Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,612 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 330 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-3963 | Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, or (3)… | EXPLOIT ×2 ✓HIGH 9.3EPSS 2.42% | 25 July 2007 |
| CVE-2007-3958 | Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certain GIF file, as demonstrated by Art.gif. | EXPLOIT ✓HIGH 7.1EPSS 22.8% | 24 July 2007 |
| CVE-2007-3957 | Buffer overflow in Nipun Jain xserver 0.1 alpha allows remote attackers to cause a denial of service via a POST request with a long URI. | EXPLOIT ✓MEDIUM 5.0EPSS 6.81% | 24 July 2007 |
| CVE-2007-3956 | TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which allows remote attackers to cause a denial of service (CPU and memory consumption) via long username and password parameters in a… | EXPLOIT ✓HIGH 7.8EPSS 8.14% | 24 July 2007 |
| CVE-2007-3955 | Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote attackers to execute arbitrary code via a long second argument (varBrowser argument) to the search method. | EXPLOIT ✓MEDIUM 6.8EPSS 8.24% | 24 July 2007 |
| CVE-2007-2926 | ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id… | EXPLOIT ✓MEDIUM 4.3EPSS 13.1% | 24 July 2007 |
| CVE-2007-3947 | request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as demonstrated by a request containing two Location header lines, which results in a segmentation fault. | EXPLOIT ✓MEDIUM 5.8EPSS 8.07% | 24 July 2007 |
| CVE-2007-3939 | SQL injection vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) CMS 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 2.07% | 21 July 2007 |
| CVE-2007-3938 | SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.8x and earlier before 20070720 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a view action in the Topics module, a different vulnerability… | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 21 July 2007 |
| CVE-2007-3937 | Multiple SQL injection vulnerabilities in A-shop 0.70 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 0.95% | 21 July 2007 |
| CVE-2007-3936 | Directory traversal vulnerability in admin/filebrowser.asp in A-shop 0.70 and earlier, and possibly 0.71, allows remote attackers to delete arbitrary files via unspecified filename references in the delfiles parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 2.32% | 21 July 2007 |
| CVE-2007-3935 | PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 9.3EPSS 3.98% | 21 July 2007 |
| CVE-2007-3934 | PHP remote file inclusion vulnerability in postscript/postscript.php in BBS E-Market allows remote attackers to execute arbitrary PHP code via a URL in the p_mode parameter. | EXPLOIT ✓HIGH 7.5EPSS 8.42% | 21 July 2007 |
| CVE-2007-3933 | SQL injection vulnerability in insertorder.cfm in QuickEStore 8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the CFTOKEN parameter, a different vector than CVE-2006-2053. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 21 July 2007 |
| CVE-2007-3932 | uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to upload a non-JPEG file, which allows remote attackers to upload and execute arbitrary PHP code in the… | EXPLOIT ✓HIGH 7.5EPSS 6.33% | 21 July 2007 |
| CVE-2007-3927 | Multiple buffer overflows in Ipswitch IMail Server 2006 before 2006.21 (1) allow remote attackers to execute arbitrary code via unspecified vectors in Imailsec and (2) allow attackers to have an unknown impact via an unspecified vector related to… | EXPLOIT ✓HIGH 10.0EPSS 21.9% | 21 July 2007 |
| CVE-2007-3925 | Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Search or (2) Search Charset command. | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 84.7% | 21 July 2007 |
| CVE-2007-3909 | Multiple SQL injection vulnerabilities in Bandersnatch 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) date and (2) limit parameters to index.php, and other unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 1.35% | 19 July 2007 |
| CVE-2007-3889 | Multiple SQL injection vulnerabilities in Insanely Simple Blog 0.5 and earlier allow remote attackers to execute arbitrary SQL commands via the current_subsection parameter to index.php and other unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 1.75% | 18 July 2007 |
| CVE-2007-3888 | Multiple cross-site scripting (XSS) vulnerabilities in Insanely Simple Blog 0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the search action, possibly related to the term parameter to index.php; or (2) an anonymous… | EXPLOIT ✓MEDIUM 4.3EPSS 1.54% | 18 July 2007 |
| CVE-2007-3884 | SQL injection vulnerability in philboard_forum.asp in husrevforum 1.0.1 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.87% | 18 July 2007 |
| CVE-2007-3883 | The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite files via a full pathname in (1) the second argument to the Save method, or the first argument to the (2) SaveLayoutChanges or (3)… | EXPLOIT ×2 ✓MEDIUM 5.1EPSS 8.20% | 18 July 2007 |
| CVE-2007-3882 | SQL injection vulnerability in index.php in Expert Advisor allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 18 July 2007 |
| CVE-2007-3881 | SQL injection vulnerability in index.php in Pictures Rating (Picture Rating) allows remote attackers to execute arbitrary SQL commands via the msgid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 18 July 2007 |
| CVE-2007-3855 | Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to have an unknown impact via (1) SYS.DBMS_DRS in the DataGuard component (DB03), (2) SYS.DBMS_STANDARD in the… | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 15.8% | 18 July 2007 |
| CVE-2007-3764 | The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial… | EXPLOIT ✓MEDIUM 5.0EPSS 31.5% | 18 July 2007 |
| CVE-2007-3763 | The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of… | EXPLOIT ✓MEDIUM 5.0EPSS 26.6% | 18 July 2007 |
| CVE-2007-3840 | SQL injection vulnerability in referralUrl.php in Traffic Stats allows remote attackers to execute arbitrary SQL commands via the offset parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 17 July 2007 |
| CVE-2007-3838 | Cross-site scripting (XSS) vulnerability in takeprofedit.php in TBDev.NET DR 11-10-05-BETA-SF1:111005 and earlier allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of a SCRIPT element in the avatar parameter. | EXPLOIT ✓LOW 2.6EPSS 1.52% | 17 July 2007 |
| CVE-2007-3832 | Buffer overflow in the AOL Instant Messenger (AIM) protocol handler in AIM.DLL in Cerulean Studios Trillian allows remote attackers to execute arbitrary code via a malformed aim: URI, as demonstrated by a long URI beginning with the aim:///#1111111/… | EXPLOIT ✓HIGH 9.3EPSS 11.8% | 17 July 2007 |
| CVE-2007-3824 | SQL injection vulnerability in katgoster.asp in MzK Blog (tr) allows remote attackers to execute arbitrary SQL commands via the katID parameter. | EXPLOIT ✓HIGH 10.0EPSS 1.82% | 17 July 2007 |
| CVE-2007-3822 | Multiple cross-site scripting (XSS) vulnerabilities in Webcit before 7.11 allow remote attackers to inject arbitrary web script or HTML via (1) the who parameter to showuser; and other vectors involving (2) calendar mode, (3) bulletin board mode, (4)… | EXPLOIT ✓LOW 2.6EPSS 2.48% | 17 July 2007 |
| CVE-2007-3814 | Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the idurlo field in the delete_urlo function in (a) index.php in the urlobox module; the iden field in the (2) update_file and (3)… | EXPLOIT ✓HIGH 7.5EPSS 2.13% | 17 July 2007 |
| CVE-2007-3813 | PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitrary PHP code via a URL in the MK_PATH parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 59.4% | 17 July 2007 |
| CVE-2007-3812 | SQL injection vulnerability in forums.php in CMScout 1.23 and earlier allows remote attackers to execute arbitrary SQL commands via the f parameter in a forums action to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.18% | 17 July 2007 |
| CVE-2007-3811 | Multiple SQL injection vulnerabilities in eSyndiCat allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php or (2) the name parameter to page.php. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 17 July 2007 |
| CVE-2007-3810 | SQL injection vulnerability in index.php in Realtor 747 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 17 July 2007 |
| CVE-2007-3809 | Multiple SQL injection vulnerabilities in Prozilla Directory Script allow remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action to directory.php, and other unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 1.03% | 17 July 2007 |
| CVE-2007-3808 | SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL commands via the categories[] parameter in a search action to index.php, a different vector than CVE-2005-2000. | EXPLOIT ✓HIGH 7.5EPSS 2.49% | 17 July 2007 |
| CVE-2007-3806 | The glob function in PHP 5.2.3 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an invalid value of the flags parameter, probably related to memory corruption or an invalid read on win32 platforms,… | EXPLOIT ✓MEDIUM 6.8EPSS 10.7% | 17 July 2007 |
| CVE-2007-3017 | The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/applets/wysiwyg/rendereditor.asp, which allows remote authenticated users to inject arbitrary JavaScript via a request to… | EXPLOIT ✓MEDIUM 4.0EPSS 5.14% | 17 July 2007 |
| CVE-2007-3799 | The session_start function in ext/session in PHP 4.x up to 4.4.7 and 5.x up to 5.2.3 allows remote attackers to insert arbitrary attributes into the session cookie via special characters in a cookie that is obtained from (1) PATH_INFO, (2) the… | EXPLOIT ✓MEDIUM 4.3EPSS 7.92% | 16 July 2007 |
| CVE-2007-3798 | Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value. | EXPLOIT ✓CRITICAL 9.8EPSS 70.4% | 16 July 2007 |
| CVE-2007-3792 | Multiple PHP remote file inclusion vulnerabilities in AzDG Dating Gold 3.0.5 allow remote attackers to execute arbitrary PHP code via a URL in the int_path parameter to (1) header.php, (2) footer.php, or (3) secure.admin.php in templates/. | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 5.27% | 15 July 2007 |
| CVE-2007-3790 | The com_print_typeinfo function in the bz2 extension in PHP 5.2.3 allows context-dependent attackers to cause a denial of service via a long argument. | EXPLOIT ✓MEDIUM 5.8EPSS 3.02% | 15 July 2007 |
| CVE-2007-3789 | SQL injection vulnerability in admin/index.php in Inmostore 4.0 allows remote attackers to execute arbitrary SQL commands via the Password field. | EXPLOIT ✓HIGH 7.5EPSS 1.87% | 15 July 2007 |
| CVE-2007-3785 | Absolute path traversal vulnerability in a certain ActiveX control in PGPBBox.dll in EldoS SecureBlackbox (sbb) 5.1.0.112 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveToFile method. | EXPLOIT ✓MEDIUM 4.0EPSS 1.90% | 15 July 2007 |
| CVE-2007-3014 | Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) errors/rights.asp or (2) errors/transaction.asp, or (3) the name of… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 4.48% | 15 July 2007 |
| CVE-2007-3013 | SQL injection vulnerability in activeWeb contentserver before 5.6.2964 allows remote authenticated users with edit permission to execute arbitrary SQL commands via the id parameter to admin/picture/picture_real_edit.asp, and probably other unspecified… | EXPLOIT ✓MEDIUM 6.5EPSS 2.90% | 15 July 2007 |
| CVE-2007-3772 | Directory traversal vulnerability in news/show.php in PsNews 1.1 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.4EPSS 2.39% | 15 July 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.