Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,636 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 335 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-3188 | SQL injection vulnerability in down_indir.asp in Fullaspsite GeometriX Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 12 June 2007 |
| CVE-2007-3181 | Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p_cnct structure in a connect (0x01) request to port 3050/tcp, related to "an InterBase version of… | EXPLOIT ✓HIGH 10.0EPSS 13.2% | 12 June 2007 |
| CVE-2007-3186 | Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, as demonstrated using a gopher URI. | EXPLOIT ✓HIGH 9.3EPSS 4.93% | 12 June 2007 |
| CVE-2007-2222 | Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that… | EXPLOIT ×2 ✓HIGH 9.3EPSS 54.7% | 12 June 2007 |
| CVE-2007-3171 | Uebimiau Webmail allows remote attackers to obtain sensitive information via a request to demo/pop3/error.php with an invalid value of the (1) smarty or (2) selected_theme parameter, which reveals the path in various error messages. | EXPLOIT ✓MEDIUM 5.0EPSS 2.46% | 11 June 2007 |
| CVE-2007-3170 | Multiple cross-site scripting (XSS) vulnerabilities in Uebimiau Webmail allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to redirect.php or (2) the selected_theme parameter to demo/pop3/error.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.53% | 11 June 2007 |
| CVE-2007-3169 | Buffer overflow in a certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) or execute arbitrary code… | EXPLOIT ✓HIGH 9.3EPSS 11.9% | 11 June 2007 |
| CVE-2007-3168 | A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to delete arbitrary files via the DeleteLocalFile method. | EXPLOIT ✓HIGH 7.8EPSS 6.31% | 11 June 2007 |
| CVE-2007-3167 | Stack-based buffer overflow in the Vivotek Motion Jpeg ActiveX control (aka MjpegControl) in MjpegDecoder.dll 2.0.0.13 allows remote attackers to execute arbitrary code via a long PtzUrl property value. | EXPLOIT ✓HIGH 7.6EPSS 6.12% | 11 June 2007 |
| CVE-2007-3166 | Buffer overflow in Qualcomm Eudora 7.1.0.9 allows user-assisted, remote IMAP servers to execute arbitrary code via a long FLAGS response to a SELECT INBOX command. | EXPLOIT ✓MEDIUM 6.8EPSS 2.09% | 11 June 2007 |
| CVE-2007-3162 | Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Accelerator (ida) 5.2 allows remote attackers to cause a denial of service (Internet Explorer crash) via a long argument. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 8.19% | 11 June 2007 |
| CVE-2007-3161 | Buffer overflow in Ace-FTP Client 1.24a allows user-assisted, remote FTP servers to execute arbitrary code via a long response. | EXPLOIT ✓MEDIUM 6.8EPSS 3.30% | 11 June 2007 |
| CVE-2007-3160 | PHP remote file inclusion vulnerability in admin/header.php in PHP Real Estate Classifieds Premium Plus allows remote attackers to execute arbitrary PHP code via a URL in the loc parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.14% | 11 June 2007 |
| CVE-2007-3159 | http.c in MiniWeb Http Server 0.8.x allows remote attackers to cause a denial of service (application crash) via a negative value in the Content-Length HTTP header. | EXPLOIT ✓MEDIUM 5.0EPSS 2.76% | 11 June 2007 |
| CVE-2007-3158 | download_script.asp in ASP Folder Gallery allows remote attackers to read arbitrary files via a filename in the file parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.27% | 11 June 2007 |
| CVE-2007-3157 | IPSecDrv.sys 10.4.0.12 in SafeNET High Assurance Remote 1.4.0 Build 12, and SoftRemote, allows remote attackers to cause a denial of service (infinite loop and system hang) via an invalid packet with certain bytes in an option header, possibly related… | EXPLOIT ✓MEDIUM 5.0EPSS 8.83% | 11 June 2007 |
| CVE-2007-3151 | rpttop.htm in the web management interface in Packeteer PacketShaper 7.3.0g2 and 7.5.0g1 allows remote attackers to cause a denial of service (device reboot) via a request with empty values of the OP.MEAS.DATAQUERY and MEAS.TYPE parameters. | EXPLOIT ✓MEDIUM 5.0EPSS 7.34% | 11 June 2007 |
| CVE-2006-3974 | Cross-site scripting (XSS) vulnerability in cgi-bin/admin in 3Com OfficeConnect Secure Router with firmware 1.04-168 allows remote attackers to inject arbitrary web script or HTML via the tk parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.77% | 11 June 2007 |
| CVE-2007-3148 | Buffer overflow in the Yahoo! | EXPLOIT ×2 ✓HIGH 9.3EPSS 12.3% | 11 June 2007 |
| CVE-2007-3147 | Buffer overflow in the Yahoo! | EXPLOIT ×3 ✓HIGH 9.3EPSS 40.4% | 11 June 2007 |
| CVE-2007-3141 | PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 allows remote attackers to execute arbitrary PHP code via a URL in the editor_insert_top parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.97% | 11 June 2007 |
| CVE-2007-1685 | Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 2372. | EXPLOIT ✓HIGH 10.0EPSS 13.5% | 8 June 2007 |
| CVE-2007-3140 | SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value in an XML RPC wp.suggestCategories methodCall, a different vector than CVE-2007-1897. | EXPLOIT ✓MEDIUM 6.5EPSS 7.32% | 8 June 2007 |
| CVE-2007-3139 | config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to access the application via a login action to admin.php. | EXPLOIT ✓MEDIUM 6.8EPSS 3.51% | 8 June 2007 |
| CVE-2007-3138 | Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.90% | 8 June 2007 |
| CVE-2007-3137 | Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in WmsCMS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sbl, (2) sbr, or (3) search parameter. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.80% | 8 June 2007 |
| CVE-2007-3136 | PHP remote file inclusion vulnerability in inc/nuke_include.php in newsSync 1.5.0rc6 allows remote attackers to execute arbitrary PHP code via a URL in the newsSync_NUKE_PATH parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.34% | 8 June 2007 |
| CVE-2007-3134 | Multiple cross-site scripting (XSS) vulnerabilities in atomPhotoBlog.php in Atom PhotoBlog 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Your Name, (2) Your Homepage, and (3) Your Comment fields, when using… | EXPLOIT ✓MEDIUM 4.3EPSS 1.53% | 8 June 2007 |
| CVE-2007-3133 | SQL injection vulnerability in urunbak.asp in W1L3D4 WEBmarket 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.64% | 8 June 2007 |
| CVE-2007-3130 | Multiple PHP remote file inclusion vulnerabilities in the OpenWiki (formerly JD-Wiki) component (com_jd-wiki) 1.0.2, and possibly earlier, for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 4.46% | 8 June 2007 |
| CVE-2007-3119 | SQL injection vulnerability in news.asp in Kartli Alisveris Sistemi (aka Free-PayPal-Shopping-Cart) 1.0 allows remote attackers to execute arbitrary SQL commands via the news_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 7 June 2007 |
| CVE-2007-3118 | Multiple PHP remote file inclusion vulnerabilities in Kravchuk letter (K-letter) 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the scdir parameter to (1) action.php, (2) subs.php, or (3) unsubs.php. | EXPLOIT ✓HIGH 7.5EPSS 3.39% | 7 June 2007 |
| CVE-2007-3111 | Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used on Windows 2000 SP4, allows remote attackers to execute arbitrary code via a long URL property value. | EXPLOIT ✓HIGH 10.0EPSS 44.4% | 7 June 2007 |
| CVE-2007-3098 | The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a denial of service (crash) via a crafted packet to port 165/TCP. | EXPLOIT ✓MEDIUM 5.0EPSS 3.57% | 6 June 2007 |
| CVE-2007-3096 | Directory traversal vulnerability in login.php in PBLang (PBL) 4.67.16.a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 2.50% | 6 June 2007 |
| CVE-2007-2919 | Multiple stack-based buffer overflows in the FViewerLoading ActiveX control (FlipViewerX.dll) in E-Book Systems FlipViewer before 4.1 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via long (1) UID, (2) Opf, (3)… | EXPLOIT ✓HIGH 9.3EPSS 33.7% | 6 June 2007 |
| CVE-2007-2864 | Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file. | EXPLOIT ✓HIGH 9.3EPSS 49.6% | 6 June 2007 |
| CVE-2007-2237 | Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error. | EXPLOIT ×2 ✓MEDIUM 5.5EPSS 15.4% | 6 June 2007 |
| CVE-2007-3088 | SQL injection vulnerability in index.php in Comicsense allows remote attackers to execute arbitrary SQL commands via the epi parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.17% | 6 June 2007 |
| CVE-2007-3086 | Unrestricted critical resource lock in Agnitum Outpost Firewall PRO 4.0 1007.591.145 and earlier allows local users to cause a denial of service (system hang) by capturing the outpost_ipc_hdr mutex. | EXPLOIT ✓MEDIUM 4.9EPSS 0.68% | 6 June 2007 |
| CVE-2007-3082 | Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.8EPSS 2.93% | 6 June 2007 |
| CVE-2007-3080 | SQL injection vulnerability in haberoku.asp in Hunkaray Okul Portaly 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 6 June 2007 |
| CVE-2007-3077 | SQL injection vulnerability in listmembers.php in EQdkp 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the rank parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 6 June 2007 |
| CVE-2007-3076 | A certain ActiveX control in sasatl.dll in Zenturi ProgramChecker allows remote attackers to download arbitrary files to the client system via the DownloadFile function. | EXPLOIT ✓HIGH 7.8EPSS 2.59% | 6 June 2007 |
| CVE-2007-3071 | Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSellerate SDK allows user-assisted remote attackers to execute arbitrary code via a long first argument. | EXPLOIT ×2 ✓HIGH 9.3EPSS 5.84% | 6 June 2007 |
| CVE-2007-3070 | Cross-site scripting (XSS) vulnerability in index.php in BDigital Web Solutions WebStudio allows remote attackers to inject arbitrary web script or HTML via the pageid parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.80% | 6 June 2007 |
| CVE-2007-3068 | Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF playlist containing a long filename. | EXPLOIT ×4 ✓MEDIUM 6.8EPSS 32.9% | 6 June 2007 |
| CVE-2007-3065 | SQL injection vulnerability in viewimage.php in Particle Soft Particle Gallery 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the editcomment parameter, a different version and vector than CVE-2006-2862. | EXPLOIT ✓HIGH 7.5EPSS 1.05% | 6 June 2007 |
| CVE-2007-3064 | Cross-site scripting (XSS) vulnerability in diary.php in My Databook allows remote attackers to inject arbitrary web script or HTML via the year parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.51% | 6 June 2007 |
| CVE-2007-3063 | SQL injection vulnerability in diary.php in My Databook allows remote attackers to execute arbitrary SQL commands via the delete parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 6 June 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.