Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,612 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 328 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-3872 | Multiple stack-based buffer overflows in the Shared Trace Service (OVTrace) service for HP OpenView Operations A.07.50 for Windows, and possibly earlier versions, allow remote attackers to execute arbitrary code via certain crafted requests. | EXPLOIT ✓MEDIUM 6.8EPSS 30.3% | 9 August 2007 |
| CVE-2007-4264 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) 1.5.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) path and (2) download… | EXPLOIT ✓MEDIUM 4.3EPSS 1.49% | 9 August 2007 |
| CVE-2007-4258 | SQL injection vulnerability in directory.php in Prozilla Pub Site Directory allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 8 August 2007 |
| CVE-2007-4257 | Multiple buffer overflows in Live for Speed (LFS) S1 and S2 allow user-assisted remote attackers to execute arbitrary code via (1) a .spr file (single player replay file) containing a long user name or (2) a .ply file containing a long number plate… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 4.77% | 8 August 2007 |
| CVE-2007-4256 | Directory traversal vulnerability in showpage.cgi in YNP Portal System 2.2.0 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 6.45% | 8 August 2007 |
| CVE-2007-4255 | Buffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a long first argument to the msql_connect function. | EXPLOIT ×2 ✓HIGH 7.5EPSS 9.33% | 8 August 2007 |
| CVE-2007-4254 | Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Designer 7.0 for Microsoft Visual Studio 6 allows remote attackers to execute arbitrary code via a long argument to the NotSafe method. | EXPLOIT ✓MEDIUM 6.8EPSS 11.5% | 8 August 2007 |
| CVE-2007-4253 | SQL injection vulnerability in the News module in modules.php in Envolution 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2005-4263. | EXPLOIT ✓HIGH 7.5EPSS 1.03% | 8 August 2007 |
| CVE-2007-4252 | Absolute path traversal vulnerability in a certain ActiveX control in CkString.dll 1.1 and earlier in CHILKAT ASP String allows remote attackers to create or overwrite arbitrary files via a full pathname in the first argument to the SaveToFile method, a… | EXPLOIT ✓MEDIUM 4.3EPSS 1.76% | 8 August 2007 |
| CVE-2007-4244 | PHP remote file inclusion vulnerability in langset.php in J! | EXPLOIT ✓HIGH 7.5EPSS 7.83% | 8 August 2007 |
| CVE-2007-4235 | Multiple PHP remote file inclusion vulnerabilities in VietPHP allow remote attackers to execute arbitrary PHP code via a URL in (1) the dirpath parameter to (a) _functions.php, or (2) the language parameter to (b) admin/index.php or (c) index.php. | EXPLOIT ×3 ✓HIGH 9.3EPSS 3.40% | 8 August 2007 |
| CVE-2007-4232 | PHP remote file inclusion vulnerability in admin/inc/change_action.php in Andreas Robertz PHPNews 0.93 allows remote attackers to execute arbitrary PHP code via a URL in the format_menue parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 51.7% | 8 August 2007 |
| CVE-2007-4231 | PHP remote file inclusion vulnerability in order/login.php in IDevSpot PhpHostBot 1.06 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the svr_rootscript parameter, a different vector than CVE-2007-4094 and CVE-2006-3776. | EXPLOIT ✓MEDIUM 6.8EPSS 3.58% | 8 August 2007 |
| CVE-2007-4229 | Unspecified vulnerability in KDE Konqueror 3.5.7 and earlier allows remote attackers to cause a denial of service (failed assertion and application crash) via certain malformed HTML, as demonstrated by a document containing TEXTAREA, BUTTON, BR, BDO,… | EXPLOIT ✓MEDIUM 4.3EPSS 2.18% | 8 August 2007 |
| CVE-2007-4226 | Directory traversal vulnerability in the BlueCat Networks Proteus IPAM appliance 2.0.2.0 (Adonis DNS/DHCP appliance 5.0.2.8) allows remote authenticated administrators, with certain TFTP privileges, to create and overwrite arbitrary files via a .. | EXPLOIT ✓HIGH 7.1EPSS 3.77% | 8 August 2007 |
| CVE-2007-4210 | Multiple SQL injection vulnerabilities in module.php in LANAI (la-nai) CMS 1.2.14 allow remote attackers to execute arbitrary SQL commands via (1) the mid parameter in an faqviewgroup action in the FAQ Modules, (2) the cid parameter in the EZSHOPINGCART… | EXPLOIT ×4 ✓HIGH 7.5EPSS 2.94% | 8 August 2007 |
| CVE-2007-4208 | SQL injection vulnerability in default.asp in Next Gen Portfolio Manager allows remote attackers to execute arbitrary SQL commands via the (1) Users_Email or (2) Users_Password parameter in an ExecuteTheLogin action. | EXPLOIT ✓HIGH 7.5EPSS 1.69% | 8 August 2007 |
| CVE-2007-4191 | Panda Antivirus 2008 stores service executables under the product's installation directory with weak permissions, which allows local users to obtain LocalSystem privileges by modifying PAVSRV51.EXE or other unspecified files, a related issue to… | EXPLOIT ✓MEDIUM 6.9EPSS 0.76% | 8 August 2007 |
| CVE-2007-4186 | PHP remote file inclusion vulnerability in admin.tour_toto.php in the Tour de France Pool (com_tour_toto) 1.0.1 module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 5.79% | 8 August 2007 |
| CVE-2007-4183 | SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 8 August 2007 |
| CVE-2007-4178 | Cross-site scripting (XSS) vulnerability in index.php in WebDirector 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the deslocal parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.54% | 8 August 2007 |
| CVE-2007-3845 | Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbitrary commands via certain vectors associated with launching "a file handling program based on the file… | EXPLOIT ✓HIGH 9.3EPSS 5.70% | 8 August 2007 |
| CVE-2007-3844 | Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an… | EXPLOIT ✓MEDIUM 4.3EPSS 5.45% | 8 August 2007 |
| CVE-2007-4174 | Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST… | EXPLOIT ×2 ✓MEDIUM 5.8EPSS 6.21% | 7 August 2007 |
| CVE-2007-4173 | SQL injection vulnerability in duyuruoku.asp in Hunkaray Okul Portali 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-3080. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 7 August 2007 |
| CVE-2007-4171 | SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI. | EXPLOIT ✓HIGH 7.5EPSS 1.40% | 7 August 2007 |
| CVE-2007-4156 | Multiple SQL injection vulnerabilities in wolioCMS allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to member.php in a page action, related to a SELECT statement in common.php; and the (2) loginid parameter (uid… | EXPLOIT ✓HIGH 7.5EPSS 1.26% | 3 August 2007 |
| CVE-2007-4155 | Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll in EMC VMware 6.0.0 allows remote attackers to execute arbitrary local programs via a full pathname in the first two arguments to the (1) CreateProcess or (2)… | EXPLOIT ✓HIGH 9.3EPSS 9.62% | 3 August 2007 |
| CVE-2007-4146 | Cross-site scripting (XSS) vulnerability in webevent.cgi in WebEvent 2.61 through 4.03 allows remote attackers to inject arbitrary web script or HTML via the cmd parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.49% | 3 August 2007 |
| CVE-2007-4145 | Heap-based buffer overflow in the BlueSkychat (BlueSkyCat) ActiveX control (V2.V2Ctrl.1) in v2.ocx 8.1.2.0 and earlier allows remote attackers to execute arbitrary code via a long string in the second argument to the ConnecttoServer method. | EXPLOIT ✓MEDIUM 4.3EPSS 5.30% | 3 August 2007 |
| CVE-2007-4143 | user.php in the Billing Control Panel in phpCoupon allows remote authenticated users to obtain Premium Member status, and possibly acquire free coupons, via a modified URL containing a certain billing parameter and REQ=auth, status=success, and… | EXPLOIT ✓MEDIUM 4.0EPSS 4.16% | 3 August 2007 |
| CVE-2007-4140 | Buffer overflow in Live for Speed (LFS) S2 ALPHA PATCH 0.5x allows user-assisted remote attackers to execute arbitrary code via a .mpr file (replay file) that contains a long car name. | EXPLOIT ✓MEDIUM 6.8EPSS 3.89% | 3 August 2007 |
| CVE-2007-4128 | SQL injection vulnerability in index.php in the Firestorm Technologies GMaps (com_gmaps) 1.00 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mapId parameter in a viewmap action. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 1 August 2007 |
| CVE-2007-4127 | PHP remote file inclusion vulnerability in check_entry.php in Ralf Image Gallery (RIG), aka Raphael Moll RIG Image Gallery, 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir_abs_src parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 3.01% | 1 August 2007 |
| CVE-2007-4119 | Multiple SQL injection vulnerabilities in yonetici.asp in Berthanas Ziyaretci Defteri 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) Pass fields. | EXPLOIT ✓HIGH 7.5EPSS 1.17% | 1 August 2007 |
| CVE-2007-4116 | SQL injection vulnerability in philboard_forum.asp in Metyus Forum Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.10% | 31 July 2007 |
| CVE-2007-4115 | Multiple cross-site scripting (XSS) vulnerabilities in IT!CMS (itcms) 0.2 allow remote attackers to inject arbitrary web script or HTML via the wndtitle parameter to (1) lang-en.php, (2) menu-ed.php, or (3) titletext-ed.php. | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 2.38% | 31 July 2007 |
| CVE-2007-4111 | SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as user or manager, allows remote attackers to execute arbitrary SQL commands via the Password parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.07% | 31 July 2007 |
| CVE-2007-4110 | SQL injection vulnerability in sign_in.aspx in Message Board / Threaded Discussion Forum Application Template allows remote attackers to execute arbitrary SQL commands via the Password parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.17% | 31 July 2007 |
| CVE-2007-4109 | SQL injection vulnerability in sign_in.aspx in WebStore (Online Store Application Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.18% | 31 July 2007 |
| CVE-2007-4106 | SQL injection vulnerability in login.asp in CodeWidgets Pay Roll - Time Sheet and Punch Card Application With Web Interface allows remote attackers to execute arbitrary SQL commands via the Password parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.07% | 31 July 2007 |
| CVE-2007-4105 | A certain ActiveX control in BaiduBar.dll in Baidu Soba Search Bar 5.4 allows remote attackers to execute arbitrary code via a request containing "a link to download and a file to execute," possibly involving remote file inclusion. | EXPLOIT ✓HIGH 9.3EPSS 7.32% | 31 July 2007 |
| CVE-2007-4104 | Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, one of which involves an rss2 feed with an invalid or missing… | EXPLOIT ✓MEDIUM 4.3EPSS 5.05% | 31 July 2007 |
| CVE-2007-4101 | Multiple PHP remote file inclusion vulnerabilities in Madoa Poll 1.1 allow remote attackers to execute arbitrary PHP code via the Madoa parameter to (1) index.php, (2) vote.php, and (3) admin.php. | EXPLOIT ×3 ✓MEDIUM 6.8EPSS 2.91% | 31 July 2007 |
| CVE-2007-4095 | SQL injection vulnerability in BSM Store Dependent Forums 1.02 allows remote attackers to execute arbitrary SQL commands via a Username field in an unspecified component, probably the FrmUserName parameter in login.asp. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 30 July 2007 |
| CVE-2007-4092 | Directory traversal vulnerability in index.php in iFoto 1.0.1 and earlier allows remote attackers to list arbitrary directories, and possibly download arbitrary photos, via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.69% | 30 July 2007 |
| CVE-2007-4089 | Vikingboard 0.1.2 allows remote attackers to obtain sensitive information via the debug parameter to (1) forum.php, (2) cp.php, and possibly other unspecified components. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 2.40% | 30 July 2007 |
| CVE-2007-4088 | Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) id, (2) f, (3) quote, and (4) act parameters to cp.php; the (5) u parameter to user.php; the (6) f… | EXPLOIT ×4 ✓MEDIUM 4.3EPSS 4.38% | 30 July 2007 |
| CVE-2007-4085 | Multiple SQL injection vulnerabilities in AlstraSoft AskMe Pro allow remote attackers to execute arbitrary SQL commands via the (1) que_id parameter to forum_answer.php or (2) the cat_id parameter to search.php. | EXPLOIT ✓MEDIUM 6.8EPSS 0.93% | 30 July 2007 |
| CVE-2007-4084 | Multiple SQL injection vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to execute arbitrary SQL commands via (1) the pgmid parameter in an uploadProducts action to merchants/index.php and possibly (2) the rowid parameter to… | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 30 July 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.