SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,636 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026

25,049 results · page 334 of 501

CVESummaryPriorityPublished
CVE-2007-3312Directory traversal vulnerability in admin/plugin_manager.php in Jasmine CMS 1.0 allows remote authenticated administrators to include and execute arbitrary local files a ..EXPLOIT ✓HIGH 9.0EPSS 7.32%21 June 2007
CVE-2007-3311SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.04%21 June 2007
CVE-2007-3310Cross-site scripting (XSS) vulnerability in arama.asp in TDizin allows remote attackers to inject arbitrary web script or HTML via the ara parameter.EXPLOIT ✓MEDIUM 4.3EPSS 3.18%21 June 2007
CVE-2007-3307SQL injection vulnerability in game_listing.php in Solar Empire 2.9.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.EXPLOIT ✓HIGH 7.5EPSS 1.04%21 June 2007
CVE-2007-3306PHP remote file inclusion vulnerability in crontab/run_billing.php in MiniBill 1.2.5 allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter, a different vector than CVE-2006-4489.EXPLOIT ✓HIGH 7.5EPSS 64.4%21 June 2007
CVE-2007-3301SQL injection vulnerability in forum/include/error/autherror.cfm in FuseTalk allows remote attackers to execute arbitrary SQL commands via the errorcode parameter.EXPLOIT ✓HIGH 7.5EPSS 1.00%20 June 2007
CVE-2007-3297Multiple PHP remote file inclusion vulnerabilities in Musoo 0.21 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[ini_array][EXTLIB_PATH] parameter to (1) msDb.php, (2) modules/MusooTemplateLite.php, or (3)…EXPLOIT ✓HIGH 7.5EPSS 8.99%20 June 2007
CVE-2007-3294Multiple buffer overflows in libtidy, as used in the Tidy extension for PHP 5.2.3 and possibly other products, allow context-dependent attackers to execute arbitrary code via (1) a long second argument to the tidy_parse_string function or (2) an…EXPLOIT ✓HIGH 7.5EPSS 9.39%20 June 2007
CVE-2007-3293SQL injection vulnerability in categoria.php in LiveCMS 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.26%20 June 2007
CVE-2007-3292Unrestricted file upload vulnerability in LiveCMS 3.4 and earlier allows remote attackers to upload and execute arbitrary PHP code by specifying a PHP file type in a parameter intended for "a small image" associated with an article.EXPLOIT ✓HIGH 7.5EPSS 2.45%20 June 2007
CVE-2007-3291Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via an article name, possibly involving the titulo parameter in article.php.EXPLOIT ✓MEDIUM 4.3EPSS 1.57%20 June 2007
CVE-2007-3290categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the cid parameter, which reveals the path in a forced SQL error message.EXPLOIT ✓HIGH 9.3EPSS 3.11%20 June 2007
CVE-2007-3289PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter.EXPLOIT ✓HIGH 7.5EPSS 12.2%20 June 2007
CVE-2007-3284corefoundation.dll in Apple Safari 3.0.1 (552.12.2) for Windows allows remote attackers to cause a denial of service (crash) via certain forms that trigger errors related to History, possibly involving multiple form fields with the same name.EXPLOIT ✓HIGH 7.8EPSS 3.08%19 June 2007
CVE-2007-3282Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the DeleteRecordSourceIfUnused method.EXPLOIT ✓HIGH 7.8EPSS 42.2%19 June 2007
CVE-2007-3281Cross-site scripting (XSS) vulnerability in index.php in Php Hosting Biller 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.EXPLOIT ✓MEDIUM 4.3EPSS 1.86%19 June 2007
CVE-2007-3272Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓HIGH 7.8EPSS 2.84%19 June 2007
CVE-2007-3271PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the serverPath parameter.EXPLOIT ✓HIGH 7.5EPSS 3.28%19 June 2007
CVE-2007-3270PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the strIncludePrefix parameter.EXPLOIT ✓HIGH 10.0EPSS 4.17%19 June 2007
CVE-2007-3267Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.01b and earlier allows remote attackers to inject arbitrary web script or HTML via the fromaction parameter in a log action, a different vector than CVE-2007-3235.EXPLOIT ✓MEDIUM 4.3EPSS 1.87%19 June 2007
CVE-2007-3266Directory traversal vulnerability in webif.cgi in ifnet WEBIF allows remote attackers to include and execute arbitrary local files a ..EXPLOIT ✓HIGH 9.0EPSS 7.86%19 June 2007
CVE-2007-3127content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to obtain sensitive information via a "';" (quote semicolon) sequence in the page parameter, which reveals the installation path in the resulting forced SQL error…EXPLOIT ✓MEDIUM 5.0EPSS 3.03%19 June 2007
CVE-2007-3251Multiple directory traversal vulnerabilities in e-Vision CMS 2.02 and earlier allow remote attackers to (1) include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.8EPSS 3.99%18 June 2007
CVE-2007-3249Cross-site scripting (XSS) vulnerability in mod_lettermansubscribe.php in the Letterman Subscriber (mod_letterman) before 1.2.5 module for Joomla! allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.93%18 June 2007
CVE-2007-3101Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to…EXPLOIT ✓MEDIUM 4.3EPSS 44.5%18 June 2007
CVE-2007-3243Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the re parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.80%15 June 2007
CVE-2007-3237PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter.EXPLOIT ✓MEDIUM 6.8EPSS 67.7%15 June 2007
CVE-2007-3236PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter.EXPLOIT ✓HIGH 7.5EPSS 77.0%15 June 2007
CVE-2007-3235Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to inject arbitrary web script or HTML via the topic parameter.EXPLOIT ✓MEDIUM 4.3EPSS 0.90%15 June 2007
CVE-2007-3234SQL injection vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the topic parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%15 June 2007
CVE-2007-3233The TEC-IT TBarCode OCX ActiveX control (TBarCode7.ocx) 7.0.2.3524 allows remote attackers to overwrite arbitrary files via the SaveImage method.EXPLOIT ✓MEDIUM 5.0EPSS 5.98%15 June 2007
CVE-2007-3230PHP remote file inclusion vulnerability in phphtml.php in Idan Sofer PHP::HTML 0.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the htmlclass_path parameter.EXPLOIT ✓MEDIUM 6.8EPSS 67.9%14 June 2007
CVE-2007-3228PHP remote file inclusion vulnerability in saf/lib/PEAR/PhpDocumentor/Documentation/tests/bug-559668.php in Sitellite CMS 4.2.12 and earlier might allow remote attackers to execute arbitrary PHP code via a URL in the FORUM[LIB] parameter.EXPLOIT ✓MEDIUM 6.8EPSS 67.5%14 June 2007
CVE-2007-3227Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.EXPLOIT ✓MEDIUM 4.3EPSS 3.68%14 June 2007
CVE-2007-3222PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the dir_module parameter.EXPLOIT ✓HIGH 7.5EPSS 7.44%14 June 2007
CVE-2007-3221PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter.EXPLOIT ✓MEDIUM 6.8EPSS 67.8%14 June 2007
CVE-2007-3220PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter.EXPLOIT ✓MEDIUM 6.8EPSS 62.7%14 June 2007
CVE-2007-2449Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote…EXPLOIT ✓MEDIUM 4.3EPSS 77.4%14 June 2007
CVE-2007-3217Multiple PHP remote file inclusion vulnerabilities in Prototype of an PHP application 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the path_inc parameter to (1) index.php in gestion/; (2) identification.php, (3) disconnect.php,…EXPLOIT ×12 ✓HIGH 7.5EPSS 10.1%14 June 2007
CVE-2007-3216Multiple buffer overflows in the LGServer component of CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.1 allow remote attackers to execute arbitrary code via crafted arguments to the (1) rxsAddNewUser, (2)…EXPLOIT ×3 ✓HIGH 10.0EPSS 59.2%14 June 2007
CVE-2007-3214SQL injection vulnerability in style.php in e-Vision CMS 2.02 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the template parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.13%14 June 2007
CVE-2007-3212Multiple cross-site scripting (XSS) vulnerabilities in links.php in Beehive Forum 0.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewmode, (2) fid, and (3) sort_dir parameters, different vectors than CVE-2005-4460.EXPLOIT ✓MEDIUM 4.3EPSS 1.77%14 June 2007
CVE-2007-3201Visual truncation vulnerability in Windows Privacy Tray (WinPT) 1.2.0 allows user-assisted remote attackers to install a key listed under the wrong user ID, and possibly cause the user to encrypt a victim's correspondence with this attacker-supplied…EXPLOIT ✓HIGH 7.1EPSS 2.71%12 June 2007
CVE-2007-3199Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension and an image content type, as demonstrated by image/jpeg.EXPLOIT ✓HIGH 7.5EPSS 3.00%12 June 2007
CVE-2007-3198Cross-site scripting (XSS) vulnerability in comments.php in Maran PHP Blog (Maran Blog), possibly only versions before 20070610, allows remote attackers to inject arbitrary web script or HTML via the id parameter.EXPLOIT ✓MEDIUM 4.3EPSS 2.49%12 June 2007
CVE-2007-3196SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL commands via the ticketid parameter in a showticket action.EXPLOIT ✓HIGH 7.5EPSS 1.20%12 June 2007
CVE-2007-3192admin/setup.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to read and modify configuration settings via a direct request.EXPLOIT ✓HIGH 9.4EPSS 3.56%12 June 2007
CVE-2007-3191Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to obtain configuration information via a direct request to admin/adm/test.php, which calls the phpinfo function.EXPLOIT ✓HIGH 9.4EPSS 8.38%12 June 2007
CVE-2007-3190Multiple SQL injection vulnerabilities in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) pass parameters.EXPLOIT ✓MEDIUM 6.8EPSS 1.45%12 June 2007
CVE-2007-3189Cross-site scripting (XSS) vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter.EXPLOIT ✓MEDIUM 4.3EPSS 3.97%12 June 2007

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.