Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,612 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 327 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-4439 | PHP remote file inclusion vulnerability in popup_window.php in Squirrelcart 1.x.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_isp_root parameter, probably related to cart.php. | EXPLOIT ✓HIGH 7.5EPSS 2.44% | 21 August 2007 |
| CVE-2007-4434 | Cross-site scripting (XSS) vulnerability in textfilesearch.asp in the Text File Search ASP (Classic) edition allows remote attackers to inject arbitrary web script or HTML via the query parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.52% | 20 August 2007 |
| CVE-2007-4430 | Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. | EXPLOIT ✓MEDIUM 5.0EPSS 13.3% | 20 August 2007 |
| CVE-2007-4420 | Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw Office Viewer Component 5.1 allows remote attackers to create or overwrite arbitrary files via a full pathname in the second argument to the… | EXPLOIT ✓HIGH 9.3EPSS 2.92% | 18 August 2007 |
| CVE-2007-4419 | Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for remote attackers to guess the cookie and access the Admin area. | EXPLOIT ✓HIGH 9.3EPSS 4.83% | 18 August 2007 |
| CVE-2007-4391 | Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! | EXPLOIT ×2 ✓HIGH 9.3EPSS 9.31% | 17 August 2007 |
| CVE-2007-4390 | The Command Line Interface (CLI), aka Adonis Administration Console, on the BlueCat Networks Adonis DNS/DHCP appliance 5.0.2.8 allows local admin users to gain root privileges on the underlying operating system via shell metacharacters in a command. | EXPLOIT ✓HIGH 7.2EPSS 1.01% | 17 August 2007 |
| CVE-2007-4389 | Cross-site request forgery (CSRF) vulnerability in /xslt in 2wire 1701HG, 1800HW, and 2071 Gateway routers, with 3.17.5, 3.7.1, and 5.29.51 software, allows remote attackers to create DNS mappings as administrators, and conduct DNS poisoning attacks,… | EXPLOIT ✓HIGH 7.8EPSS 2.14% | 17 August 2007 |
| CVE-2007-4386 | SQL injection vulnerability in search.php in GetMyOwnArcade allows remote attackers to execute arbitrary SQL commands via the query parameter. | EXPLOIT ✓MEDIUM 6.0EPSS 1.01% | 17 August 2007 |
| CVE-2007-4385 | OWASP Stinger before 2.5 allows remote attackers to bypass input validation routines by using multipart encoded requests instead of form-urlencoded requests. | EXPLOIT ✓MEDIUM 6.8EPSS 3.08% | 17 August 2007 |
| CVE-2007-4384 | Multiple PHP remote file inclusion vulnerabilities in depouilg.php3 in Stephane Pineau VOTE 1c allow remote attackers to execute arbitrary PHP code via a URL in the (1) NomVote and (2) FilePalHex parameters. | EXPLOIT ✓MEDIUM 6.8EPSS 2.09% | 17 August 2007 |
| CVE-2007-4382 | CounterPath X-Lite 3.0 34025, and possibly eyeBeam, allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Content-Type header. | EXPLOIT ✓MEDIUM 5.0EPSS 3.14% | 17 August 2007 |
| CVE-2007-4381 | Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself. | EXPLOIT ✓HIGH 9.3EPSS 5.42% | 17 August 2007 |
| CVE-2007-4377 | Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argument to the SEARCH command. | EXPLOIT ✓MEDIUM 6.0EPSS 5.01% | 16 August 2007 |
| CVE-2007-4375 | The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versions exposes a memory comparison function via RPC over TCP, which allows remote attackers to (1) obtain sensitive information (process… | EXPLOIT ✓MEDIUM 5.8EPSS 3.38% | 16 August 2007 |
| CVE-2007-4370 | Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbitrary code via a long string to UDP port 26000. | EXPLOIT ×3 ✓HIGH 7.5EPSS 59.2% | 15 August 2007 |
| CVE-2007-4369 | Directory traversal vulnerability in go/_files in SOTEeSKLEP before 4.0 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.49% | 15 August 2007 |
| CVE-2007-4368 | SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter in a GenerateMainFrame command. | EXPLOIT ✓HIGH 7.5EPSS 3.31% | 15 August 2007 |
| CVE-2007-4366 | WengoPhone 2.1 allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Content-Type header. | EXPLOIT ✓MEDIUM 5.0EPSS 3.36% | 15 August 2007 |
| CVE-2007-4362 | SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.15% | 15 August 2007 |
| CVE-2007-4359 | Multiple SQL injection vulnerabilities in SkilMatch Staffing Systems JobLister3 allow remote attackers to execute arbitrary SQL commands via (1) the search form or (2) the jobid parameter to index.php in a showbyID action. | EXPLOIT ✓MEDIUM 6.8EPSS 1.10% | 15 August 2007 |
| CVE-2007-4358 | Zoidcom 0.6.7 and earlier allows remote attackers to cause a denial of service (application crash) via a JOIN packet (aka connection packet) containing 0x69 in the ninth byte, which triggers a "double-delete" of trace data, a different vulnerability… | EXPLOIT ✓MEDIUM 4.3EPSS 2.85% | 15 August 2007 |
| CVE-2007-3386 | Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter… | EXPLOIT ✓MEDIUM 4.3EPSS 59.0% | 14 August 2007 |
| CVE-2007-3382 | Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers… | EXPLOIT ✓MEDIUM 4.3EPSS 37.5% | 14 August 2007 |
| CVE-2007-1749 | Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size,… | EXPLOIT ✓HIGH 9.3EPSS 41.5% | 14 August 2007 |
| CVE-2007-3034 | Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted metafile (image) with a large record length… | EXPLOIT ✓HIGH 9.3EPSS 51.9% | 14 August 2007 |
| CVE-2007-2223 | Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow. | EXPLOIT ✓HIGH 9.3EPSS 48.7% | 14 August 2007 |
| CVE-2007-2216 | The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation, which allows remote attackers to execute arbitrary code by requesting the HelpString property, involving a… | EXPLOIT ✓HIGH 9.3EPSS 41.4% | 14 August 2007 |
| CVE-2007-4341 | PHP remote file inclusion vulnerability in adm/my_statistics.php in Omnistar Lib2 PHP 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.69% | 14 August 2007 |
| CVE-2007-4338 | index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's name in the value of an fcms_login_id cookie. | EXPLOIT ✓HIGH 10.0EPSS 8.92% | 14 August 2007 |
| CVE-2007-4336 | Buffer overflow in the Live Picture Corporation DXSurface.LivePicture.FlashPix.1 (DirectTransform FlashPix) ActiveX control in DXTLIPI.DLL 6.0.2.827, as packaged in Microsoft DirectX Media 6.0 SDK, allows remote attackers to execute arbitrary code via a… | EXPLOIT ✓MEDIUM 4.3EPSS 50.7% | 14 August 2007 |
| CVE-2007-4334 | Cross-site scripting (XSS) vulnerability in whois.php in Php-stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML via the IP parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.77% | 14 August 2007 |
| CVE-2007-4330 | PHP remote file inclusion vulnerability in shoutbox.php in Shoutbox 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.80% | 14 August 2007 |
| CVE-2007-4329 | Multiple PHP remote file inclusion vulnerabilities in Web News 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php, (2) news.php, or (3) feed.php. | EXPLOIT ×3 ✓MEDIUM 6.8EPSS 7.03% | 14 August 2007 |
| CVE-2007-4328 | Multiple PHP remote file inclusion vulnerabilities in Mapos Bilder Galerie 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php, (2) galerie.php, or (3) anzagien.php. | EXPLOIT ✓MEDIUM 6.8EPSS 6.46% | 14 August 2007 |
| CVE-2007-4327 | Multiple PHP remote file inclusion vulnerabilities in File Uploader 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php or (2) datei.php. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 3.13% | 14 August 2007 |
| CVE-2007-4325 | PHP remote file inclusion vulnerability in index.php in Gaestebuch 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.77% | 14 August 2007 |
| CVE-2007-4321 | fail2ban 0.8 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by adding arbitrary IP addresses to the sshd log file, as demonstrated by… | EXPLOIT ✓MEDIUM 6.8EPSS 5.75% | 14 August 2007 |
| CVE-2007-4320 | PHP remote file inclusion vulnerability in admin/addons/archive/archive.php in Ncaster 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the adminfolder parameter. | EXPLOIT ✓HIGH 7.5EPSS 72.0% | 14 August 2007 |
| CVE-2007-4318 | Cross-site scripting (XSS) vulnerability in Forms/General_1 in the management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allows remote authenticated administrators to inject arbitrary web script or HTML via the sysSystemName… | EXPLOIT ✓MEDIUM 4.3EPSS 2.31% | 13 August 2007 |
| CVE-2007-4314 | pixlie.php in Pixlie 1.7 allows remote attackers to trigger the reading and JPEG image processing of files in a remote directory tree via a URL in the root parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.81% | 13 August 2007 |
| CVE-2007-4313 | PHP remote file inclusion vulnerability in public_includes/pub_blocks/activecontent.php in Php Blue Dragon CMS 3.0.0 allows remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter, a different vector than… | EXPLOIT ✓MEDIUM 6.8EPSS 68.7% | 13 August 2007 |
| CVE-2007-4312 | SQL injection vulnerability in index.php in Php Blue Dragon CMS 3.0.0 allows remote attackers to execute arbitrary SQL commands via the article_id parameter in a "print articles" action. | EXPLOIT ✓HIGH 7.5EPSS 1.03% | 13 August 2007 |
| CVE-2007-4305 | Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies in Systrace on NetBSD and OpenBSD allow local users to defeat system call interposition, and consequently bypass access control policy and auditing. | EXPLOIT ✓MEDIUM 6.2EPSS 0.86% | 13 August 2007 |
| CVE-2007-4302 | Multiple race conditions in certain system call wrappers in Generic Software Wrappers Toolkit (GSWTK) allow local users to defeat system call interposition and possibly gain privileges or bypass auditing. | EXPLOIT ✓MEDIUM 6.2EPSS 0.72% | 13 August 2007 |
| CVE-2007-4288 | Microsoft Windows Media Player 11 (wmplayer.exe) allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .au file that triggers a divide-by-zero error, as demonstrated by iapetus.au. | EXPLOIT ✓MEDIUM 4.3EPSS 14.8% | 9 August 2007 |
| CVE-2007-4287 | PHP remote file inclusion vulnerability in fc_functions/fc_example.php in FishCart 3.2 RC2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the docroot parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.68% | 9 August 2007 |
| CVE-2007-4286 | Buffer overflow in the Next Hop Resolution Protocol (NHRP) functionality in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (restart) and execute arbitrary code via a crafted NHRP packet. | EXPLOIT ✓HIGH 9.3EPSS 19.4% | 9 August 2007 |
| CVE-2007-4283 | PHP remote file inclusion vulnerability in bridge/yabbse.inc.php in Coppermine Photo Gallery (CPG) 1.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the sourcedir parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.37% | 9 August 2007 |
| CVE-2007-4279 | PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter. | EXPLOIT ✓HIGH 7.5EPSS 75.3% | 9 August 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.