SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,636 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026

25,049 results · page 332 of 501

CVESummaryPriorityPublished
CVE-2007-3583SQL injection vulnerability in details_news.php in Girlserv ads 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the idnew parameter.EXPLOIT ✓HIGH 7.5EPSS 1.20%5 July 2007
CVE-2007-3582SQL injection vulnerability in index.php in SuperCali PHP Event Calendar 0.4.0 allows remote attackers to execute arbitrary SQL commands via the o parameter.EXPLOIT ✓HIGH 7.5EPSS 2.45%5 July 2007
CVE-2007-3574Multiple cross-site scripting (XSS) vulnerabilities in setup.cgi on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.00.06 firmware allow remote attackers to inject arbitrary web script or HTML via the (1) c4_trap_ip_, (2) devname, (3)…EXPLOIT ✓MEDIUM 4.3EPSS 1.94%5 July 2007
CVE-2007-3572Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the param parameter, as demonstrated by URL encoded…EXPLOIT ✓HIGH 9.3EPSS 8.38%5 July 2007
CVE-2007-3569Multiple cross-site scripting (XSS) vulnerabilities in Oliver Library Management System allow remote attackers to inject arbitrary web script or HTML via the (1) updateform and (2) displayform parameter to (a) gateway/gateway.exe; the (3) TERMS, (4)…EXPLOIT ✓MEDIUM 4.3EPSS 4.39%5 July 2007
CVE-2007-3011The DBAsciiAccess CGI Script in the web interface in Fujitsu-Siemens Computers ServerView before 4.50.09 allows remote attackers to execute arbitrary commands via shell metacharacters in the Servername subparameter of the ParameterList parameter.EXPLOIT ✓HIGH 7.5EPSS 4.17%5 July 2007
CVE-2007-3563SQL injection vulnerability in includes/view_page.php in AV Arcade 2.1b allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_page action to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.21%4 July 2007
CVE-2007-3562SQL injection vulnerability in videos.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.78%4 July 2007
CVE-2007-3558SQL injection vulnerability in Coppermine Photo Gallery (CPG) before 1.4.11 allows remote attackers to execute arbitrary SQL commands via an album password cookie to an unspecified component.EXPLOIT ✓HIGH 7.5EPSS 1.02%4 July 2007
CVE-2007-3556Liesbeth base CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an include file containing account credentials via a direct request for config.inc.EXPLOIT ✓MEDIUM 5.0EPSS 3.02%4 July 2007
CVE-2007-3555Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.EXPLOIT ✓MEDIUM 4.3EPSS 2.95%4 July 2007
CVE-2007-3554Stack-based buffer overflow in the HPSDDX Class (SDD) ActiveX control in sdd.dll in HP Instant Support - Driver Check before 1.5.0.3 allows remote attackers to execute arbitrary code via a long argument to the queryHub function.EXPLOIT ×2 ✓HIGH 7.6EPSS 17.9%4 July 2007
CVE-2007-3553Cross-site scripting (XSS) vulnerability in Rapid Install Web Server in Oracle Application Server 11i allows remote attackers to inject arbitrary web script or HTML via a URL to the "Secondary Login Page", as demonstrated using (1) pls/ and (2)…EXPLOIT ✓MEDIUM 4.3EPSS 1.81%3 July 2007
CVE-2007-3549SQL injection vulnerability in view_sub_cat.php in Buddy Zone 1.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%3 July 2007
CVE-2007-3548Stack-based buffer overflow in W3Filer 2.1.3 allows remote FTP servers to cause a denial of service (application hang or crash) and possibly execute arbitrary code by sending a large banner to a client that is sending a file.EXPLOIT ✓HIGH 7.1EPSS 3.89%3 July 2007
CVE-2007-3547Directory traversal vulnerability in qti_checkname.php in QuickTicket 1.2 allows remote attackers to include and execute arbitrary local files a ..EXPLOIT ✓HIGH 7.8EPSS 2.94%3 July 2007
CVE-2007-3542Cross-site scripting (XSS) vulnerability in admin/auth.php in Pluxml 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.88%3 July 2007
CVE-2007-3539Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) t and (2) f parameters in (a) qti_ind_post.php and (b) qti_ind_post_prt.php; (3) dir…EXPLOIT ✓HIGH 7.5EPSS 4.83%3 July 2007
CVE-2007-3536Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers to execute arbitrary code via long (1) Host, (2) Password, or (3) LogFile property values.EXPLOIT ✓HIGH 7.6EPSS 13.7%3 July 2007
CVE-2007-3535Multiple directory traversal vulnerabilities in GL-SH Deaf Forum 6.4.4 and earlier allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ×2 ✓MEDIUM 6.4EPSS 2.64%3 July 2007
CVE-2007-3534SQL injection vulnerability in login.php in WebChat 0.78 allows remote attackers to execute arbitrary SQL commands via the rid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.06%3 July 2007
CVE-2007-3530PHPDirector 0.21 and earlier stores the admin account name and password in config.php, which allows local users to gain privileges by reading this file.EXPLOIT ✓HIGH 7.2EPSS 0.83%3 July 2007
CVE-2007-3529videos.php in PHPDirector 0.21 and earlier allows remote attackers to obtain sensitive information via an empty value of the id[] parameter, which reveals the path in an error message.EXPLOIT ✓HIGH 7.8EPSS 2.68%3 July 2007
CVE-2007-3526Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the news_id parameter to view_news.php, (2) the cat_id parameter to view_events.php, or (3) the member_id parameter to…EXPLOIT ✓HIGH 7.5EPSS 2.49%3 July 2007
CVE-2007-3524Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the level parameter to (1) admin/includes/author_panel_header.php or (2)…EXPLOIT ✓MEDIUM 6.8EPSS 64.2%3 July 2007
CVE-2007-3523Multiple directory traversal vulnerabilities in Module/Galerie.php in XCMS 1.1 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.4EPSS 2.39%3 July 2007
CVE-2007-3522Multiple PHP remote file inclusion vulnerabilities in sPHPell 1.01 allow remote attackers to execute arbitrary PHP code via a URL in the SpellIncPath parameter to (1) spellcheckpageinc.php, (2) spellchecktext.php, (3) spellcheckwindow.php, or (4)…EXPLOIT ✓MEDIUM 6.8EPSS 66.2%3 July 2007
CVE-2007-3521SQL injection vulnerability in ArcadeBuilder Game Portal Manager 1.7 allows remote attackers to execute arbitrary SQL commands via a usercookie cookie.EXPLOIT ✓HIGH 7.5EPSS 1.06%3 July 2007
CVE-2007-3520SQL injection vulnerability in process.php in Easybe 1-2-3 Music Store allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.EXPLOIT ✓HIGH 7.5EPSS 1.22%3 July 2007
CVE-2007-3519SQL injection vulnerability in eventdisplay.php in phpEventCalendar 0.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.23%3 July 2007
CVE-2007-3518SQL injection vulnerability in msg.php in HispaH YouTube Clone Script (youtubeclone) allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.22%3 July 2007
CVE-2007-3517Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) index.php, (2) demo/claroline170/index.php, and possibly other scripts.EXPLOIT ✓MEDIUM 4.3EPSS 1.81%3 July 2007
CVE-2007-3515SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 10.0EPSS 1.82%3 July 2007
CVE-2007-3505Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.4EPSS 7.94%2 July 2007
CVE-2007-2801Multiple cross-site scripting (XSS) vulnerabilities in open.php in eTicket 1.5.5 and 1.5.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) err and (2) warn parameters.EXPLOIT ✓MEDIUM 4.3EPSS 2.35%30 June 2007
CVE-2007-3493A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other products, allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument…EXPLOIT ✓HIGH 7.5EPSS 31.3%29 June 2007
CVE-2007-3492Conti FtpServer 1.0 allows remote authenticated users to cause a denial of service (daemon crash) via a certain string containing "//A:" in the argument to the LIST command.EXPLOIT ✓MEDIUM 6.8EPSS 2.66%29 June 2007
CVE-2007-3490Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified vectors, possibly related to the sheet name, as demonstrated by 2670.xls.EXPLOIT ✓HIGH 7.5EPSS 36.6%29 June 2007
CVE-2007-3488Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5 before 1.29; SNC-CS10 and SNC-CS11 before 1.06; SNC-DF40N and SNC-DF70N before 1.18; SNC-RZ50N and SNC-CS50N before 2.22; SNC-DF85N,…EXPLOIT ✓HIGH 10.0EPSS 16.2%29 June 2007
CVE-2007-3487Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote attackers to create or overwrite arbitrary files via the argument to the saveXMLAsFile method.EXPLOIT ✓MEDIUM 6.4EPSS 8.77%29 June 2007
CVE-2007-3479Stack-based buffer overflow in PCSoft WinDEV 11 (01F110053p) allows user-assisted remote attackers to execute arbitrary code via a long string in the "used DLL" field in a WDP project file.EXPLOIT ✓MEDIUM 6.8EPSS 3.48%28 June 2007
CVE-2007-3473The gdImageCreateXbm function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via unspecified vectors involving a gdImageCreate failure.EXPLOIT ✓MEDIUM 4.3EPSS 13.3%28 June 2007
CVE-2007-3461SQL injection vulnerability in property.php in elkagroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.06%27 June 2007
CVE-2007-3460Multiple PHP remote file inclusion vulnerabilities in index.php3 in EVA-Web 1.1 through 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) aide or (2) perso parameter.EXPLOIT ✓HIGH 7.5EPSS 3.28%27 June 2007
CVE-2007-3459A certain ActiveX control in Avaxswf.dll 1.0.0.1 in Civitech Avax Vector 1.3 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the WriteMovie method.EXPLOIT ✓MEDIUM 6.4EPSS 2.88%27 June 2007
CVE-2006-7210Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a PNG image with crafted (1) Width and (2) Height values in the IHDR block.EXPLOIT ×3 ✓MEDIUM 5.0EPSS 25.1%27 June 2007
CVE-2007-3452SQL injection vulnerability in essentials/minutes/doc.php in eDocStore allows remote attackers to execute arbitrary SQL commands via the doc_id parameter in an inline action.EXPLOIT ✓HIGH 7.5EPSS 1.07%27 June 2007
CVE-2007-3451PHP remote file inclusion vulnerability in admin/index.php in 6ALBlog allows remote authenticated administrators to execute arbitrary PHP code via a URL in the pg parameter.EXPLOIT ✓MEDIUM 6.5EPSS 2.79%27 June 2007
CVE-2007-3450SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the member parameter.EXPLOIT ✓MEDIUM 6.8EPSS 0.83%27 June 2007
CVE-2007-3449SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the newsid parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.14%27 June 2007

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.