SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,576 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026

25,049 results · page 323 of 501

CVESummaryPriorityPublished
CVE-2007-5053Multiple incomplete blacklist vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the admin_home parameter to modules/poll/poll_summary.php or (2) the rootdp parameter to include/db.php;…EXPLOIT ✓HIGH 7.5EPSS 2.16%24 September 2007
CVE-2007-4573The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to…EXPLOIT ×2 ✓HIGH 7.2EPSS 0.82%24 September 2007
CVE-2007-5052Multiple cross-site scripting (XSS) vulnerabilities in index.php in Vigile CMS 1.8 allow remote attackers to inject arbitrary web script or HTML via a request to the wiki module with (1) the title parameter or (2) a "title=" sequence in the PATH_INFO,…EXPLOIT ✓MEDIUM 4.3EPSS 1.51%24 September 2007
CVE-2007-5050Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.98%24 September 2007
CVE-2007-5036Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated users to cause a denial of service (HTTPS service outage) via a crafted query string in an HTTPS request to (1) adLog.cgi, (2)…EXPLOIT ✓MEDIUM 5.0EPSS 9.62%24 September 2007
CVE-2007-5027Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/ddns in the web management panel for the WBR3404TX broadband router with firmware R1.94p0vTIG allow remote attackers to inject arbitrary web script or HTML via the (1) DD or (2) DU parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.67%21 September 2007
CVE-2007-5026dBlog CMS, probably 2.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for dblog.mdb.EXPLOIT ✓MEDIUM 5.0EPSS 2.53%21 September 2007
CVE-2007-5019Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attackers to have an unknown impact via a long argument to the dnsResolve (isInstalled.dnsResolve) method.EXPLOIT ✓HIGH 10.0EPSS 10.5%20 September 2007
CVE-2007-5018Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command.EXPLOIT ✓MEDIUM 6.0EPSS 3.65%20 September 2007
CVE-2007-5017Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo!EXPLOIT ✓MEDIUM 5.0EPSS 2.55%20 September 2007
CVE-2007-5016SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands via the abc parameter.EXPLOIT ✓HIGH 7.5EPSS 1.02%20 September 2007
CVE-2007-5015Multiple PHP remote file inclusion vulnerabilities in Streamline PHP Media Server 1.0-beta4 allow remote attackers to execute arbitrary PHP code via a URL in the sl_theme_unix_path parameter to (1) admin_footer.php, (2) info_footer.php, (3)…EXPLOIT ✓MEDIUM 6.8EPSS 38.6%20 September 2007
CVE-2007-5011webbatch.exe in WebBatch allows remote attackers to obtain sensitive information via the dumpinputdata parameter.EXPLOIT ✓MEDIUM 5.0EPSS 2.45%20 September 2007
CVE-2007-5010Cross-site scripting (XSS) vulnerability in WebBatch allows remote attackers to inject arbitrary web script or HTML via the URL to webbatch.exe.EXPLOIT ✓MEDIUM 4.3EPSS 1.51%20 September 2007
CVE-2007-5009PHP remote file inclusion vulnerability in language/lang_german/lang_main_album.php in phpBB Plus 1.53, and 1.53a before 20070922, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.EXPLOIT ✓MEDIUM 6.8EPSS 45.0%20 September 2007
CVE-2007-4984SQL injection vulnerability in index.php in the Ktauber.com StylesDemo mod for phpBB 2.0.xx allows remote attackers to execute arbitrary SQL commands via the s parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%19 September 2007
CVE-2007-4983Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic and 7.0.3.3016 allows remote attackers to create or overwrite arbitrary local files via a ..\ (dot dot backslash) in the second…EXPLOIT ✓HIGH 10.0EPSS 47.3%19 September 2007
CVE-2007-4982Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Technologies QRCode ActiveX 3.0.0.1 and earlier allow remote attackers to create or overwrite arbitrary files via a full pathname in the…EXPLOIT ✓HIGH 10.0EPSS 10.4%19 September 2007
CVE-2007-4980The readRequest method in org/gcaldaemon/core/http/HTTPListener.java in GCALDaemon 1.0-beta13 allows remote attackers to cause a denial of service via a large integer value in the Content-Length HTTP header, which triggers a fatal Java OutOfMemoryError.EXPLOIT ✓MEDIUM 4.3EPSS 4.76%19 September 2007
CVE-2007-4979SQL injection vulnerability in index.php in the sondages module in KwsPHP 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a results action, a different module than CVE-2007-4956.2.EXPLOIT ✓HIGH 7.5EPSS 1.01%19 September 2007
CVE-2007-4978Multiple PHP remote file inclusion vulnerabilities in phpSyncML 0.1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter to (1) Decoder.php and (2) Encoder.php in WBXML/.EXPLOIT ✓HIGH 7.5EPSS 2.76%19 September 2007
CVE-2007-4977Cross-site scripting (XSS) vulnerability in mode.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the referer parameter.EXPLOIT ✓LOW 3.5EPSS 3.38%19 September 2007
CVE-2007-4976Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.5EPSS 8.52%19 September 2007
CVE-2007-4975Cross-site scripting (XSS) vulnerability in hilfe.php in b1gMail 6.3.1 allows remote attackers to inject arbitrary web script or HTML via the chapter parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.74%19 September 2007
CVE-2007-4966SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_delete[] parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.46%18 September 2007
CVE-2007-4965Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the…EXPLOIT ✓MEDIUM 5.8EPSS 14.0%18 September 2007
CVE-2007-4964WinImage 8.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via an invalid BPB_BytsPerSec field in the header of a .IMG file.EXPLOIT ✓MEDIUM 5.0EPSS 2.81%18 September 2007
CVE-2007-4962Directory traversal vulnerability in WinImage 8.10 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a ..EXPLOIT ✓HIGH 9.3EPSS 5.99%18 September 2007
CVE-2007-3010Alcatel OmniPCX Enterprise Remote Code Execution VulnerabilityKEVEXPLOIT ×3 ✓CRITICAL 9.8EPSS 97.4%18 September 2007
CVE-2007-4957Multiple directory traversal vulnerabilities in download.php in Chupix CMS 0.2.3 allow remote attackers to read or overwrite arbitrary files via a ..EXPLOIT ✓HIGH 7.5EPSS 7.38%18 September 2007
CVE-2007-4956Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to login.php, (2) the id parameter to index.php in a carnet editer action in the Member_Space (espace_membre)…EXPLOIT ×3 ✓HIGH 7.5EPSS 3.53%18 September 2007
CVE-2007-4955PHP remote file inclusion vulnerability in admin.joomlaflashfun.php in the Flash Fun!EXPLOIT ✓MEDIUM 6.8EPSS 30.0%18 September 2007
CVE-2007-4954PHP remote file inclusion vulnerability in admin.joom12pic.php in the joom12Pic (com_joom12pic) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.EXPLOIT ✓MEDIUM 6.8EPSS 28.7%18 September 2007
CVE-2007-4953SQL injection vulnerability in index.php in SimpCMS allows remote attackers to execute arbitrary SQL commands via the keyword parameter in a search site action.EXPLOIT ✓HIGH 7.5EPSS 1.01%18 September 2007
CVE-2007-4952SQL injection vulnerability in article.php in OmniStar Article Manager allows remote attackers to execute arbitrary SQL commands via the page_id parameter in a favorite op action, a different vector than CVE-2006-5917.EXPLOIT ✓HIGH 7.5EPSS 0.95%18 September 2007
CVE-2007-4942PHP remote file inclusion vulnerability in modules/Discipline/StudentFieldBreakdown.php in Focus/SIS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the FocusPath parameter, a different vector than CVE-2007-4806.EXPLOIT ✓HIGH 7.5EPSS 2.28%18 September 2007
CVE-2007-4941KMPlayer 2.9.3.1210 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a .avi file with certain large "indx truck size" and nEntriesInuse values.EXPLOIT ✓HIGH 7.1EPSS 3.09%18 September 2007
CVE-2007-4939Heap-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allows remote attackers to cause a denial of service…EXPLOIT ✓HIGH 9.3EPSS 11.9%18 September 2007
CVE-2007-4938Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and…EXPLOIT ✓HIGH 7.6EPSS 16.0%18 September 2007
CVE-2007-4937CS Guestbook stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin name and MD5 password hash via a direct request for base/usr/0.php.EXPLOIT ✓MEDIUM 5.0EPSS 2.58%18 September 2007
CVE-2007-4934Multiple PHP remote file inclusion vulnerabilities in phpFFL 1.24 allow remote attackers to execute arbitrary PHP code via a URL in the PHPFFL_FILE_ROOT parameter to (1) program_files/livedraft/livedraft.php or (2) program_files/livedraft/admin.php.EXPLOIT ✓MEDIUM 4.6EPSS 21.7%18 September 2007
CVE-2007-4933Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and earlier allows remote attackers to inject arbitrary PHP code into cfg/appearence.inc.php via a save_appearence action in admin.php, as…EXPLOIT ✓HIGH 7.5EPSS 2.41%18 September 2007
CVE-2007-4932admin.php in Shop-Script FREE 2.0 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to access the admin panel.EXPLOIT ✓HIGH 7.5EPSS 2.51%18 September 2007
CVE-2007-4930Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 207W camera allow remote attackers to perform certain actions as administrators via (1) axis-cgi/admin/restart.cgi, (2) the user and sgrp parameters to axis-cgi/admin/pwdgrp.cgi in…EXPLOIT ×3 ✓MEDIUM 4.3EPSS 2.18%18 September 2007
CVE-2007-4925The ewirePC_Decrypt function in ewirepcfunctions.php in eWire Payment Client (ePC) 1.60 and 1.70 allows remote attackers to execute arbitrary commands via shell metacharacters in the paymentinfo parameter to simplePHPLinux/3payment_receive.php.EXPLOIT ✓HIGH 7.5EPSS 3.17%18 September 2007
CVE-2007-4923PHP remote file inclusion vulnerability in admin.joomlaradiov5.php in the Joomla Radio 5 (com_joomlaradiov5) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.EXPLOIT ✓MEDIUM 6.8EPSS 41.6%17 September 2007
CVE-2007-4922SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a play ac action to index.php.EXPLOIT ✓MEDIUM 6.5EPSS 0.86%17 September 2007
CVE-2007-4921PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attackers to execute arbitrary PHP code via a URL in the approot parameter.EXPLOIT ✓HIGH 7.5EPSS 52.8%17 September 2007
CVE-2007-4920SQL injection vulnerability in soporte_derecha_w.php in PHP Webquest 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter.EXPLOIT ✓HIGH 7.5EPSS 1.17%17 September 2007
CVE-2007-4919Multiple SQL injection vulnerabilities in JBlog 1.0 allow (1) remote attackers to execute arbitrary SQL commands via the id parameter to index.php, and allow (2) remote authenticated administrators to execute arbitrary SQL commands via the id parameter…EXPLOIT ×2 ✓HIGH 7.5EPSS 0.99%17 September 2007

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.