Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,576 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 325 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-4757 | PHP remote file inclusion vulnerability in menu.php in phpMytourney allows remote attackers to execute arbitrary PHP code via a URL in the functions_file parameter. | EXPLOIT ✓HIGH 7.5EPSS 64.7% | 8 September 2007 |
| CVE-2007-4754 | Format string vulnerability in the safe_bprintf function in acesrc/acebot_cmds.c in Alien Arena 2007 6.10 and earlier allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in a nickname. | EXPLOIT ✓HIGH 7.5EPSS 4.80% | 8 September 2007 |
| CVE-2007-4748 | Buffer overflow in the PowerPlayer.dll ActiveX control in PPStream 2.0.1.3829 allows remote attackers to execute arbitrary code via a long Logo parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 7.21% | 6 September 2007 |
| CVE-2007-4744 | PHP remote file inclusion vulnerability in environment.php in AnyInventory 1.9.1 and 2.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DIR_PREFIX parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 60.1% | 6 September 2007 |
| CVE-2007-3913 | SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 2.01% | 6 September 2007 |
| CVE-2007-4740 | The HPRevolutionRegistryManager ActiveX control in Hp.Revolution.RegistryManager.dll 1 in Telecom Italy Alice Messenger allows remote attackers to create registry keys and values via the arguments to the WriteRegistry method. | EXPLOIT ✓HIGH 9.3EPSS 3.72% | 6 September 2007 |
| CVE-2007-4738 | Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) db_conf or (2) ADODB_DIR parameter to utils/stphpimage_show.php; or a URL in the… | EXPLOIT ✓HIGH 7.5EPSS 10.7% | 6 September 2007 |
| CVE-2007-4737 | Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the STPHPLIB_DIR parameter to (1) stphpapplication.php, (2) stphpbtnimage.php, or (3)… | EXPLOIT ✓HIGH 7.5EPSS 8.61% | 6 September 2007 |
| CVE-2007-4736 | SQL injection vulnerability in category.php in CartKeeper CKGold Shopping Cart 2.0 allows remote attackers to execute arbitrary SQL commands via the category_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 6 September 2007 |
| CVE-2007-4735 | Buffer overflow in Next Generation Software Virtual DJ (VDJ) 5.0 allows user-assisted remote attackers to execute arbitrary code via a long file path in an m3u file. | EXPLOIT ✓HIGH 9.3EPSS 6.98% | 6 September 2007 |
| CVE-2007-4734 | Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a long file path in an m3u file. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 5.59% | 6 September 2007 |
| CVE-2007-4726 | Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.73% | 5 September 2007 |
| CVE-2007-4725 | Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assisted remote attackers to execute arbitrary code via a long filename in an archive, leading to a… | EXPLOIT ✓MEDIUM 6.8EPSS 5.56% | 5 September 2007 |
| CVE-2007-4722 | Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie07051001.dll 1.0.0.1 in Move Media Player allow remote attackers to execute arbitrary code via a long string to the (1) Play and (2) Buzzer… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 10.1% | 5 September 2007 |
| CVE-2007-4719 | SQL injection vulnerability in read.php in 212cafeBoard 6.30 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.14% | 5 September 2007 |
| CVE-2007-4718 | Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 5.1EPSS 7.48% | 5 September 2007 |
| CVE-2007-4717 | Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) dir parameter in admin/adminusers.php, the (2) action parameter in… | EXPLOIT ×3 ✓LOW 3.5EPSS 3.11% | 5 September 2007 |
| CVE-2007-4715 | Multiple PHP remote file inclusion vulnerabilities in Weblogicnet allow remote attackers to execute arbitrary PHP code via a URL in the files_dir parameter in (1) es_desp.php, (2) es_custom_menu.php, and (3) es_offer.php. | EXPLOIT ✓HIGH 7.5EPSS 4.13% | 5 September 2007 |
| CVE-2007-4714 | SQL injection vulnerability in error_view.php in Yvora 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 5 September 2007 |
| CVE-2007-4712 | PHP remote file inclusion vulnerability in index.php in eNetman 1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 57.9% | 5 September 2007 |
| CVE-2007-4711 | Multiple cross-site scripting (XSS) vulnerabilities in Toms Gaestebuch 1.00 allow remote attackers to inject arbitrary web script or HTML via the (1) homepage, (2) mail, and (3) name parameters in a show action to (a) form.php; the (4) language and (5)… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 3.87% | 5 September 2007 |
| CVE-2007-4476 | Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack." | EXPLOIT ✓HIGH 7.5EPSS 14.9% | 5 September 2007 |
| CVE-2007-4653 | SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter in a search action. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 4 September 2007 |
| CVE-2007-4652 | The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir restrictions via a session file that is a symlink. | EXPLOIT ✓MEDIUM 4.4EPSS 0.61% | 4 September 2007 |
| CVE-2007-3997 | The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir restrictions via MySQL LOCAL INFILE operations, as demonstrated by a query with LOAD DATA LOCAL INFILE. | EXPLOIT ✓HIGH 7.5EPSS 13.8% | 4 September 2007 |
| CVE-2007-4649 | MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for their installation directory trees, which allows local users to gain privileges by replacing application… | EXPLOIT ✓HIGH 7.2EPSS 0.89% | 31 August 2007 |
| CVE-2007-4648 | The nvcoaft51 driver in Norman Virus Control (NVC) 5.82 uses weak permissions (unrestricted write access) for the NvcOa device, which allows local users to gain privileges by (1) triggering a buffer overflow in a kernel pool via a string argument to… | EXPLOIT ✓HIGH 7.2EPSS 0.92% | 31 August 2007 |
| CVE-2007-4647 | newswire/uploadmedia.cgi in 2coolcode Our Space (Ourspace) 2.0.9 allows remote attackers to upload certain files via unspecified vectors, probably involving unrestricted functionality in uploadmedia.cgi. | EXPLOIT ✓MEDIUM 5.0EPSS 2.36% | 31 August 2007 |
| CVE-2007-4646 | Buffer overflow in the pop3 service in Hexamail Server 3.0.0.001 Lite allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long USER command. | EXPLOIT ✓HIGH 10.0EPSS 15.5% | 31 August 2007 |
| CVE-2007-4645 | SQL injection vulnerability in index.php in NMDeluxe 2.0.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a newspost do action, a different vulnerability than CVE-2006-1108. | EXPLOIT ✓MEDIUM 6.4EPSS 1.17% | 31 August 2007 |
| CVE-2007-4642 | Multiple buffer overflows in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allow remote attackers to execute arbitrary code via a long chat (PKT_CHAT) message that is not properly handled by the (1) D_NetPlayerEvent function in d_net.c or the (2)… | EXPLOIT ✓HIGH 10.0EPSS 16.3% | 31 August 2007 |
| CVE-2007-4641 | Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.4EPSS 2.67% | 31 August 2007 |
| CVE-2007-4640 | Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload and execute arbitrary PHP files in uploads/ via an Uploads action. | EXPLOIT ✓MEDIUM 6.4EPSS 2.43% | 31 August 2007 |
| CVE-2007-4639 | EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbg_create_listener, which allows remote authenticated users to cause a denial of service (daemon crash) and possibly execute… | EXPLOIT ✓MEDIUM 6.5EPSS 5.13% | 31 August 2007 |
| CVE-2007-4638 | Blizzard Entertainment StarCraft Brood War 1.15.1 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed map, which triggers an out-of-bounds read during a minimap preview. | EXPLOIT ✓MEDIUM 4.3EPSS 6.18% | 31 August 2007 |
| CVE-2007-4637 | xGB.php in xGB 2.0 does not require authentication for an admin edit action, which allows remote attackers to make unspecified changes via an unknown series of steps. | EXPLOIT ✓MEDIUM 6.4EPSS 2.17% | 31 August 2007 |
| CVE-2007-4636 | Multiple PHP remote file inclusion vulnerabilities in phpBG 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter to (1) intern/admin/other/backup.php, (2) intern/admin/, (3) intern/clan/member_add.php, (4)… | EXPLOIT ✓HIGH 7.5EPSS 71.1% | 31 August 2007 |
| CVE-2007-4635 | Messenger 8.1.0.209 and 8.1.0.402 allows remote attackers to cause a denial of service (application crash) via certain file-transfer packets, possibly involving a buffer overflow, as demonstrated by ym8bug.exe. | EXPLOIT ✓MEDIUM 5.0EPSS 2.15% | 31 August 2007 |
| CVE-2007-4634 | Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to execute arbitrary SQL commands via… | EXPLOIT ✓HIGH 9.3EPSS 4.31% | 31 August 2007 |
| CVE-2007-4515 | Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! | EXPLOIT ×2 ✓HIGH 9.3EPSS 33.0% | 31 August 2007 |
| CVE-2007-2931 | Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat… | EXPLOIT ×2 ✓HIGH 9.3EPSS 55.5% | 31 August 2007 |
| CVE-2007-4630 | Cross-site scripting (XSS) vulnerability in xlaapmview.asp in Absolute Poll Manager XE 4.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.01% | 31 August 2007 |
| CVE-2007-4628 | SQL injection vulnerability in shownews.php in phpns 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.33% | 31 August 2007 |
| CVE-2007-4627 | SQL injection vulnerability in index.php in ABC eStore 3.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.06% | 31 August 2007 |
| CVE-2007-4611 | SQL injection vulnerability in viewevent.php in Moonware (aka Dale Mooney Gallery) allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 31 August 2007 |
| CVE-2007-4607 | Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used in Postcast Server Pro 3.0.61 and other products, allows remote attackers to execute arbitrary code via a long argument to the… | EXPLOIT ×2 ✓HIGH 9.3EPSS 56.4% | 31 August 2007 |
| CVE-2007-4606 | PHP remote file inclusion vulnerability in convert/mvcw_conver.php in the Virtual War (VWar) module for PHPNuke-Clan (PNC) 4.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter, a different vector… | EXPLOIT ✓HIGH 7.5EPSS 2.13% | 31 August 2007 |
| CVE-2007-4605 | PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter, a different vector than CVE-2006-1503, CVE-2006-1636, and… | EXPLOIT ✓HIGH 7.5EPSS 2.13% | 31 August 2007 |
| CVE-2007-4604 | SQL injection vulnerability in viewitem.php in DL PayCart 1.01 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 31 August 2007 |
| CVE-2007-4603 | Multiple SQL injection vulnerabilities in index.php in ACG News 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter in a showarticle action or (2) the catid parameter in a showcat action. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.24% | 31 August 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.