SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,636 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026

25,049 results · page 333 of 501

CVESummaryPriorityPublished
CVE-2007-3448Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.86%27 June 2007
CVE-2007-3447SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the "basic search box." NOTE: 4.0.2 and other versions might also be affected.EXPLOIT ✓MEDIUM 6.8EPSS 1.14%27 June 2007
CVE-2007-3446BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers to obtain login access.EXPLOIT ✓HIGH 7.5EPSS 7.70%27 June 2007
CVE-2007-3435Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) BarCodeAx.dll 4.9 allows remote attackers to execute arbitrary code via a long argument.EXPLOIT ×2 ✓HIGH 9.3EPSS 35.4%27 June 2007
CVE-2007-3434index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the page parameter, which reveals the table prefix in an error message.EXPLOIT ✓MEDIUM 5.0EPSS 2.68%27 June 2007
CVE-2007-3433SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter in an add action.EXPLOIT ✓HIGH 7.5EPSS 1.04%27 June 2007
CVE-2007-3432Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jpg filename.EXPLOIT ✓HIGH 7.5EPSS 8.18%27 June 2007
CVE-2007-3431PHP remote file inclusion vulnerability in cal.func.php in Valerio Capello Dagger - The Cutting Edge r23jan2007 allows remote attackers to execute arbitrary PHP code via a URL in the dir_edge_lang parameter.EXPLOIT ✓MEDIUM 6.8EPSS 70.7%27 June 2007
CVE-2007-3430SQL injection vulnerability in index.php in Simple Invoices 2007 05 25 allows remote attackers to execute arbitrary SQL commands via the submit parameter in an email action.EXPLOIT ✓HIGH 7.5EPSS 1.20%27 June 2007
CVE-2007-3429Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.EXPLOIT ✓MEDIUM 6.8EPSS 2.07%27 June 2007
CVE-2007-3427SQL injection vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a stats action.EXPLOIT ✓HIGH 7.5EPSS 1.64%27 June 2007
CVE-2007-3426Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.93%27 June 2007
CVE-2007-3425Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbitrary local files via the lang parameter, a different vector and version than CVE-2007-1076.2.EXPLOIT ✓MEDIUM 5.0EPSS 3.12%27 June 2007
CVE-2006-7208PHP remote file inclusion vulnerability in download.php in the Adam van Dongen Forum (com_forum) component (aka phpBB component) 1.2.4RC3 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path…EXPLOIT ✓MEDIUM 6.8EPSS 5.11%26 June 2007
CVE-2007-3410Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPlayer 10, 10.1, and possibly 10.5, RealOne Player, RealPlayer Enterprise, and Helix Player 10.5-GOLD and 10.0.5 through 10.0.8, allows…EXPLOIT ✓HIGH 9.3EPSS 36.1%26 June 2007
CVE-2007-3407Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) via a URL with a trailing encoded space (%20).EXPLOIT ✓MEDIUM 5.0EPSS 8.43%26 June 2007
CVE-2007-3406Multiple absolute path traversal vulnerabilities in Microsoft Internet Explorer 6 on Windows XP SP2 allow remote attackers to access arbitrary local files via the file: URI in the (1) src attribute of a (a) bgsound, (b) input, (c) EMBED, (d) img, or (e)…EXPLOIT ✓MEDIUM 4.3EPSS 10.9%26 June 2007
CVE-2007-3404Directory traversal vulnerability in ShowImage.php in SiteDepth CMS 3.44 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.85%26 June 2007
CVE-2007-3403Unrestricted file upload vulnerability in upload.php in dreamLog (aka dreamblog) 0.5 allows remote attackers to upload and execute arbitrary PHP code in uploads/images/ via the uploadedFile[] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.51%26 June 2007
CVE-2007-3402SQL injection vulnerability in index.php in pagetool 1.07 allows remote attackers to execute arbitrary SQL commands via the news_id parameter in a pagetool_news action.EXPLOIT ✓HIGH 7.5EPSS 1.22%26 June 2007
CVE-2007-3401PHP remote file inclusion vulnerability in footer.inc.php in B1G b1gBB 2.24 allows remote attackers to execute arbitrary PHP code via a URL in the tfooter parameter.EXPLOIT ✓HIGH 7.5EPSS 74.0%26 June 2007
CVE-2007-3400The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.7, allows remote attackers to overwrite arbitrary files via the CreateFile method.EXPLOIT ✓HIGH 9.3EPSS 3.64%26 June 2007
CVE-2007-3398LiteWEB 2.7 allows remote attackers to cause a denial of service (hang) via a large number of requests for nonexistent pages.EXPLOIT ✓MEDIUM 5.0EPSS 2.82%26 June 2007
CVE-2007-3396Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter.EXPLOIT ✓MEDIUM 4.3EPSS 2.45%26 June 2007
CVE-2007-3394Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the (1) artid parameter to mod.php in a viewarticle action (publisher mod) and the (2) bid parameter to banners.php in a click action.EXPLOIT ×2 ✓HIGH 7.5EPSS 2.14%26 June 2007
CVE-2007-3183Multiple SQL injection vulnerabilities in Calendarix 0.7.20070307, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters to calendar.php and the (3) search string to…EXPLOIT ✓MEDIUM 6.8EPSS 4.50%26 June 2007
CVE-2007-3182Multiple cross-site scripting (XSS) vulnerabilities in Calendarix 0.7.20070307, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) month parameters to calendar.php, and the (3)…EXPLOIT ✓MEDIUM 4.3EPSS 4.30%26 June 2007
CVE-2007-2520SQL injection vulnerability in admin.php in MyNews 0.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authacc cookie.EXPLOIT ✓MEDIUM 6.8EPSS 1.10%26 June 2007
CVE-2007-2401CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing…EXPLOIT ✓MEDIUM 4.3EPSS 7.06%25 June 2007
CVE-2007-3371PHP remote file inclusion vulnerability in plugins/widgets/htmledit/htmledit.php in Powl 0.94 allows remote attackers to execute arbitrary PHP code via a URL in the _POWL[installPath] parameter.EXPLOIT ✓HIGH 7.5EPSS 71.2%22 June 2007
CVE-2007-3370Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote attackers to execute arbitrary PHP code via a URL in (1) the sunPath parameter to include.php or (2) the dir parameter to skin/board/default/doctype.php.EXPLOIT ✓HIGH 7.5EPSS 74.5%22 June 2007
CVE-2007-3365MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions, which allows remote attackers to obtain sensitive information (script source code) via a modified extension, as demonstrated by post.mscgI.EXPLOIT ✓HIGH 7.5EPSS 5.97%22 June 2007
CVE-2007-3364Cross-site scripting (XSS) vulnerability in the cgi-bin/post.mscgi sample page in MyServer 0.8.9 allows remote attackers to inject arbitrary web script or HTML via the body content.EXPLOIT ✓MEDIUM 4.3EPSS 4.15%22 June 2007
CVE-2007-3360hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data containing NICK and EXEC strings, which exceeds the bounds of a hash table, and injects an EXEC hook function that receives and executes…EXPLOIT ✓HIGH 9.3EPSS 7.46%22 June 2007
CVE-2007-3358PHP remote file inclusion vulnerability in html/load_lang.php in SerWeb 0.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SERWEB[serwebdir] parameter.EXPLOIT ✓MEDIUM 6.8EPSS 68.0%22 June 2007
CVE-2007-3354Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition allow remote attackers to execute arbitrary SQL commands via the s_user_id parameter to ViewCat.php and other unspecified vectors.EXPLOIT ✓HIGH 7.5EPSS 2.11%22 June 2007
CVE-2007-3346Directory traversal vulnerability in index.php in PHPAccounts 0.5 allows remote attackers to include arbitrary local files via unspecified manipulations of the page parameter.EXPLOIT ✓HIGH 7.8EPSS 2.77%22 June 2007
CVE-2007-3336Multiple "pointer overwrite" vulnerabilities in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (formerly Computer Associates) products, allow remote attackers to execute arbitrary code by sending certain TCP data at…EXPLOIT ✓HIGH 10.0EPSS 8.96%22 June 2007
CVE-2006-7206Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating a ADODB.Recordset object and making a series of calls to the NextRecordset method with a long string argument, which causes an…EXPLOIT ✓HIGH 7.8EPSS 22.1%22 June 2007
CVE-2007-3340BugHunter HTTP SERVER (httpsv.exe) 1.6.2 allows remote attackers to cause a denial of service (application crash) via a large number of requests for nonexistent pages.EXPLOIT ✓HIGH 7.8EPSS 4.08%21 June 2007
CVE-2007-3334Multiple heap-based buffer overflows in the (1) Communications Server (iigcc.exe) and (2) Data Access Server (iigcd.exe) components for Ingres Database Server 3.0.3, as used in CA (Computer Associates) products including eTrust Secure Content Manager r8…EXPLOIT ✓HIGH 10.0EPSS 10.3%21 June 2007
CVE-2007-3339Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject arbitrary web script or HTML via the (1) FTVAR_LINKP and (2) FTVAR_URLP…EXPLOIT ×3 ✓MEDIUM 4.3EPSS 4.08%21 June 2007
CVE-2007-3332Directory traversal vulnerability in Satellite.php in Satel Lite for PhpNuke allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.74%21 June 2007
CVE-2007-3327httpsv.exe in HTTP Server 1.6.2 allows remote attackers to obtain sensitive information (script source code) via a URI with a trailing %20 (encoded space).EXPLOIT ✓MEDIUM 5.0EPSS 2.63%21 June 2007
CVE-2007-3325PHP remote file inclusion vulnerability in lib/language.php in LAN Management System (LMS) 1.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643 and…EXPLOIT ✓HIGH 7.5EPSS 64.4%21 June 2007
CVE-2007-3324Multiple cross-site scripting (XSS) vulnerabilities in Comersus Cart 7.07 allow remote attackers to inject arbitrary web script or HTML via the redirectUrl parameter to (1) comersus_customerAuthenticateForm.asp or (2) comersus_message.asp, different…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.84%21 June 2007
CVE-2007-3323SQL injection vulnerability in comersus_optReviewReadExec.asp in Comersus Shop Cart 7.07 allows remote attackers to execute arbitrary SQL commands via the idProduct parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%21 June 2007
CVE-2007-3315Multiple PHP remote file inclusion vulnerabilities in YourFreeScreamer 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the serverPath parameter to bodyTemplate.php in (1) templates/Classic/, (2)…EXPLOIT ✓MEDIUM 6.8EPSS 1.92%21 June 2007
CVE-2007-3314Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (English Trial), and 2.0 with Portable Executable Viewer 1.00 (English Trial), allows remote attackers to execute arbitrary code via a long…EXPLOIT ✓MEDIUM 6.8EPSS 43.4%21 June 2007
CVE-2007-3313Multiple SQL injection vulnerabilities in Jasmine CMS 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the login_username parameter to login.php or (2) the item parameter to news.php.EXPLOIT ✓HIGH 7.5EPSS 1.75%21 June 2007

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.