Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,567 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 320 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-5461 | Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request… | EXPLOIT ×2 ✓LOW 3.5EPSS 39.7% | 15 October 2007 |
| CVE-2007-5458 | SQL injection vulnerability in index.php in the newsletter module 1.0 for KwsPHP, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsletter parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.95% | 14 October 2007 |
| CVE-2007-5457 | Multiple PHP remote file inclusion vulnerabilities in Michael Dempfle Joomla Flash Uploader (com_jfu or com_joomla_flash_uploader) 2.5.1 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path… | EXPLOIT ✓MEDIUM 6.8EPSS 37.6% | 14 October 2007 |
| CVE-2007-5455 | Cross-site scripting (XSS) vulnerability in wxis.exe in WWWISIS 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a call to the iah/iah.xis IsisScript code, possibly involving the lang or exprSearch parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.52% | 14 October 2007 |
| CVE-2007-5453 | Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing PHP sequences to the php-stats-options record in the _options table, which is used in an eval function call by… | EXPLOIT ✓HIGH 8.5EPSS 3.91% | 14 October 2007 |
| CVE-2007-5452 | Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote attackers to execute arbitrary SQL commands via the (1) ip or (2) t parameter. | EXPLOIT ✓HIGH 10.0EPSS 2.90% | 14 October 2007 |
| CVE-2007-5451 | PHP remote file inclusion vulnerability in admin.color.php in the com_colorlab (aka com_color) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 31.2% | 14 October 2007 |
| CVE-2007-5450 | Unspecified vulnerability in Safari on the Apple iPod touch (aka iTouch) and iPhone 1.1.1 allows user-assisted remote attackers to cause a denial of service (application crash), and enable filesystem browsing by the local user, via a certain TIFF file. | EXPLOIT ✓HIGH 9.3EPSS 4.90% | 14 October 2007 |
| CVE-2007-5449 | SQL injection vulnerability in searchresult.php in Softbiz Recipes Portal Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.44% | 14 October 2007 |
| CVE-2007-5447 | ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by reading arbitrary… | EXPLOIT ✓MEDIUM 4.3EPSS 4.58% | 14 October 2007 |
| CVE-2007-5446 | Absolute path traversal vulnerability in a certain ActiveX control in PBEmail7Ax.dll in PBEmail 7 ActiveX Edition allows remote attackers to create or overwrite arbitrary files via a full pathname in the XmlFilePath argument to the SaveSenderToXml method. | EXPLOIT ✓MEDIUM 6.4EPSS 5.79% | 14 October 2007 |
| CVE-2007-5440 | Multiple PHP remote file inclusion vulnerabilities in CRS Manager allow remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter to (1) index.php or (2) login.php. | EXPLOIT ✓HIGH 7.5EPSS 3.22% | 14 October 2007 |
| CVE-2007-5332 | Multiple unspecified vulnerabilities in (1) mediasvr and (2) caloggerd in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, have unknown impact and attack vectors related to memory corruption. | EXPLOIT ✓HIGH 10.0EPSS 5.29% | 13 October 2007 |
| CVE-2007-5208 | hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a from address, which is not properly handled when invoking… | EXPLOIT ✓HIGH 7.6EPSS 67.3% | 13 October 2007 |
| CVE-2007-5430 | Multiple SQL injection vulnerabilities in Stride 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the p parameter to main.php in the Content Management System, (2) the id parameter in a sto cmd action to shop.php in the Merchant… | EXPLOIT ×3 ✓HIGH 7.5EPSS 1.89% | 12 October 2007 |
| CVE-2007-5429 | Cross-site scripting (XSS) vulnerability in index.php in Nucleus 3.01 allows remote attackers to inject arbitrary web script or HTML via the archive parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.73% | 12 October 2007 |
| CVE-2007-5428 | Cross-site scripting (XSS) vulnerability in UMI CMS allows remote attackers to inject arbitrary web script or HTML via the search_string parameter to the default URI in search_do/. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 12 October 2007 |
| CVE-2007-5427 | Cross-site scripting (XSS) vulnerability in the com_search component in Joomla! | EXPLOIT ✓MEDIUM 4.3EPSS 1.93% | 12 October 2007 |
| CVE-2007-5426 | Multiple cross-site scripting (XSS) vulnerabilities in ActiveKB NX 2.5.4 allow remote attackers to inject arbitrary web script or HTML via the page parameter to the default URI for some directories, as demonstrated by (1) ActiveKB/ and (2)… | EXPLOIT ✓MEDIUM 4.3EPSS 1.79% | 12 October 2007 |
| CVE-2007-5423 | tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function. | EXPLOIT ×2 ✓HIGH 7.5EPSS 76.7% | 12 October 2007 |
| CVE-2007-5417 | Directory traversal vulnerability in index.php in boastMachine (aka bMachine) 2.8 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.42% | 12 October 2007 |
| CVE-2007-5416 | Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by invoking the… | EXPLOIT ✓MEDIUM 6.8EPSS 4.42% | 12 October 2007 |
| CVE-2007-5412 | Multiple PHP remote file inclusion vulnerabilities in the Quoc-Huy MP3 Allopass (com_mp3_allopass) 1.0 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter to (1) allopass.php and (2)… | EXPLOIT ✓MEDIUM 6.8EPSS 37.5% | 12 October 2007 |
| CVE-2007-5411 | Cross-site scripting (XSS) vulnerability in the Linksys SPA941 VoIP Phone with firmware 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the From header in a SIP message. | EXPLOIT ✓MEDIUM 4.3EPSS 1.47% | 12 October 2007 |
| CVE-2007-5410 | PHP remote file inclusion vulnerability in admin.wmtrssreader.php in the webmaster-tips.net Flash RSS Reader (com_wmtrssreader) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 5.37% | 12 October 2007 |
| CVE-2007-5409 | PHP remote file inclusion vulnerability in admin/nuseo_admin_d.php in NuSEO PHP Enterprise 1.6 (NuSEO.PHP), when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the nuseo_dir parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.07% | 12 October 2007 |
| CVE-2007-5408 | SQL injection vulnerability in category.php in cpDynaLinks 1.02 allows remote attackers to execute arbitrary SQL commands via the category parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 0.97% | 12 October 2007 |
| CVE-2007-5407 | Multiple PHP remote file inclusion vulnerabilities in the JContentSubscription (com_jcs) 1.5.8 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) jcs.function.php; (2)… | EXPLOIT ✓MEDIUM 6.8EPSS 40.2% | 12 October 2007 |
| CVE-2007-5390 | PHP remote file inclusion vulnerability in index.php in PicoFlat CMS 0.4.14 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pagina parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 4.37% | 12 October 2007 |
| CVE-2007-5388 | Multiple PHP remote file inclusion vulnerabilities in WebDesktop 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) app parameter to apps/apps.php and the (2) wsk parameter to wsk/wsk.php. | EXPLOIT ✓MEDIUM 6.8EPSS 38.4% | 12 October 2007 |
| CVE-2007-5387 | PHP remote file inclusion vulnerability in active/components/xmlrpc/client.php in Pindorama 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the c[components] parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 28.9% | 12 October 2007 |
| CVE-2007-5386 | Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote attackers to inject arbitrary web script or HTML via the query string. | EXPLOIT ✓MEDIUM 4.3EPSS 3.33% | 12 October 2007 |
| CVE-2007-5381 | Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute arbitrary code by setting a long hostname on the target system, then causing an error message to… | EXPLOIT ✓HIGH 9.3EPSS 14.7% | 12 October 2007 |
| CVE-2007-5374 | cp_memberedit.php in LightBlog 8.4.1.1 does not check for administrative credentials when processing an admin action, which allows remote authenticated users to increase the privileges of any account. | EXPLOIT ✓MEDIUM 6.5EPSS 2.19% | 11 October 2007 |
| CVE-2007-5370 | Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/dnewsweb.exe in NetWin DNewsWeb (DNews News Server) 57e1 allow remote attackers to inject arbitrary web script or HTML via the (1) group or (2) utag parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.79% | 11 October 2007 |
| CVE-2007-5365 | Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon… | EXPLOIT ✓HIGH 7.2EPSS 80.3% | 11 October 2007 |
| CVE-2007-5363 | PHP remote file inclusion vulnerability in admin.panoramic.php in the Panoramic Picture Viewer (com_panoramic) mambot (plugin) 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 31.4% | 11 October 2007 |
| CVE-2007-5362 | Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to… | EXPLOIT ✓MEDIUM 6.8EPSS 36.5% | 11 October 2007 |
| CVE-2007-3896 | The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as… | EXPLOIT ✓HIGH 9.3EPSS 53.8% | 11 October 2007 |
| CVE-2007-5322 | Insecure method vulnerability in the FPOLE.OCX 6.0.8450.0 ActiveX control in Microsoft Visual FoxPro 6.0 allows remote attackers to execute arbitrary programs by specifying them as an argument to the FoxDoCmd function. | EXPLOIT ✓HIGH 7.5EPSS 18.6% | 9 October 2007 |
| CVE-2007-5321 | Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers to include arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 2.33% | 9 October 2007 |
| CVE-2007-5320 | Multiple absolute path traversal vulnerabilities in Pegasus Imaging ImagXpress 8.0 allow remote attackers to (1) delete arbitrary files via the CacheFile attribute in the ThumbnailXpres.1 ActiveX control (PegasusImaging.ActiveX.ThumnailXpress1.dll) or… | EXPLOIT ✓MEDIUM 4.0EPSS 6.51% | 9 October 2007 |
| CVE-2007-4466 | Multiple stack-based buffer overflows in Electronic Arts (EA) SnoopyCtrl ActiveX control (NPSnpy.dll) allow remote attackers to execute arbitrary code via unspecified methods and parameters. | EXPLOIT ✓MEDIUM 6.8EPSS 30.9% | 9 October 2007 |
| CVE-2007-2217 | Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote attackers to execute arbitrary code via crafted image files that trigger memory corruption, as demonstrated by a certain .tif (TIFF)… | EXPLOIT ×2 ✓HIGH 9.3EPSS 41.4% | 9 October 2007 |
| CVE-2007-5316 | SQL injection vulnerability in browsecats.php in Softbiz Jobs and Recruitment Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 1.39% | 9 October 2007 |
| CVE-2007-5315 | PHP remote file inclusion vulnerability in common.php in LiveAlbum 0.9.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the livealbum_dir parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 38.6% | 9 October 2007 |
| CVE-2007-5314 | PHP remote file inclusion vulnerability in system/funcs/xkurl.php in xKiosk WEB 3.0.1i, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the PEARPATH parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.38% | 9 October 2007 |
| CVE-2007-5313 | PHP remote file inclusion vulnerability in install/config.php in Picturesolution 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.76% | 9 October 2007 |
| CVE-2007-5312 | Cross-site scripting (XSS) vulnerability in TorrentTrader Classic 1.07 allows remote attackers to inject arbitrary web script or HTML via the (1) color parameter to pjirc/css.php and the (2) cat parameter to browse.php. | EXPLOIT ✓MEDIUM 4.3EPSS 2.26% | 9 October 2007 |
| CVE-2007-5311 | Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic Edition 1.07 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 3.10% | 9 October 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.