Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,567 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 317 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-6000 | KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a denial of service (crash) via large HTTP cookie parameters. | EXPLOIT ✓MEDIUM 5.0EPSS 3.34% | 15 November 2007 |
| CVE-2007-5999 | SQL injection vulnerability in product_desc.php in Softbiz Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 15 November 2007 |
| CVE-2007-5998 | SQL injection vulnerability in ads.php in Softbiz Ad Management plus Script 1 allows remote authenticated users to execute arbitrary SQL commands via the package parameter. | EXPLOIT ✓MEDIUM 6.5EPSS 0.87% | 15 November 2007 |
| CVE-2007-5997 | SQL injection vulnerability in campaign_stats.php in Softbiz Banner Exchange Network Script 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓MEDIUM 6.5EPSS 0.87% | 15 November 2007 |
| CVE-2007-5996 | SQL injection vulnerability in searchresult.php in Softbiz Link Directory Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter, a related issue to CVE-2007-5449. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 15 November 2007 |
| CVE-2007-5995 | PHP remote file inclusion vulnerability in examples/patExampleGen/bbcodeSource.php in patBBcode 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the example parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.02% | 15 November 2007 |
| CVE-2007-5993 | Cross-site scripting (XSS) vulnerability in Visionary Technology in Library Solutions (VTLS) vtls.web.gateway before 48.1.1 allows remote attackers to inject arbitrary web script or HTML via the searchtype parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.91% | 15 November 2007 |
| CVE-2007-5992 | SQL injection vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewcat s action on the forums page. | EXPLOIT ✓HIGH 7.5EPSS 1.13% | 15 November 2007 |
| CVE-2007-4684 | Integer overflow in the kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a large num_sels argument to the i386_set_ldt system call. | EXPLOIT ✓MEDIUM 6.9EPSS 1.00% | 15 November 2007 |
| CVE-2007-5984 | classes/Url.php in Justin Hagstrom AutoIndex PHP Script before 2.2.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via a %00 sequence in the dir parameter to index.php, which triggers an erroneous "recursive… | EXPLOIT ✓HIGH 7.8EPSS 8.45% | 15 November 2007 |
| CVE-2007-5983 | Cross-site scripting (XSS) vulnerability in index.php in Justin Hagstrom AutoIndex PHP Script before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF). | EXPLOIT ✓MEDIUM 4.3EPSS 2.02% | 15 November 2007 |
| CVE-2007-5982 | Multiple cross-site scripting (XSS) vulnerabilities in X7 Chat 2.0.4, 2.0.5, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) room parameter to sources/frame.php, the (2) theme_c parameter to… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 3.05% | 15 November 2007 |
| CVE-2007-5979 | Cross-site scripting (XSS) vulnerability in download_plugin.php3 in F5 Firepass 4100 SSL VPN 5.4 through 5.5.2 and 6.0 through 6.0.1 allows remote attackers to inject arbitrary web script or HTML via the backurl parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.60% | 15 November 2007 |
| CVE-2007-5978 | SQL injection vulnerability in brokenlink.php in the mylinks module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 15 November 2007 |
| CVE-2007-5974 | SQL injection vulnerability in mailer.php in JPortal 2 allows remote attackers to execute arbitrary SQL commands via the to parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.27% | 15 November 2007 |
| CVE-2007-5973 | SQL injection vulnerability in articles.php in JPortal 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 15 November 2007 |
| CVE-2007-3694 | Cross-site scripting (XSS) vulnerability in login.php in Miro Project Broadcast Machine 0.9.9.9 allows remote attackers to inject arbitrary web script or HTML via the username parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 14 November 2007 |
| CVE-2007-5954 | Cross-site scripting (XSS) vulnerability in buscador.php in JLMForo System allows remote attackers to inject arbitrary web script or HTML via the clave parameter. | EXPLOIT ✓MEDIUM 6.1EPSS 1.13% | 14 November 2007 |
| CVE-2007-5952 | Cross-site scripting (XSS) vulnerability in admin/index.php in Helios Calendar 1.2.1 Beta allows remote attackers to inject arbitrary web script or HTML via the username parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 14 November 2007 |
| CVE-2007-5951 | SQL injection vulnerability in articles.php in E-Vendejo 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 14 November 2007 |
| CVE-2007-5944 | Cross-site scripting (XSS) vulnerability in Servlet Engine / Web Container in IBM WebSphere Application Server (WAS) 5.1.1.4 through 5.1.1.16 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header. | EXPLOIT ✓MEDIUM 4.3EPSS 1.79% | 14 November 2007 |
| CVE-2007-5941 | Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument to the ShockwaveVersion method. | EXPLOIT ✓HIGH 10.0EPSS 32.3% | 14 November 2007 |
| CVE-2007-3898 | The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack… | EXPLOIT ×2 ✓MEDIUM 6.4EPSS 52.3% | 14 November 2007 |
| CVE-2007-5926 | OpenBase 10.0.5 and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in arguments to the (1) AsciiBackup, (2) OEMLicenseInstall, and possibly other stored procedures. | EXPLOIT ✓HIGH 9.0EPSS 3.44% | 10 November 2007 |
| CVE-2007-5925 | The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to cause a denial of service (database crash) via a certain CONTAINS operation on an indexed column, which… | EXPLOIT ✓MEDIUM 4.0EPSS 11.4% | 10 November 2007 |
| CVE-2007-5923 | Cross-site scripting (XSS) vulnerability in forms/smpwservices.fcc in CA (formerly Computer Associates) eTrust SiteMinder Agent allows remote attackers to inject arbitrary web script or HTML via the SMAUTHREASON parameter, a different vector than… | EXPLOIT ✓MEDIUM 4.3EPSS 1.36% | 10 November 2007 |
| CVE-2007-5918 | Cross-site request forgery (CSRF) vulnerability in edit.php in the MS TopSites add-on for PHP-Nuke does not verify that the uname parameter matches the current account, which allows remote authenticated users to change arbitrary accounts or change the… | EXPLOIT ✓MEDIUM 6.0EPSS 0.78% | 10 November 2007 |
| CVE-2007-5915 | Directory traversal vulnerability in index.php in phphelpdesk 0.6.16 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 1.81% | 10 November 2007 |
| CVE-2007-5914 | Direct static code injection vulnerability in dirsys/modules/config/post.php in JBC Explorer 7.20 RC1 and earlier allows remote authenticated administrators to inject arbitrary PHP code via the DEBUG parameter, which can be executed by accessing… | EXPLOIT ✓MEDIUM 6.8EPSS 5.43% | 10 November 2007 |
| CVE-2007-5913 | dirsys/modules/auth.php in JBC Explorer 7.20 RC1 and earlier does not require authentication, which allows remote attackers to (1) delete auth.inc.php via the suppr parameter, and (2) re-create the auth.inc.php file with contents that specify a new… | EXPLOIT ✓MEDIUM 6.8EPSS 7.26% | 10 November 2007 |
| CVE-2007-5912 | SQL injection vulnerability in mailer.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the to parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 10 November 2007 |
| CVE-2007-5911 | Multiple stack-based buffer overflows in the AxMetaStream ActiveX control in AxMetaStream.dll 3.3.2.26 in Viewpoint Media Player 3.2 allow remote attackers to execute arbitrary code via a long string argument to the (1) BroadcastKey, (2)… | EXPLOIT ✓MEDIUM 6.8EPSS 4.01% | 10 November 2007 |
| CVE-2007-4517 | Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remote authenticated users to execute arbitrary code via a long (1) OWNER or (2) NAME argument. | EXPLOITMEDIUM 6.0EPSS 5.38% | 8 November 2007 |
| CVE-2007-5890 | Directory traversal vulnerability in index.php in easyGB 2.1.1 allows remote attackers to include arbitrary files via the DatabaseType parameter. | EXPLOIT ✓HIGH 10.0EPSS 3.24% | 8 November 2007 |
| CVE-2007-5887 | SQL injection vulnerability in boards/printer.asp in ASP Message Board 2.2.1c allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 7 November 2007 |
| CVE-2007-5845 | Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.98% | 6 November 2007 |
| CVE-2007-5844 | Directory traversal vulnerability in inc/includes.inc in GuppY 4.6.3 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.35% | 6 November 2007 |
| CVE-2007-5843 | PHP remote file inclusion vulnerability in includes/common.php in scWiki 1.0 Beta 2 allows remote attackers to execute arbitrary PHP code via a URL in the pathdot parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 37.5% | 6 November 2007 |
| CVE-2007-5842 | Multiple PHP remote file inclusion vulnerabilities in Vortex Portal 1.0.42 allow remote attackers to execute arbitrary PHP code via a URL in the cfgProgDir parameter to (1) admincp/auth/secure.php or (2) admincp/auth/checklogin.php. | EXPLOIT ✓MEDIUM 6.8EPSS 46.5% | 6 November 2007 |
| CVE-2007-5841 | PHP remote file inclusion vulnerability in admin/index.php in nuBoard 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the site parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 31.4% | 6 November 2007 |
| CVE-2007-5840 | PHP remote file inclusion vulnerability in starnet/themes/c-sky/main.inc.php in Fred Stuurman SyndeoCMS 2.5.01 allows remote attackers to execute arbitrary PHP code via a URL in the cmsdir parameter, a different vector than CVE-2006-4920.2. | EXPLOIT ✓MEDIUM 6.8EPSS 3.18% | 6 November 2007 |
| CVE-2007-5837 | GUI.pm in yarssr 0.2.2, when Gnome default URL handling is disabled, allows remote attackers to execute arbitrary commands via shell metacharacters in a link element in a feed. | EXPLOIT ✓MEDIUM 6.8EPSS 6.21% | 5 November 2007 |
| CVE-2007-5826 | Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote attackers to create or overwrite arbitrary files with arbitrary contents via a full pathname in the second argument to the… | EXPLOIT ✓HIGH 9.3EPSS 3.68% | 5 November 2007 |
| CVE-2007-5824 | webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a stats method action to /xml-rpc with (1) an empty Authorization header line, which triggers… | EXPLOIT ✓HIGH 7.1EPSS 5.59% | 5 November 2007 |
| CVE-2007-5823 | Directory traversal vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to create or overwrite arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.64% | 5 November 2007 |
| CVE-2007-5822 | Direct static code injection vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to inject arbitrary PHP code into a certain file in regged/ via the username parameter in a Register action, possibly related to the… | EXPLOIT ✓HIGH 7.5EPSS 3.31% | 5 November 2007 |
| CVE-2007-5821 | Multiple directory traversal vulnerabilities in DM Guestbook 0.4.1 and earlier allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 5.53% | 5 November 2007 |
| CVE-2007-5820 | Directory traversal vulnerability in index.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 9.3EPSS 2.97% | 5 November 2007 |
| CVE-2007-5817 | dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to perform certain privileged actions via a (1) del, (2) delbackup, (3) res, or (4) ren action. | EXPLOIT ✓MEDIUM 6.1EPSS 1.03% | 5 November 2007 |
| CVE-2007-5816 | dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to obtain sensitive author credentials by making a request with an editauthor action, then reading the value of the newlocalpassword password input field in the HTML source of the… | EXPLOIT ✓MEDIUM 5.0EPSS 2.52% | 5 November 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.