SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,612 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026

25,049 results · page 331 of 501

CVESummaryPriorityPublished
CVE-2007-3103The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file.EXPLOIT ✓MEDIUM 6.2EPSS 0.90%15 July 2007
CVE-2007-3673Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and…EXPLOIT ✓MEDIUM 6.9EPSS 1.06%15 July 2007
CVE-2007-2394Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via crafted (1) title and (2) author fields in an SMIL file, related to improper calculations for memory…EXPLOIT ×2 ✓HIGH 9.3EPSS 12.1%15 July 2007
CVE-2007-3725The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) before 0.91 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive, resulting in a NULL pointer dereference.EXPLOIT ✓MEDIUM 4.3EPSS 7.69%12 July 2007
CVE-2007-3714Directory traversal vulnerability in Ada Image Server (ImgSvr) 0.6.5 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.70%11 July 2007
CVE-2007-3703Stack-based buffer overflow in a certain ActiveX control in sasatl.dll 1.5.0.531 in Zenturi Program Checker (ProgramChecker) Pro allows remote attackers to execute arbitrary code via a long argument to the Fill method.EXPLOIT ✓MEDIUM 6.8EPSS 4.05%11 July 2007
CVE-2007-3702Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 7.51%11 July 2007
CVE-2007-3701TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which might allow remote attackers to send certain network traffic and avoid detection, as demonstrated by a cmd.exe attack.EXPLOIT ✓HIGH 7.5EPSS 8.48%11 July 2007
CVE-2007-3693Cross-site scripting (XSS) vulnerability in Gobi as of 20070711, built on Helma, allows remote attackers to inject arbitrary web script or HTML via the q parameter to the search function.EXPLOIT ✓MEDIUM 4.3EPSS 1.22%11 July 2007
CVE-2007-3697PHP remote file inclusion vulnerability in phpbb/sendmsg.php in FlashBB 1.1.8 and earlier allows remote attackers to execute arbitrary code via a URL in the phpbb_root_path parameter.EXPLOIT ✓HIGH 7.5EPSS 12.8%11 July 2007
CVE-2007-3687SQL injection vulnerability in inferno.php in the Inferno Technologies RPG Inferno 2.4 and earlier, a vBulletin module, allows remote authenticated attackers to execute arbitrary SQL commands via the id parameter in a ScanMember do action.EXPLOIT ✓MEDIUM 6.5EPSS 1.03%11 July 2007
CVE-2007-3683SQL injection vulnerability in pagetopic.php in Aigaion 1.3.3 and earlier allows remote attackers to execute arbitrary SQL commands via the topic_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.20%11 July 2007
CVE-2007-3682SQL injection vulnerability in index.php in OpenLD 1.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.25%11 July 2007
CVE-2007-3681The IOCTL 9031 (BIOCGSTATS) handler in the NPF.SYS device driver in WinPcap before 4.0.1 allows local users to overwrite memory and execute arbitrary code via malformed Interrupt Request Packet (Irp) parameters.EXPLOIT ✓MEDIUM 6.6EPSS 2.38%11 July 2007
CVE-2007-3456Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an "input…EXPLOIT ✓HIGH 9.3EPSS 56.3%11 July 2007
CVE-2007-0042Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms…EXPLOIT ✓HIGH 7.8EPSS 76.2%10 July 2007
CVE-2007-3670Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell…EXPLOIT ✓MEDIUM 4.3EPSS 29.4%10 July 2007
CVE-2007-3655Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and earlier, allows remote attackers to execute arbitrary code via a long codebase attribute in a JNLP file.EXPLOIT ×2 ✓MEDIUM 6.8EPSS 12.3%10 July 2007
CVE-2007-3649Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Digital Imaging allows remote attackers to create or overwrite arbitrary files via the second argument to the SaveToFile method.EXPLOIT ✓MEDIUM 6.8EPSS 4.56%10 July 2007
CVE-2007-3646SQL injection vulnerability in index.php in FlashGameScript 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a member action.EXPLOIT ✓HIGH 7.5EPSS 1.24%10 July 2007
CVE-2007-3638Buffer overflow in Yahoo!EXPLOIT ✓MEDIUM 6.0EPSS 2.44%10 July 2007
CVE-2007-3636Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via unspecified vectors.EXPLOIT ✓HIGH 7.5EPSS 3.08%10 July 2007
CVE-2007-3633Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveLastError method and…EXPLOIT ✓MEDIUM 6.4EPSS 2.88%10 July 2007
CVE-2007-3632Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a URL in the homedir parameter to (1) OLE/PPS/File.php, (2) OLE/PPS/Root.php, (3)…EXPLOIT ✓MEDIUM 6.8EPSS 61.5%10 July 2007
CVE-2007-3631SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field.EXPLOIT ✓HIGH 7.5EPSS 1.22%10 July 2007
CVE-2007-3630changePW.php in AV Tutorial Script (avtutorial) 1.0 does not require authentication or knowledge of an old password for password changes, which allows remote attackers to change passwords for arbitrary users via a modified password parameter.EXPLOIT ✓MEDIUM 6.4EPSS 2.33%10 July 2007
CVE-2007-3629SQL injection vulnerability in oku.asp in Levent Veysi Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 10.0EPSS 1.47%9 July 2007
CVE-2007-3627Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) login.php, (2) auth.php, and (3) subscribe.php.EXPLOIT ×3 ✓HIGH 7.5EPSS 0.93%9 July 2007
CVE-2007-3624Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long string in the group parameter to /msgserver/html/group.EXPLOIT ✓HIGH 10.0EPSS 36.8%9 July 2007
CVE-2007-3621Multiple CRLF injection vulnerabilities in callboth.php in AsteriDex 3.0 and earlier allow remote attackers to inject arbitrary shell commands via the (1) IN and (2) OUT parameters.EXPLOIT ✓HIGH 7.5EPSS 8.16%9 July 2007
CVE-2007-3619Directory traversal vulnerability in login.php in Maia Mailguard 1.0.2 and earlier allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 8.86%9 July 2007
CVE-2007-3614Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to…EXPLOIT ×3 ✓HIGH 7.5EPSS 70.0%6 July 2007
CVE-2007-3613Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attackers to inject arbitrary web script or HTML via the PARAMS parameter.EXPLOIT ✓MEDIUM 4.3EPSS 2.39%6 July 2007
CVE-2007-3612Stack-based buffer overflow in Visual IRC (ViRC) 2.0 allows remote IRC servers to execute arbitrary code via a long response to a JOIN command.EXPLOIT ✓HIGH 7.5EPSS 4.92%6 July 2007
CVE-2007-3611admin.php in VRNews 1.1.1, and possibly other 1.x versions, does not require authentication, which allows remote attackers to perform certain administrative actions via a direct request with a (1) edit, (2) add, (3) config, or (4) del value in the act…EXPLOIT ✓HIGH 9.3EPSS 3.27%6 July 2007
CVE-2007-3610SQL injection vulnerability in categories_type.php in phpVID 0.9.9 allows remote attackers to execute arbitrary SQL commands via the cat parameter.EXPLOIT ✓HIGH 7.5EPSS 1.22%6 July 2007
CVE-2007-3609Multiple SQL injection vulnerabilities in eMeeting Online Dating Software 5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) b.php and (2) account/gallery.php, and other unspecified vectors.EXPLOIT ✓HIGH 7.5EPSS 1.78%6 July 2007
CVE-2007-3608Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certain files via unspecified vectors.EXPLOIT ×2 ✓MEDIUM 5.0EPSS 2.83%6 July 2007
CVE-2007-3607Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) via unspecified vectors.EXPLOIT ×2 ✓MEDIUM 5.0EPSS 3.75%6 July 2007
CVE-2007-3606Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCII versions, allows remote attackers to execute arbitrary code via a long first argument to the LaunchGui function.EXPLOIT ✓HIGH 7.6EPSS 7.65%6 July 2007
CVE-2007-3605Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP SAP GUI allows remote attackers to execute arbitrary code via a long argument to the PrepareToPostHTML function.EXPLOIT ×2 ✓HIGH 7.6EPSS 69.9%6 July 2007
CVE-2007-3594Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter in (a) ping.do and (b) traceRoute.do in map/; the (2) reportName,…EXPLOIT ×5 ✓LOW 2.6EPSS 5.77%6 July 2007
CVE-2007-3593Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject arbitrary web script or HTML via the (1) alpha parameter in (a) netflow/jspui/applicationList.jsp, the (2) task parameter in (b)…EXPLOIT ×5 ✓MEDIUM 4.3EPSS 4.10%6 July 2007
CVE-2007-3590Cross-site scripting (XSS) vulnerability in visitenkarte.php in b1gBB 2.24.0 allows remote attackers to inject arbitrary web script or HTML via the user parameter.EXPLOIT ✓MEDIUM 4.3EPSS 3.20%5 July 2007
CVE-2007-3589Multiple SQL injection vulnerabilities in b1gbb 2.24.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) showthread.php or (2) showboard.php.EXPLOIT ✓HIGH 7.5EPSS 1.04%5 July 2007
CVE-2007-2839gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary commands via unknown vectors.EXPLOIT ✓HIGH 7.2EPSS 0.77%5 July 2007
CVE-2007-3587MyCMS 0.9.8 and earlier allows remote attackers to gain privileges via the admin cookie parameter, as demonstrated by a post to admin/settings.php that injects PHP code into settings.inc, which can then be executed via a direct request to index.php.EXPLOIT ✓HIGH 7.5EPSS 2.89%5 July 2007
CVE-2007-3586Multiple direct static code injection vulnerabilities in MyCMS 0.9.8 and earlier allow remote attackers to inject arbitrary PHP code into (1) a _score.txt file via the score parameter, or (2) a _setby.txt file via a login cookie, which is then included…EXPLOIT ✓HIGH 7.5EPSS 2.31%5 July 2007
CVE-2007-3585PHP remote file inclusion vulnerability in games.php in MyCMS 0.9.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.EXPLOIT ✓HIGH 7.5EPSS 2.34%5 July 2007
CVE-2007-3584SQL injection vulnerability in viewforum.php in PNphpBB2 1.2i and earlier for Postnuke allows remote attackers to execute arbitrary SQL commands via the order parameter.EXPLOIT ✓HIGH 7.5EPSS 1.03%5 July 2007

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.