Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,612 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 331 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-3103 | The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file. | EXPLOIT ✓MEDIUM 6.2EPSS 0.90% | 15 July 2007 |
| CVE-2007-3673 | Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and… | EXPLOIT ✓MEDIUM 6.9EPSS 1.06% | 15 July 2007 |
| CVE-2007-2394 | Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via crafted (1) title and (2) author fields in an SMIL file, related to improper calculations for memory… | EXPLOIT ×2 ✓HIGH 9.3EPSS 12.1% | 15 July 2007 |
| CVE-2007-3725 | The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) before 0.91 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive, resulting in a NULL pointer dereference. | EXPLOIT ✓MEDIUM 4.3EPSS 7.69% | 12 July 2007 |
| CVE-2007-3714 | Directory traversal vulnerability in Ada Image Server (ImgSvr) 0.6.5 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.70% | 11 July 2007 |
| CVE-2007-3703 | Stack-based buffer overflow in a certain ActiveX control in sasatl.dll 1.5.0.531 in Zenturi Program Checker (ProgramChecker) Pro allows remote attackers to execute arbitrary code via a long argument to the Fill method. | EXPLOIT ✓MEDIUM 6.8EPSS 4.05% | 11 July 2007 |
| CVE-2007-3702 | Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 7.51% | 11 July 2007 |
| CVE-2007-3701 | TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which might allow remote attackers to send certain network traffic and avoid detection, as demonstrated by a cmd.exe attack. | EXPLOIT ✓HIGH 7.5EPSS 8.48% | 11 July 2007 |
| CVE-2007-3693 | Cross-site scripting (XSS) vulnerability in Gobi as of 20070711, built on Helma, allows remote attackers to inject arbitrary web script or HTML via the q parameter to the search function. | EXPLOIT ✓MEDIUM 4.3EPSS 1.22% | 11 July 2007 |
| CVE-2007-3697 | PHP remote file inclusion vulnerability in phpbb/sendmsg.php in FlashBB 1.1.8 and earlier allows remote attackers to execute arbitrary code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 12.8% | 11 July 2007 |
| CVE-2007-3687 | SQL injection vulnerability in inferno.php in the Inferno Technologies RPG Inferno 2.4 and earlier, a vBulletin module, allows remote authenticated attackers to execute arbitrary SQL commands via the id parameter in a ScanMember do action. | EXPLOIT ✓MEDIUM 6.5EPSS 1.03% | 11 July 2007 |
| CVE-2007-3683 | SQL injection vulnerability in pagetopic.php in Aigaion 1.3.3 and earlier allows remote attackers to execute arbitrary SQL commands via the topic_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 11 July 2007 |
| CVE-2007-3682 | SQL injection vulnerability in index.php in OpenLD 1.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.25% | 11 July 2007 |
| CVE-2007-3681 | The IOCTL 9031 (BIOCGSTATS) handler in the NPF.SYS device driver in WinPcap before 4.0.1 allows local users to overwrite memory and execute arbitrary code via malformed Interrupt Request Packet (Irp) parameters. | EXPLOIT ✓MEDIUM 6.6EPSS 2.38% | 11 July 2007 |
| CVE-2007-3456 | Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an "input… | EXPLOIT ✓HIGH 9.3EPSS 56.3% | 11 July 2007 |
| CVE-2007-0042 | Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms… | EXPLOIT ✓HIGH 7.8EPSS 76.2% | 10 July 2007 |
| CVE-2007-3670 | Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell… | EXPLOIT ✓MEDIUM 4.3EPSS 29.4% | 10 July 2007 |
| CVE-2007-3655 | Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and earlier, allows remote attackers to execute arbitrary code via a long codebase attribute in a JNLP file. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 12.3% | 10 July 2007 |
| CVE-2007-3649 | Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Digital Imaging allows remote attackers to create or overwrite arbitrary files via the second argument to the SaveToFile method. | EXPLOIT ✓MEDIUM 6.8EPSS 4.56% | 10 July 2007 |
| CVE-2007-3646 | SQL injection vulnerability in index.php in FlashGameScript 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a member action. | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 10 July 2007 |
| CVE-2007-3638 | Buffer overflow in Yahoo! | EXPLOIT ✓MEDIUM 6.0EPSS 2.44% | 10 July 2007 |
| CVE-2007-3636 | Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 3.08% | 10 July 2007 |
| CVE-2007-3633 | Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveLastError method and… | EXPLOIT ✓MEDIUM 6.4EPSS 2.88% | 10 July 2007 |
| CVE-2007-3632 | Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a URL in the homedir parameter to (1) OLE/PPS/File.php, (2) OLE/PPS/Root.php, (3)… | EXPLOIT ✓MEDIUM 6.8EPSS 61.5% | 10 July 2007 |
| CVE-2007-3631 | SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 10 July 2007 |
| CVE-2007-3630 | changePW.php in AV Tutorial Script (avtutorial) 1.0 does not require authentication or knowledge of an old password for password changes, which allows remote attackers to change passwords for arbitrary users via a modified password parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 2.33% | 10 July 2007 |
| CVE-2007-3629 | SQL injection vulnerability in oku.asp in Levent Veysi Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 10.0EPSS 1.47% | 9 July 2007 |
| CVE-2007-3627 | Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) login.php, (2) auth.php, and (3) subscribe.php. | EXPLOIT ×3 ✓HIGH 7.5EPSS 0.93% | 9 July 2007 |
| CVE-2007-3624 | Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long string in the group parameter to /msgserver/html/group. | EXPLOIT ✓HIGH 10.0EPSS 36.8% | 9 July 2007 |
| CVE-2007-3621 | Multiple CRLF injection vulnerabilities in callboth.php in AsteriDex 3.0 and earlier allow remote attackers to inject arbitrary shell commands via the (1) IN and (2) OUT parameters. | EXPLOIT ✓HIGH 7.5EPSS 8.16% | 9 July 2007 |
| CVE-2007-3619 | Directory traversal vulnerability in login.php in Maia Mailguard 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 8.86% | 9 July 2007 |
| CVE-2007-3614 | Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to… | EXPLOIT ×3 ✓HIGH 7.5EPSS 70.0% | 6 July 2007 |
| CVE-2007-3613 | Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attackers to inject arbitrary web script or HTML via the PARAMS parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.39% | 6 July 2007 |
| CVE-2007-3612 | Stack-based buffer overflow in Visual IRC (ViRC) 2.0 allows remote IRC servers to execute arbitrary code via a long response to a JOIN command. | EXPLOIT ✓HIGH 7.5EPSS 4.92% | 6 July 2007 |
| CVE-2007-3611 | admin.php in VRNews 1.1.1, and possibly other 1.x versions, does not require authentication, which allows remote attackers to perform certain administrative actions via a direct request with a (1) edit, (2) add, (3) config, or (4) del value in the act… | EXPLOIT ✓HIGH 9.3EPSS 3.27% | 6 July 2007 |
| CVE-2007-3610 | SQL injection vulnerability in categories_type.php in phpVID 0.9.9 allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 6 July 2007 |
| CVE-2007-3609 | Multiple SQL injection vulnerabilities in eMeeting Online Dating Software 5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) b.php and (2) account/gallery.php, and other unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 1.78% | 6 July 2007 |
| CVE-2007-3608 | Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certain files via unspecified vectors. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 2.83% | 6 July 2007 |
| CVE-2007-3607 | Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) via unspecified vectors. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 3.75% | 6 July 2007 |
| CVE-2007-3606 | Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCII versions, allows remote attackers to execute arbitrary code via a long first argument to the LaunchGui function. | EXPLOIT ✓HIGH 7.6EPSS 7.65% | 6 July 2007 |
| CVE-2007-3605 | Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP SAP GUI allows remote attackers to execute arbitrary code via a long argument to the PrepareToPostHTML function. | EXPLOIT ×2 ✓HIGH 7.6EPSS 69.9% | 6 July 2007 |
| CVE-2007-3594 | Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter in (a) ping.do and (b) traceRoute.do in map/; the (2) reportName,… | EXPLOIT ×5 ✓LOW 2.6EPSS 5.77% | 6 July 2007 |
| CVE-2007-3593 | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject arbitrary web script or HTML via the (1) alpha parameter in (a) netflow/jspui/applicationList.jsp, the (2) task parameter in (b)… | EXPLOIT ×5 ✓MEDIUM 4.3EPSS 4.10% | 6 July 2007 |
| CVE-2007-3590 | Cross-site scripting (XSS) vulnerability in visitenkarte.php in b1gBB 2.24.0 allows remote attackers to inject arbitrary web script or HTML via the user parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.20% | 5 July 2007 |
| CVE-2007-3589 | Multiple SQL injection vulnerabilities in b1gbb 2.24.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) showthread.php or (2) showboard.php. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 5 July 2007 |
| CVE-2007-2839 | gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary commands via unknown vectors. | EXPLOIT ✓HIGH 7.2EPSS 0.77% | 5 July 2007 |
| CVE-2007-3587 | MyCMS 0.9.8 and earlier allows remote attackers to gain privileges via the admin cookie parameter, as demonstrated by a post to admin/settings.php that injects PHP code into settings.inc, which can then be executed via a direct request to index.php. | EXPLOIT ✓HIGH 7.5EPSS 2.89% | 5 July 2007 |
| CVE-2007-3586 | Multiple direct static code injection vulnerabilities in MyCMS 0.9.8 and earlier allow remote attackers to inject arbitrary PHP code into (1) a _score.txt file via the score parameter, or (2) a _setby.txt file via a login cookie, which is then included… | EXPLOIT ✓HIGH 7.5EPSS 2.31% | 5 July 2007 |
| CVE-2007-3585 | PHP remote file inclusion vulnerability in games.php in MyCMS 0.9.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.34% | 5 July 2007 |
| CVE-2007-3584 | SQL injection vulnerability in viewforum.php in PNphpBB2 1.2i and earlier for Postnuke allows remote attackers to execute arbitrary SQL commands via the order parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.03% | 5 July 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.