Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,567 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 321 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-5310 | PHP remote file inclusion vulnerability in admin.wmtportfolio.php in the webmaster-tips.net wmtportfolio 1.0 (com_wmtportfolio) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 4.37% | 9 October 2007 |
| CVE-2007-5309 | PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 5.79% | 9 October 2007 |
| CVE-2007-5308 | SQL injection vulnerability in galerie.php in PHP Homepage M (phpHPm) 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action. | EXPLOIT ✓MEDIUM 6.8EPSS 1.12% | 9 October 2007 |
| CVE-2007-5307 | ELSEIF CMS Beta 0.6 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by uploading a .php file via… | EXPLOIT ✓HIGH 7.5EPSS 2.38% | 9 October 2007 |
| CVE-2007-5306 | ELSEIF CMS Beta 0.6 allows remote attackers to obtain sensitive information (full path) via unspecified vectors to utilisateurs/votesresultats.php. | EXPLOIT ✓MEDIUM 5.0EPSS 2.83% | 9 October 2007 |
| CVE-2007-5305 | Multiple PHP remote file inclusion vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) contenus parameter to (a) contenus.php; the (2) tpelseifportalrepertoire parameter to (b) votes.php, (c)… | EXPLOIT ✓HIGH 7.5EPSS 9.30% | 9 October 2007 |
| CVE-2007-5304 | Multiple cross-site scripting (XSS) vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) repertimage parameter to utilisateurs/vousetesbannis.php, the (2) elseifvotetxtresultatduvote parameter… | EXPLOIT ✓MEDIUM 4.3EPSS 3.76% | 9 October 2007 |
| CVE-2007-5301 | Buffer overflow in the vorbis_stream_info function in input/vorbis/vorbis_engine.c (aka the vorbis input plugin) in AlsaPlayer before 0.99.80-rc3 allows remote attackers to execute arbitrary code via a .OGG file with long comments. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 10.2% | 9 October 2007 |
| CVE-2007-5300 | Off-by-one error in the do_login_loop function in libwzd-core/wzd_login.c in wzdftpd 0.8.0, 0.8.2, and possibly other versions allows remote attackers to cause a denial of service (daemon crash) via a long USER command that triggers a stack-based buffer… | EXPLOIT ✓MEDIUM 5.0EPSS 4.91% | 9 October 2007 |
| CVE-2007-5299 | Multiple directory traversal vulnerabilities in SkaDate 5.0 and 6.0, and possibly later versions such as 6.482, allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 8.27% | 9 October 2007 |
| CVE-2007-5298 | Multiple PHP remote file inclusion vulnerabilities in CMS Creamotion allow remote attackers to execute arbitrary PHP code via a URL in the cfg[document_uri] parameter to (1) _administration/securite.php and (2)… | EXPLOIT ✓MEDIUM 6.4EPSS 7.43% | 9 October 2007 |
| CVE-2007-5294 | PHP remote file inclusion vulnerability in core/aural.php in IDMOS 1.0-beta (aka Phoenix) allows remote attackers to execute arbitrary PHP code via a URL in the site_absolute_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 5.61% | 9 October 2007 |
| CVE-2007-5293 | Multiple cross-site scripting (XSS) vulnerabilities in IDMOS 1.0-beta (aka Phoenix) allow remote attackers to inject arbitrary web script or HTML via the (1) err_msg parameter to error.php and the (2) content parameter to templates/simple/ia.php. | EXPLOIT ✓LOW 2.6EPSS 2.33% | 9 October 2007 |
| CVE-2007-5290 | Multiple cross-site scripting (XSS) vulnerabilities in MailBee WebMail Pro 3.4 and earlier; and possibly MailBee WebMail Pro ASP before 3.4.64, WebMail Lite ASP before 4.0.11, and WebMail Lite PHP before 4.0.22; allow remote attackers to inject… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 3.82% | 9 October 2007 |
| CVE-2007-5278 | Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a… | EXPLOIT ✓MEDIUM 4.3EPSS 2.02% | 8 October 2007 |
| CVE-2007-5272 | SQL injection vulnerability in kategori.asp in Furkan Tastan Blog allows remote attackers to execute arbitrary SQL commands via the id parameter in a goster kat action. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 8 October 2007 |
| CVE-2007-5271 | Multiple PHP remote file inclusion vulnerabilities in Trionic Cite CMS 1.2 rev9 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the bField[bf_data] parameter to (1) interface/editors/-custom.php or (2)… | EXPLOIT ✓MEDIUM 6.8EPSS 28.7% | 8 October 2007 |
| CVE-2007-5265 | Multiple format string vulnerabilities in websrv.cpp in Dawn of Time 1.69s beta4 and earlier allow remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) password fields when accessing certain "restricted… | EXPLOIT ✓HIGH 7.5EPSS 5.33% | 8 October 2007 |
| CVE-2007-5264 | Battlefront Dropteam 1.3.3 and earlier sends the client's online account name and password to the game server, which allows malicious game servers to steal account information. | EXPLOIT ✓MEDIUM 5.0EPSS 3.11% | 8 October 2007 |
| CVE-2007-4924 | The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length header field in Session Initiation Protocol (SIP)… | EXPLOIT ✓MEDIUM 5.0EPSS 10.7% | 8 October 2007 |
| CVE-2007-5261 | Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to categorydetail.php and the (2) ddlCategory parameter to search.php. | EXPLOIT ✓MEDIUM 6.4EPSS 2.00% | 6 October 2007 |
| CVE-2007-5257 | Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allows remote attackers to execute arbitrary code via long strings in the first and second arguments to the… | EXPLOIT ✓HIGH 10.0EPSS 15.2% | 6 October 2007 |
| CVE-2007-5256 | Multiple stack-based buffer overflows in FSD 2.052 d9 and earlier, and FSFDT FSD 3.000 d9 and earlier, allow (1) remote attackers to execute arbitrary code via a long HELP command on TCP port 3010 to the sysuser::exechelp function in sysuser.cc and (2)… | EXPLOIT ×3 ✓HIGH 7.5EPSS 7.07% | 6 October 2007 |
| CVE-2007-5255 | Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance 3.4.14 allows remote attackers to inject arbitrary web script or HTML via the ie parameter to the /search URI. | EXPLOIT ✓MEDIUM 4.3EPSS 2.02% | 6 October 2007 |
| CVE-2007-5253 | c32web.exe in McMurtrey/Whitaker Cart32 before 6.4 allows remote attackers to read arbitrary files via the ImageName parameter in a GetImage action, by appending a NULL byte (%00) sequence followed by an image file extension, as demonstrated by a… | EXPLOIT ✓MEDIUM 5.0EPSS 8.87% | 6 October 2007 |
| CVE-2007-5248 | Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause… | EXPLOIT ✓HIGH 9.3EPSS 7.48% | 6 October 2007 |
| CVE-2007-5244 | Stack-based buffer overflow in Borland InterBase LI 8.0.0.53 through 8.1.0.253 on Linux, and possibly unspecified versions on Solaris, allows remote attackers to execute arbitrary code via a long attach request on TCP port 3050 to the open_marker_file… | EXPLOIT ×2 ✓HIGH 9.3EPSS 37.5% | 6 October 2007 |
| CVE-2007-5243 | Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0.257, allow remote attackers to execute arbitrary code via (1) a long service attach request on TCP port 3050 to the (a) SVC_attach… | EXPLOIT ×12 ✓HIGH 9.3EPSS 40.1% | 6 October 2007 |
| CVE-2007-5235 | Cross-site scripting (XSS) vulnerability in index.php in Uebimiau 2.7.2 through 2.7.10 allows remote attackers to inject arbitrary web script or HTML via the f_email parameter. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.21% | 6 October 2007 |
| CVE-2007-5234 | PHP remote file inclusion vulnerability in upload/common/footer.php in Ossigeno CMS 2.2 alpha3 allows remote attackers to execute arbitrary PHP code via a URL in the level parameter. | EXPLOIT ✓HIGH 7.5EPSS 42.3% | 5 October 2007 |
| CVE-2007-5233 | SQL injection vulnerability in index.php in Web Template Management System 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a readmore action. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 5 October 2007 |
| CVE-2007-5231 | Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to upload and execute arbitrary .php files by sending a modified MIME type. | EXPLOIT ✓MEDIUM 4.6EPSS 1.94% | 5 October 2007 |
| CVE-2007-5230 | admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform administrative actions via a direct request. | EXPLOIT ✓HIGH 7.5EPSS 4.66% | 5 October 2007 |
| CVE-2007-5229 | Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attackers to change settings and hijack blog feeds via a request to wp-admin/options-general.php that submits parameter values to… | EXPLOIT ✓MEDIUM 6.4EPSS 4.90% | 5 October 2007 |
| CVE-2007-5225 | Integer signedness error in FIFO filesystems (named pipes) on Sun Solaris 8 through 10 allows local users to read the contents of unspecified memory locations via a negative maximum length value to the I_PEEK ioctl. | EXPLOIT ✓MEDIUM 4.9EPSS 0.97% | 5 October 2007 |
| CVE-2007-5222 | SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQL commands via a "Firefox ID=" substring in a Referer HTTP header. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.65% | 5 October 2007 |
| CVE-2007-5221 | PHP remote file inclusion vulnerability in mail/childwindow.inc.php in Poppawid 2.7 allows remote attackers to execute arbitrary PHP code via a URL in the form parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.71% | 5 October 2007 |
| CVE-2007-5219 | Directory traversal vulnerability in the CLAVSetting.CLSetting.1 ActiveX control in CLAVSetting.DLL 1.00.1829 in the CLAVSetting module in CyberLink PowerDVD 7.0 allows remote attackers to create or overwrite arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.4EPSS 15.7% | 5 October 2007 |
| CVE-2007-5218 | Cross-site scripting (XSS) vulnerability in index.php in Don Barnes DRBGuestbook 1.1.13 allows remote attackers to inject arbitrary web script or HTML via the action parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.73% | 5 October 2007 |
| CVE-2007-5217 | Stack-based buffer overflow in the ADM4 ActiveX control in adm4.dll in Altnet Download Manager 4.0.0.6, as used in (1) Kazaa 3.2.7 and (2) Grokster, allows remote attackers to execute arbitrary code via a long argument to the Install method. | EXPLOIT ✓MEDIUM 6.8EPSS 30.0% | 5 October 2007 |
| CVE-2007-5198 | Buffer overflow in the redir function in check_http.c in Nagios Plugins before 1.4.10, when running with the -f (follow) option, allows remote web servers to execute arbitrary code via Location header responses (redirects) with a large number of leading… | EXPLOIT ✓MEDIUM 6.8EPSS 8.02% | 4 October 2007 |
| CVE-2007-5187 | SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the sel parameter. | EXPLOIT ✓HIGH 7.5EPSS 4.19% | 3 October 2007 |
| CVE-2007-5186 | PHP remote file inclusion vulnerability in index.php in Segue CMS 1.8.4 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the themesdir parameter, a different vector than CVE-2006-5497. | EXPLOIT ✓MEDIUM 6.8EPSS 46.8% | 3 October 2007 |
| CVE-2007-5185 | Multiple PHP remote file inclusion vulnerabilities in phpWCMS XT 0.0.7 BETA and earlier allow remote attackers to execute arbitrary PHP code via a URL in the HTML_MENU_DirPath parameter to (1) config_HTML_MENU.php and (2) config_PHPLM.php in… | EXPLOIT ✓MEDIUM 6.8EPSS 42.3% | 3 October 2007 |
| CVE-2007-5184 | Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute arbitrary code via format string specifiers in a directory name. | EXPLOIT ✓HIGH 7.5EPSS 12.5% | 3 October 2007 |
| CVE-2007-5181 | SQL injection vulnerability in detay.asp in Netkamp Emlak Scripti allows remote attackers to execute arbitrary SQL commands via the ilan_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.18% | 3 October 2007 |
| CVE-2007-5180 | Multiple SQL injection vulnerabilities in Ohesa Emlak Portali allow remote attackers to execute arbitrary SQL commands via the (1) Kategori parameter in satilik.asp and the (2) Emlak parameter in detay.asp. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.19% | 3 October 2007 |
| CVE-2007-5178 | contrib/mx_glance_sdesc.php in the mx_glance 2.3.3 module for mxBB places a critical security check within a comment because of a missing comment delimiter, which allows remote attackers to conduct remote file inclusion attacks and execute arbitrary PHP… | EXPLOIT ✓MEDIUM 6.8EPSS 3.01% | 3 October 2007 |
| CVE-2007-5177 | SQL injection vulnerability in index.php in the MambAds (com_mambads) 1.5 and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the caid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 3 October 2007 |
| CVE-2007-5175 | PHP remote file inclusion vulnerability lib/base.php in actSite 1.991 Beta allows remote attackers to execute arbitrary PHP code via a URL in the BaseCfg[BaseDir] parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.98% | 3 October 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.