SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,612 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026

25,049 results · page 329 of 501

CVESummaryPriorityPublished
CVE-2007-4081Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to inject arbitrary web script or HTML via vectors in (a) merchants/index.php, including the (1) id or (2) msg parameter in a programedit…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 3.21%30 July 2007
CVE-2007-4079Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft SMS Text Messaging Enterprise allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) q parameter to (a) admin/membersearch.php, or (3) the userid…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 3.24%30 July 2007
CVE-2007-4076Multiple SQL injection vulnerabilities in index.asp in Alisveris Sitesi Scripti allow remote attackers to execute arbitrary SQL commands via the (1) product_id or (2) cat_id parameter in a product mod action.EXPLOIT ✓HIGH 7.5EPSS 0.93%30 July 2007
CVE-2007-4075Cross-site scripting (XSS) vulnerability in index.asp in Alisveris Sitesi Scripti allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search mod action.EXPLOIT ✓MEDIUM 4.3EPSS 1.22%30 July 2007
CVE-2007-4069SQL injection vulnerability in show_cat.php in IndexScript 2.8 and earlier allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.41%30 July 2007
CVE-2007-4068Multiple SQL injection vulnerabilities in Webyapar 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the kat_id parameter to the default URI in a download action or (2) the id parameter to the default URI in a duyurular_detay action.EXPLOIT ✓MEDIUM 5.8EPSS 1.99%30 July 2007
CVE-2007-4067Absolute path traversal vulnerability in the clInetSuiteX6.clWebDav ActiveX control in CLINETSUITEX6.OCX in Clever Internet ActiveX Suite 6.2 allows remote attackers to create or overwrite arbitrary files via a full pathname in the second argument to…EXPLOIT ✓HIGH 9.3EPSS 6.97%30 July 2007
CVE-2007-4062The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via unspecified vectors involving the deleteNessusRC method, probably a directory traversal vulnerability.EXPLOIT ✓HIGH 7.8EPSS 2.11%30 July 2007
CVE-2007-4061Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to create or overwrite arbitrary files via a ..EXPLOIT ✓HIGH 9.3EPSS 11.2%30 July 2007
CVE-2007-4060Multiple buffer overflows in the HttpSprockMake function in http.c in Frank Yaul corehttp 0.5.3alpha allow remote attackers to execute arbitrary code via a long string in the (1) method name or (2) URI in an HTTP request.EXPLOIT ✓HIGH 9.0EPSS 5.38%30 July 2007
CVE-2007-4059Absolute path traversal vulnerability in a certain ActiveX control in IntraProcessLogging.dll 5.5.3.42958 in EMC VMware allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SetLogFileName method.EXPLOIT ✓MEDIUM 5.8EPSS 7.25%30 July 2007
CVE-2007-4058Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll 2.2.5.42958 in EMC VMware 6.0.0 allows remote attackers to execute arbitrary local programs via a full pathname in the first argument to the StartProcess method.EXPLOIT ✓MEDIUM 4.3EPSS 22.4%30 July 2007
CVE-2007-4057Unrestricted file upload vulnerability in pfs.php in Neocrome Seditio 121 and earlier allows remote authenticated users to upload arbitrary PHP code via a filename ending with (1) .php.gif, (2) .php.jpg, or (3) .php.png.EXPLOIT ✓MEDIUM 6.5EPSS 2.07%30 July 2007
CVE-2007-4056SQL injection vulnerability in directory.php in Prozilla Adult Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.EXPLOIT ✓HIGH 7.5EPSS 1.04%30 July 2007
CVE-2007-4055SQL injection vulnerability in comments_get.asp in SimpleBlog 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.06%30 July 2007
CVE-2007-4054SQL injection vulnerability in category.php in PHP123 Top Sites allows remote attackers to execute arbitrary SQL commands via the cat parameter.EXPLOIT ✓HIGH 7.5EPSS 1.06%30 July 2007
CVE-2007-4053SQL injection vulnerability in include/img_view.class.php in LinPHA 1.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the order parameter to new_images.php.EXPLOIT ✓HIGH 7.5EPSS 2.51%30 July 2007
CVE-2007-4052Cross-site scripting (XSS) vulnerability in utilities/login.asp in nukedit 4.9.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the email parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.48%30 July 2007
CVE-2007-4047geoBlog (aka BitDamaged) 1 does not require authentication for (1) deletecomment.php, (2) deleteblog.php, and (3) listcomment.php in admin/, which allows remote attackers to delete arbitrary comments, delete arbitrary blogs, and have other unspecified…EXPLOIT ×2 ✓MEDIUM 6.4EPSS 3.28%27 July 2007
CVE-2007-4046SQL injection vulnerability in index.php in the Pony Gallery (com_ponygallery) 1.5 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.EXPLOIT ✓HIGH 7.5EPSS 2.17%27 July 2007
CVE-2007-4034Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo!EXPLOIT ✓HIGH 9.3EPSS 13.0%27 July 2007
CVE-2007-4033Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 18.7%27 July 2007
CVE-2007-4032Buffer overflow in CrystalPlayer Pro 1.98 allows user-assisted remote attackers to execute arbitrary code via a long string in a .mls Playlist file.EXPLOIT ✓MEDIUM 6.8EPSS 3.82%27 July 2007
CVE-2007-4031Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via a ..EXPLOIT ×2 ✓HIGH 7.8EPSS 5.71%27 July 2007
CVE-2007-4004Buffer overflow in the ftp client in IBM AIX 5.3 SP6 and 5.2.0 allows local users to execute arbitrary code via unspecified vectors that trigger the overflow in a gets function call.EXPLOIT ✓MEDIUM 6.9EPSS 0.85%26 July 2007
CVE-2007-4003pioout in IBM AIX 5.3 SP6 allows local users to execute arbitrary code by specifying a malicious library with the -R (ParseRoutine) command line argument.EXPLOIT ✓MEDIUM 6.9EPSS 1.75%26 July 2007
CVE-2007-3333Stack-based buffer overflow in capture in IBM AIX 5.3 SP6 and 5.2.0 allows remote attackers to execute arbitrary code via a large number of terminal control sequences.EXPLOIT ×2 ✓MEDIUM 6.9EPSS 3.50%26 July 2007
CVE-2007-4024Cross-site scripting (XSS) vulnerability in W1L3D4_aramasonuc.asp in W1L3D4 Philboard 0.3 allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.49%26 July 2007
CVE-2007-4022Cross-site scripting (XSS) vulnerability in frontend/x/htaccess/changepro.html in cPanel 10.9.1 allows remote attackers to inject arbitrary web script or HTML via the resname parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.76%26 July 2007
CVE-2007-3566Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 before SP2 allows remote attackers to execute arbitrary code via a long size value in a create request to port 3050/tcp.EXPLOIT ✓HIGH 7.5EPSS 66.1%26 July 2007
CVE-2007-4010The win32std extension in PHP 5.2.3 does not follow safe_mode and disable_functions restrictions, which allows remote attackers to execute arbitrary commands via the win_shell_execute function.EXPLOIT ✓MEDIUM 6.8EPSS 5.53%26 July 2007
CVE-2007-4009PHP remote file inclusion vulnerability in admin/business_inc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the thisdir parameter.EXPLOIT ✓HIGH 9.3EPSS 4.32%26 July 2007
CVE-2007-4008Directory traversal vulnerability in custom.php in Entertainment Media Sharing CMS allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.90%26 July 2007
CVE-2007-4007PHP remote file inclusion vulnerability in index.php in Article Directory (Article Site Directory) allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.EXPLOIT ✓HIGH 9.3EPSS 3.49%26 July 2007
CVE-2007-4006Buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 has unknown impact and remote attack vectors, aka ZD-00000034.EXPLOIT ×2 ✓MEDIUM 6.8EPSS 34.5%26 July 2007
CVE-2007-4005Stack-based buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 allows remote attackers to execute arbitrary code via a long string to the shell port (514/tcp).EXPLOIT ✓MEDIUM 5.0EPSS 11.2%26 July 2007
CVE-2007-3991Multiple cross-site scripting (XSS) vulnerabilities in cv.asp in Asp cvmatik 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Adiniz (Ady), (2) Soyadiniz (Soyady), (3) Ehliyet, (4) Askerlik, and (5) GSM…EXPLOIT ✓MEDIUM 4.3EPSS 1.53%25 July 2007
CVE-2007-3989Multiple cross-site scripting (XSS) vulnerabilities in default.asp in Dora Emlak 1.0, when the goster parameter is set to iletisim, allow remote attackers to inject arbitrary web script or HTML via the (1) Adiniz and (2) Soyadiniz parameters; and…EXPLOIT ✓MEDIUM 4.3EPSS 1.49%25 July 2007
CVE-2007-3987SQL injection vulnerability in SearchResults.asp in ImageRacer 1.0, when WordSearchCrit is enabled, allows remote attackers to execute arbitrary SQL commands via the SearchWord parameter.EXPLOIT ✓HIGH 7.5EPSS 1.21%25 July 2007
CVE-2007-3984Buffer overflow in a certain ActiveX control in the NixonMyPrograms class in sasatl.dll 1.5.0.531 in Zenturi ProgramChecker allows remote attackers to execute arbitrary code via a long argument to the Scan method.EXPLOIT ✓HIGH 7.5EPSS 4.40%25 July 2007
CVE-2007-3983Absolute path traversal vulnerability in the Data Dynamics DDActiveReports2.ActiveReport.2 (ActiveReports) ActiveX control in arpro2.dll in ActiveReports 2.0 Professional Edition 2.5.0.1308 (SP5 RC) allows remote attackers to create or overwrite…EXPLOIT ✓MEDIUM 5.0EPSS 1.63%25 July 2007
CVE-2007-3982Absolute path traversal vulnerability in the Data Dynamics ActiveReport (ActiveReports) ActiveX control in actrpt2.dll 2.5 and earlier allows remote attackers to create or overwrite arbitrary files via a full pathname in the first argument to the…EXPLOIT ✓MEDIUM 5.0EPSS 2.49%25 July 2007
CVE-2007-3981SQL injection vulnerability in index.php in WSN Links Basic Edition allows remote attackers to execute arbitrary SQL commands via the catid parameter in a displaycat action.EXPLOIT ✓HIGH 7.5EPSS 1.20%25 July 2007
CVE-2007-3980PHP remote file inclusion vulnerability in page.php in RCMS Pro RGameScript Pro allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.EXPLOIT ✓HIGH 10.0EPSS 4.21%25 July 2007
CVE-2007-3979SQL injection vulnerability in index.php in BlogSite Professional (aka Blog System) 1.x allows remote attackers to execute arbitrary SQL commands via the news_id parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.14%25 July 2007
CVE-2007-3978Session fixation vulnerability in bwired allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.EXPLOIT ✓MEDIUM 4.3EPSS 2.02%25 July 2007
CVE-2007-3977Cross-site scripting (XSS) vulnerability in bwired allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.EXPLOIT ✓MEDIUM 4.3EPSS 1.27%25 July 2007
CVE-2007-3976SQL injection vulnerability in index.php in bwired allows remote attackers to execute arbitrary SQL commands via the newsID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.03%25 July 2007
CVE-2007-3974admin/ajoutaut.php in JBlog 1.0 does not require authentication, which allows remote attackers to create arbitrary accounts via modified mot and droit parameters.EXPLOIT ×2 ✓HIGH 7.5EPSS 3.67%25 July 2007
CVE-2007-3973Multiple cross-site scripting (XSS) vulnerabilities in JBlog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) index.php, or the (2) search parameter or (3) theme cookie to (b) recherche.php.EXPLOIT ×2 ✓MEDIUM 6.8EPSS 2.77%25 July 2007

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.