SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,636 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026

25,049 results · page 335 of 501

CVESummaryPriorityPublished
CVE-2007-3188SQL injection vulnerability in down_indir.asp in Fullaspsite GeometriX Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.20%12 June 2007
CVE-2007-3181Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p_cnct structure in a connect (0x01) request to port 3050/tcp, related to "an InterBase version of…EXPLOIT ✓HIGH 10.0EPSS 13.2%12 June 2007
CVE-2007-3186Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, as demonstrated using a gopher URI.EXPLOIT ✓HIGH 9.3EPSS 4.93%12 June 2007
CVE-2007-2222Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that…EXPLOIT ×2 ✓HIGH 9.3EPSS 54.7%12 June 2007
CVE-2007-3171Uebimiau Webmail allows remote attackers to obtain sensitive information via a request to demo/pop3/error.php with an invalid value of the (1) smarty or (2) selected_theme parameter, which reveals the path in various error messages.EXPLOIT ✓MEDIUM 5.0EPSS 2.46%11 June 2007
CVE-2007-3170Multiple cross-site scripting (XSS) vulnerabilities in Uebimiau Webmail allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to redirect.php or (2) the selected_theme parameter to demo/pop3/error.php.EXPLOIT ✓MEDIUM 4.3EPSS 1.53%11 June 2007
CVE-2007-3169Buffer overflow in a certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) or execute arbitrary code…EXPLOIT ✓HIGH 9.3EPSS 11.9%11 June 2007
CVE-2007-3168A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to delete arbitrary files via the DeleteLocalFile method.EXPLOIT ✓HIGH 7.8EPSS 6.31%11 June 2007
CVE-2007-3167Stack-based buffer overflow in the Vivotek Motion Jpeg ActiveX control (aka MjpegControl) in MjpegDecoder.dll 2.0.0.13 allows remote attackers to execute arbitrary code via a long PtzUrl property value.EXPLOIT ✓HIGH 7.6EPSS 6.12%11 June 2007
CVE-2007-3166Buffer overflow in Qualcomm Eudora 7.1.0.9 allows user-assisted, remote IMAP servers to execute arbitrary code via a long FLAGS response to a SELECT INBOX command.EXPLOIT ✓MEDIUM 6.8EPSS 2.09%11 June 2007
CVE-2007-3162Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Accelerator (ida) 5.2 allows remote attackers to cause a denial of service (Internet Explorer crash) via a long argument.EXPLOIT ×2 ✓MEDIUM 5.0EPSS 8.19%11 June 2007
CVE-2007-3161Buffer overflow in Ace-FTP Client 1.24a allows user-assisted, remote FTP servers to execute arbitrary code via a long response.EXPLOIT ✓MEDIUM 6.8EPSS 3.30%11 June 2007
CVE-2007-3160PHP remote file inclusion vulnerability in admin/header.php in PHP Real Estate Classifieds Premium Plus allows remote attackers to execute arbitrary PHP code via a URL in the loc parameter.EXPLOIT ✓HIGH 7.5EPSS 3.14%11 June 2007
CVE-2007-3159http.c in MiniWeb Http Server 0.8.x allows remote attackers to cause a denial of service (application crash) via a negative value in the Content-Length HTTP header.EXPLOIT ✓MEDIUM 5.0EPSS 2.76%11 June 2007
CVE-2007-3158download_script.asp in ASP Folder Gallery allows remote attackers to read arbitrary files via a filename in the file parameter.EXPLOIT ✓MEDIUM 5.0EPSS 2.27%11 June 2007
CVE-2007-3157IPSecDrv.sys 10.4.0.12 in SafeNET High Assurance Remote 1.4.0 Build 12, and SoftRemote, allows remote attackers to cause a denial of service (infinite loop and system hang) via an invalid packet with certain bytes in an option header, possibly related…EXPLOIT ✓MEDIUM 5.0EPSS 8.83%11 June 2007
CVE-2007-3151rpttop.htm in the web management interface in Packeteer PacketShaper 7.3.0g2 and 7.5.0g1 allows remote attackers to cause a denial of service (device reboot) via a request with empty values of the OP.MEAS.DATAQUERY and MEAS.TYPE parameters.EXPLOIT ✓MEDIUM 5.0EPSS 7.34%11 June 2007
CVE-2006-3974Cross-site scripting (XSS) vulnerability in cgi-bin/admin in 3Com OfficeConnect Secure Router with firmware 1.04-168 allows remote attackers to inject arbitrary web script or HTML via the tk parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.77%11 June 2007
CVE-2007-3148Buffer overflow in the Yahoo!EXPLOIT ×2 ✓HIGH 9.3EPSS 12.3%11 June 2007
CVE-2007-3147Buffer overflow in the Yahoo!EXPLOIT ×3 ✓HIGH 9.3EPSS 40.4%11 June 2007
CVE-2007-3141PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 allows remote attackers to execute arbitrary PHP code via a URL in the editor_insert_top parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.97%11 June 2007
CVE-2007-1685Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 2372.EXPLOIT ✓HIGH 10.0EPSS 13.5%8 June 2007
CVE-2007-3140SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value in an XML RPC wp.suggestCategories methodCall, a different vector than CVE-2007-1897.EXPLOIT ✓MEDIUM 6.5EPSS 7.32%8 June 2007
CVE-2007-3139config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to access the application via a login action to admin.php.EXPLOIT ✓MEDIUM 6.8EPSS 3.51%8 June 2007
CVE-2007-3138Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.90%8 June 2007
CVE-2007-3137Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in WmsCMS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sbl, (2) sbr, or (3) search parameter.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.80%8 June 2007
CVE-2007-3136PHP remote file inclusion vulnerability in inc/nuke_include.php in newsSync 1.5.0rc6 allows remote attackers to execute arbitrary PHP code via a URL in the newsSync_NUKE_PATH parameter.EXPLOIT ✓HIGH 7.5EPSS 2.34%8 June 2007
CVE-2007-3134Multiple cross-site scripting (XSS) vulnerabilities in atomPhotoBlog.php in Atom PhotoBlog 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Your Name, (2) Your Homepage, and (3) Your Comment fields, when using…EXPLOIT ✓MEDIUM 4.3EPSS 1.53%8 June 2007
CVE-2007-3133SQL injection vulnerability in urunbak.asp in W1L3D4 WEBmarket 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.64%8 June 2007
CVE-2007-3130Multiple PHP remote file inclusion vulnerabilities in the OpenWiki (formerly JD-Wiki) component (com_jd-wiki) 1.0.2, and possibly earlier, for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path…EXPLOIT ×2 ✓MEDIUM 6.8EPSS 4.46%8 June 2007
CVE-2007-3119SQL injection vulnerability in news.asp in Kartli Alisveris Sistemi (aka Free-PayPal-Shopping-Cart) 1.0 allows remote attackers to execute arbitrary SQL commands via the news_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.20%7 June 2007
CVE-2007-3118Multiple PHP remote file inclusion vulnerabilities in Kravchuk letter (K-letter) 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the scdir parameter to (1) action.php, (2) subs.php, or (3) unsubs.php.EXPLOIT ✓HIGH 7.5EPSS 3.39%7 June 2007
CVE-2007-3111Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used on Windows 2000 SP4, allows remote attackers to execute arbitrary code via a long URL property value.EXPLOIT ✓HIGH 10.0EPSS 44.4%7 June 2007
CVE-2007-3098The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a denial of service (crash) via a crafted packet to port 165/TCP.EXPLOIT ✓MEDIUM 5.0EPSS 3.57%6 June 2007
CVE-2007-3096Directory traversal vulnerability in login.php in PBLang (PBL) 4.67.16.a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 2.50%6 June 2007
CVE-2007-2919Multiple stack-based buffer overflows in the FViewerLoading ActiveX control (FlipViewerX.dll) in E-Book Systems FlipViewer before 4.1 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via long (1) UID, (2) Opf, (3)…EXPLOIT ✓HIGH 9.3EPSS 33.7%6 June 2007
CVE-2007-2864Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file.EXPLOIT ✓HIGH 9.3EPSS 49.6%6 June 2007
CVE-2007-2237Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.EXPLOIT ×2 ✓MEDIUM 5.5EPSS 15.4%6 June 2007
CVE-2007-3088SQL injection vulnerability in index.php in Comicsense allows remote attackers to execute arbitrary SQL commands via the epi parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.17%6 June 2007
CVE-2007-3086Unrestricted critical resource lock in Agnitum Outpost Firewall PRO 4.0 1007.591.145 and earlier allows local users to cause a denial of service (system hang) by capturing the outpost_ipc_hdr mutex.EXPLOIT ✓MEDIUM 4.9EPSS 0.68%6 June 2007
CVE-2007-3082Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.8EPSS 2.93%6 June 2007
CVE-2007-3080SQL injection vulnerability in haberoku.asp in Hunkaray Okul Portaly 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.01%6 June 2007
CVE-2007-3077SQL injection vulnerability in listmembers.php in EQdkp 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the rank parameter.EXPLOIT ✓HIGH 7.5EPSS 1.22%6 June 2007
CVE-2007-3076A certain ActiveX control in sasatl.dll in Zenturi ProgramChecker allows remote attackers to download arbitrary files to the client system via the DownloadFile function.EXPLOIT ✓HIGH 7.8EPSS 2.59%6 June 2007
CVE-2007-3071Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSellerate SDK allows user-assisted remote attackers to execute arbitrary code via a long first argument.EXPLOIT ×2 ✓HIGH 9.3EPSS 5.84%6 June 2007
CVE-2007-3070Cross-site scripting (XSS) vulnerability in index.php in BDigital Web Solutions WebStudio allows remote attackers to inject arbitrary web script or HTML via the pageid parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.80%6 June 2007
CVE-2007-3068Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF playlist containing a long filename.EXPLOIT ×4 ✓MEDIUM 6.8EPSS 32.9%6 June 2007
CVE-2007-3065SQL injection vulnerability in viewimage.php in Particle Soft Particle Gallery 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the editcomment parameter, a different version and vector than CVE-2006-2862.EXPLOIT ✓HIGH 7.5EPSS 1.05%6 June 2007
CVE-2007-3064Cross-site scripting (XSS) vulnerability in diary.php in My Databook allows remote attackers to inject arbitrary web script or HTML via the year parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.51%6 June 2007
CVE-2007-3063SQL injection vulnerability in diary.php in My Databook allows remote attackers to execute arbitrary SQL commands via the delete parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%6 June 2007

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.