commands via the (1) z, (2) pz, (3) ord, and (4) sort parameters. | EXPLOIT ✓HIGH 7.5EPSS 2.88% | 7 December 2007 |
| CVE-2007-6268 | Directory traversal vulnerability in pages/default.aspx in Absolute News Manager.NET 5.1 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 8.40% | 7 December 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.