Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,567 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 318 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-5815 | Absolute path traversal vulnerability in the WebCacheCleaner ActiveX control 1.3.0.3 in SonicWall SSL-VPN 200 before 2.1, and SSL-VPN 2000/4000 before 2.5, allows remote attackers to delete arbitrary files via a full pathname in the argument to the… | EXPLOIT ✓HIGH 10.0EPSS 4.53% | 5 November 2007 |
| CVE-2007-5603 | Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allows remote attackers to execute arbitrary code via a long string in the second argument to the AddRouteEntry… | EXPLOIT ×2 ✓HIGH 9.3EPSS 38.0% | 5 November 2007 |
| CVE-2007-5813 | Multiple directory traversal vulnerabilities in download.php in ISPworker 1.21 allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.82% | 5 November 2007 |
| CVE-2007-5812 | Directory traversal vulnerability in modules/Builder/DownloadModule.php in ModuleBuilder 1.0 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 6.14% | 5 November 2007 |
| CVE-2007-5802 | Directory traversal vulnerability in index.php in Firewolf Technologies Synergiser 1.2 RC1 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ×2 ✓HIGH 7.5EPSS 3.92% | 3 November 2007 |
| CVE-2007-5800 | Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow remote attackers to execute arbitrary PHP code via a URL in the bkpwp_plugin_path parameter to (1) plugins/BackUp/Archive.php; and… | EXPLOIT ✓MEDIUM 6.8EPSS 36.5% | 3 November 2007 |
| CVE-2007-5796 | Cross-site scripting (XSS) vulnerability in the management console in Blue Coat ProxySG before 4.2.6.1, and 5.x before 5.2.2.5, allows remote attackers to inject arbitrary web script or HTML by modifying the URL that is used for loading Certificate… | EXPLOIT ✓MEDIUM 4.3EPSS 2.35% | 3 November 2007 |
| CVE-2007-5795 | The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow user-assisted attackers to bypass intended restrictions and modify… | EXPLOIT ✓MEDIUM 6.3EPSS 0.72% | 2 November 2007 |
| CVE-2007-5660 | Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2008 allows remote attackers to execute arbitrary code via an unspecified "unsafe method," possibly… | EXPLOIT ×2 ✓HIGH 9.3EPSS 36.6% | 2 November 2007 |
| CVE-2007-5786 | Multiple PHP remote file inclusion vulnerabilities in GoSamba 1.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) HTML_oben.php, (2) inc_freigabe.php, (3) inc_freigabe1.php, or (4) inc_freigabe3.php… | EXPLOIT ✓HIGH 7.5EPSS 2.42% | 1 November 2007 |
| CVE-2007-5785 | SQL injection vulnerability in file.php in JobSite Professional 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 1 November 2007 |
| CVE-2007-5784 | PHP remote file inclusion vulnerability in index.php in CaupoShop Pro 2.x allows remote attackers to execute arbitrary PHP code via a URL in the action parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.07% | 1 November 2007 |
| CVE-2007-5783 | SQL injection vulnerability in emc.asp in emagiC CMS.Net 4.0 allows remote attackers to execute arbitrary SQL commands via the pageId parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 1 November 2007 |
| CVE-2007-5782 | Directory traversal vulnerability in dl.php in FireConfig 0.5 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.82% | 1 November 2007 |
| CVE-2007-5781 | PHP remote file inclusion vulnerability in inc/sige_init.php in Sige 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the SYS_PATH parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 38.6% | 1 November 2007 |
| CVE-2007-5780 | PHP remote file inclusion vulnerability in pub/pub08_comments.php in teatro 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the basePath parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.37% | 1 November 2007 |
| CVE-2007-5779 | Buffer overflow in the GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 in Gretech Online Movie Player (GOM Player) 2.1.6.3499 allows remote attackers to execute arbitrary code via a long argument to the OpenUrl method. | EXPLOIT ×2 ✓HIGH 7.5EPSS 71.5% | 1 November 2007 |
| CVE-2007-5776 | Directory traversal vulnerability in igallery.asp in Blue-Collar Productions i-Gallery 3.4 allows remote attackers to read arbitrary files via encoded backslash sequences in the d parameter, as demonstrated by a "%5c../../%5c" sequence. | EXPLOIT ✓MEDIUM 5.0EPSS 2.75% | 1 November 2007 |
| CVE-2007-5775 | Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. | EXPLOIT ✓CRITICAL 9.8EPSS 26.9% | 1 November 2007 |
| CVE-2007-5774 | index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invalid argumentname parameter in a disc op action, which reveals the path in an error message. | EXPLOIT ✓MEDIUM 5.0EPSS 2.60% | 1 November 2007 |
| CVE-2007-5773 | Cross-site request forgery (CSRF) vulnerability in index.php in the File Manager module in Flatnuke 3 allows remote attackers to perform certain actions as administrators via requests containing the pathname in the dir parameter and the filename in the… | EXPLOIT ✓MEDIUM 4.3EPSS 0.88% | 1 November 2007 |
| CVE-2007-5772 | Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrators to inject arbitrary PHP code into a description.it.php file in a subdirectory of Download/ by saving a description and setting… | EXPLOIT ✓MEDIUM 6.0EPSS 3.83% | 1 November 2007 |
| CVE-2007-5771 | Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie. | EXPLOIT ✓HIGH 7.5EPSS 6.07% | 1 November 2007 |
| CVE-2007-5754 | PHP remote file inclusion vulnerability in urlinn_includes/config.php in phpFaber URLInn 2.0.5 allows remote attackers to execute arbitrary PHP code via a URL in the dir_ws parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.07% | 31 October 2007 |
| CVE-2007-5752 | adduser.php in PHP-AGTC Membership (AGTC-Membership) System 1.1a does not require authentication, which allows remote attackers to create accounts via a modified form, as demonstrated by an account with admin (userlevel 4) privileges. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.81% | 31 October 2007 |
| CVE-2007-5740 | The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code via an IMAP tag with a null byte followed by a format string specifier, which is not counted by the… | EXPLOIT ✓HIGH 7.5EPSS 12.4% | 31 October 2007 |
| CVE-2007-5739 | Directory traversal vulnerability in component/flashupload/download.jsp in the FlashUpload component in Korean GHBoard allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.72% | 30 October 2007 |
| CVE-2007-5737 | Unrestricted file upload vulnerability in component/upload.jsp in Korean GHBoard allows remote attackers to upload arbitrary files via unspecified vectors, probably involving a direct request. | EXPLOIT ✓HIGH 7.5EPSS 2.38% | 30 October 2007 |
| CVE-2007-5733 | Unrestricted file upload vulnerability in upload/upload.php in Japanese PHP Gallery Hosting, when Open directory mode is enabled, allows remote attackers to upload and execute arbitrary PHP code via a ServerPath parameter specifying a filename with a… | EXPLOIT ✓HIGH 7.5EPSS 2.38% | 30 October 2007 |
| CVE-2007-5731 | Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag, a related issue to CVE-2007-5461. | EXPLOIT ✓LOW 3.5EPSS 7.13% | 30 October 2007 |
| CVE-2007-5728 | Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via certain input available in PHP_SELF in (1) redirect.php, possibly related to (2) login.php,… | EXPLOIT ✓MEDIUM 4.3EPSS 14.6% | 30 October 2007 |
| CVE-2007-5725 | Multiple cross-site scripting (XSS) vulnerabilities in Smart-Shop allow remote attackers to inject arbitrary web script or HTML via (1) the email parameter to index.php; or the command parameter to index.php in (2) the default action for the home page,… | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 30 October 2007 |
| CVE-2007-5724 | Multiple cross-site scripting (XSS) vulnerabilities in Omnistar Live allow remote attackers to inject arbitrary web script or HTML via (1) the category_id parameter to users/kb.php, and possibly (3) the Email Box field in profile.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.73% | 30 October 2007 |
| CVE-2007-5722 | Stack-based buffer overflow in a certain ActiveX control in GLChat.ocx 2.5.1.32 in GlobalLink 2.7.0.8, as used in Ourgame GLWorld and possibly other products, allows remote attackers to execute arbitrary code via a long first argument to the… | EXPLOIT ✓HIGH 7.5EPSS 11.7% | 30 October 2007 |
| CVE-2007-5721 | PHP remote file inclusion vulnerability in _theme/breadcrumb.php in MySpacePros MySpace Resource Script (MSRS) 1.21 allows remote attackers to execute arbitrary PHP code via a URL in the rootBase parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.02% | 30 October 2007 |
| CVE-2007-5720 | Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving creation of a profile. | EXPLOIT ✓MEDIUM 6.8EPSS 1.96% | 30 October 2007 |
| CVE-2007-5719 | SQL injection vulnerability in bb_func_search.php in miniBB 2.1 allows remote attackers to execute arbitrary SQL commands via the table parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 30 October 2007 |
| CVE-2007-4863 | SQL injection vulnerability in example.php in SAXON 5.4 allows remote attackers to execute arbitrary SQL commands via the template parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.18% | 30 October 2007 |
| CVE-2007-4862 | Cross-site scripting (XSS) vulnerability in admin/menu.php in SAXON 5.4 allows remote attackers to inject arbitrary web script or HTML via the config[news_url] parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.85% | 30 October 2007 |
| CVE-2007-5710 | Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inject arbitrary web script or HTML via the posts_columns array parameter. | EXPLOIT ✓LOW 2.6EPSS 7.00% | 30 October 2007 |
| CVE-2007-5709 | Stack-based buffer overflow in Sony SonicStage CONNECT Player (CP) 4.3 allows remote attackers to execute arbitrary code via a long file name in an M3U file. | EXPLOIT ✓HIGH 9.3EPSS 10.9% | 30 October 2007 |
| CVE-2007-5706 | Absolute path traversal vulnerability in download.php in Jeebles Directory 2.9.60 allows remote attackers to read arbitrary files via a full pathname in the query string. | EXPLOIT ✓HIGH 9.3EPSS 2.67% | 29 October 2007 |
| CVE-2007-5699 | Stack-based buffer overflow in eIQNetworks Enterprise Security Analyzer (ESA) 2.5 allows remote attackers to execute arbitrary code via certain data on TCP port 10616 that results in a long argument to the SEARCHREPORT command, a different vector than… | EXPLOIT ✓MEDIUM 6.8EPSS 3.71% | 29 October 2007 |
| CVE-2007-5697 | Multiple PHP remote file inclusion vulnerabilities in PHP Image 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the xarg parameter to (1) xarg_corner.php, (2) xarg_corner_bottom.php, and (3) xarg_corner_top.php. | EXPLOIT ✓MEDIUM 6.8EPSS 2.30% | 29 October 2007 |
| CVE-2007-5694 | Absolute path traversal vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to read arbitrary files via an absolute path in the dir parameter, a different vulnerability than CVE-2007-5491. | EXPLOIT ✓MEDIUM 6.8EPSS 7.56% | 29 October 2007 |
| CVE-2007-5693 | Eval injection vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to execute arbitrary PHP code via the edit parameter in an upd cmd action, a different vulnerability than CVE-2007-5492. | EXPLOIT ✓MEDIUM 6.0EPSS 5.08% | 29 October 2007 |
| CVE-2007-5692 | Multiple cross-site scripting (XSS) vulnerabilities in SiteBar 3.3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter to integrator.php; (2) the token parameter in a New Password action, (3) the nid_acl parameter… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 4.77% | 29 October 2007 |
| CVE-2007-5688 | Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka Multi Host Forum Pro) module 1.3.3, for phpBB and Invision Power Board (IPB or IP.Board), allow remote attackers to execute arbitrary SQL commands via the (1) go and (2)… | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 29 October 2007 |
| CVE-2007-5685 | The safe_path function in shttp before 0.0.5 allows remote attackers to conduct directory traversal attacks and read files via a combination of ".." and sub-directory specifiers that resolve to a pathname that is at or below the same level as the web… | EXPLOIT ✓MEDIUM 5.0EPSS 3.48% | 28 October 2007 |
| CVE-2007-5684 | Multiple directory traversal vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to include and execute arbitrary files via an absolute pathname in (1) error_handler_file and (2) local_php parameters to (a) tiki-index.php, or (3)… | EXPLOIT ✓HIGH 7.5EPSS 3.02% | 26 October 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.