Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,636 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 336 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-3061 | Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) cactushop6.mdb or (2) cactushop5.mdb. | EXPLOIT ✓HIGH 7.8EPSS 2.58% | 6 June 2007 |
| CVE-2007-3060 | Multiple cross-site scripting (XSS) vulnerabilities in PHP Live! | EXPLOIT ×5 ✓MEDIUM 4.3EPSS 4.96% | 6 June 2007 |
| CVE-2007-3057 | PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 68.7% | 6 June 2007 |
| CVE-2007-3055 | Cross-site scripting (XSS) vulnerability in index.php in Codelib Linker 2.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.83% | 6 June 2007 |
| CVE-2007-3052 | SQL injection vulnerability in index.php in the PNphpBB2 1.2i and earlier module for PostNuke allows remote attackers to execute arbitrary SQL commands via the c parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.51% | 6 June 2007 |
| CVE-2007-3051 | SQL injection vulnerability in inc/class_users.php in RevokeSoft RevokeBB 1.0 RC4 and earlier allows remote attackers to execute arbitrary SQL commands via the revokebb_user cookie. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 6 June 2007 |
| CVE-2007-3049 | Cross-site scripting (XSS) vulnerability in index.php in Buttercup web file manager (BWFM) May 2007 allows remote attackers to inject arbitrary web script or HTML via the title parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.49% | 6 June 2007 |
| CVE-2007-3048 | GNU screen 4.0.3 allows local users to unlock the screen via a CTRL-C sequence at the password prompt. | EXPLOIT ✓HIGH 7.2EPSS 0.71% | 5 June 2007 |
| CVE-2007-3009 | Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string… | EXPLOIT ✓MEDIUM 4.3EPSS 2.23% | 4 June 2007 |
| CVE-2007-3006 | Buffer overflow in Acoustica MP3 CD Burner 4.32 allows user-assisted remote attackers to execute arbitrary code via a .asx playlist file with a REF element containing a long string in the HREF attribute. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 8.09% | 4 June 2007 |
| CVE-2007-3003 | Multiple SQL injection vulnerabilities in myBloggie 2.1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) year parameter to index.php in a viewuser action, different vectors than CVE-2005-1500 and… | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 4 June 2007 |
| CVE-2007-3001 | Multiple cross-site scripting (XSS) vulnerabilities in PHP JackKnife (PHPJK) allow remote attackers to inject arbitrary web script or HTML via (1) the sUName parameter to UserArea/Authenticate.php, (2) the sAccountUnq parameter to… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.90% | 4 June 2007 |
| CVE-2007-3000 | Multiple SQL injection vulnerabilities in PHP JackKnife (PHPJK) allow remote attackers to execute arbitrary SQL commands via (1) the iCategoryUnq parameter to G_Display.php or (2) the iSearchID parameter to Search/DisplayResults.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.24% | 4 June 2007 |
| CVE-2007-2872 | Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments. | EXPLOIT ✓MEDIUM 6.8EPSS 8.88% | 4 June 2007 |
| CVE-2007-2991 | Cross-site scripting (XSS) vulnerability in includes/send.inc.php in Evenzia CMS allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | EXPLOIT ✓MEDIUM 4.3EPSS 1.57% | 4 June 2007 |
| CVE-2007-2988 | A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a request to… | EXPLOIT ✓HIGH 7.5EPSS 7.70% | 1 June 2007 |
| CVE-2007-2987 | Multiple buffer overflows in certain ActiveX controls in sasatl.dll in Zenturi ProgramChecker allow remote attackers to execute arbitrary code via unspecified vectors, possibly involving the (1) DebugMsgLog or (2) DoFileProperties methods. | EXPLOIT ×3 ✓HIGH 9.3EPSS 32.7% | 1 June 2007 |
| CVE-2007-2986 | PHP remote file inclusion vulnerability in lib/live_status.lib.php in AdminBot MX 9.0.5 allows remote attackers to execute arbitrary PHP code via a URL in the ROOT parameter. | EXPLOIT ✓HIGH 7.5EPSS 64.4% | 1 June 2007 |
| CVE-2007-2985 | Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload… | EXPLOIT ✓HIGH 10.0EPSS 4.17% | 1 June 2007 |
| CVE-2007-2981 | Buffer overflow in a certain ActiveX control in LEAD Technologies LEADTOOLS Raster OCR Document Object Library (ltrdc14e.dll) 14.5.0.44 allows remote attackers to execute arbitrary code via a long DictionaryFileName property. | EXPLOIT ✓HIGH 9.3EPSS 6.42% | 1 June 2007 |
| CVE-2007-2980 | Heap-based buffer overflow in a certain ActiveX control in LEADTOOLS LEAD Raster ISIS Object (LTRIS14e.DLL) 14.5.0.44 allows remote attackers to cause a denial of service (Internet Explorer crash) or execute arbitrary code via a long DriverName… | EXPLOIT ✓MEDIUM 6.8EPSS 4.71% | 1 June 2007 |
| CVE-2007-2971 | SQL injection vulnerability in getnewsitem.php in gCards 1.46 and earlier allows remote attackers to execute arbitrary SQL commands via the newsid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.98% | 1 June 2007 |
| CVE-2007-2969 | PHP remote file inclusion vulnerability in newsletter.php in WAnewsletter 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the waroot parameter. | EXPLOIT ✓HIGH 7.5EPSS 61.7% | 1 June 2007 |
| CVE-2007-2918 | Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) StarClient.dll, (4) ComLink in (c) uicomlink.dll, and (5) WebCamXMP in (d) wcamxmp.dll in Logitech VideoCall allow… | EXPLOIT ✓MEDIUM 6.8EPSS 34.1% | 1 June 2007 |
| CVE-2007-1362 | Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to cause a denial of service via (1) a large cookie path parameter, which triggers memory consumption, or (2) an internal delimiter… | EXPLOIT ✓MEDIUM 4.3EPSS 7.83% | 1 June 2007 |
| CVE-2007-2964 | The fsmsh.dll host module in F-Secure Policy Manager Server 7.00 and earlier allows remote attackers to cause a denial of service (application crash) via NTFS reserved words in filenames in URLs. | EXPLOIT ✓MEDIUM 5.0EPSS 3.56% | 31 May 2007 |
| CVE-2007-2962 | Cross-site scripting (XSS) vulnerability in search.php in Particle Gallery 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the order parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.80% | 31 May 2007 |
| CVE-2007-2959 | SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id_manufacturer parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 31 May 2007 |
| CVE-2007-2947 | Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the root_prefix parameter to (1) index.php, (2) email_subscribe.php, (3) download.php, or (4) development.php. | EXPLOIT ✓HIGH 7.5EPSS 8.99% | 31 May 2007 |
| CVE-2007-2946 | Buffer overflow in a certain ActiveX control in LeadTools Raster Dialog File_D Object (LTRDFD14e.DLL) 14.5.0.44 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) or execute arbitrary code via a long DestinationPath… | EXPLOIT ✓HIGH 10.0EPSS 8.78% | 31 May 2007 |
| CVE-2007-2943 | PHP remote file inclusion vulnerability in class/class.php in Webavis 0.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.57% | 31 May 2007 |
| CVE-2007-2942 | SQL injection vulnerability in user.php in My Little Forum 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.51% | 31 May 2007 |
| CVE-2007-2941 | Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 for vBulletin allow remote attackers to execute arbitrary PHP code via a URL in the base parameter to (1)… | EXPLOIT ✓HIGH 7.5EPSS 7.01% | 31 May 2007 |
| CVE-2007-2940 | Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary PHP code via a URL in the pachtofile parameter to (1) skin/html/table.php or (2) login.php. | EXPLOIT ✓MEDIUM 6.8EPSS 6.53% | 31 May 2007 |
| CVE-2007-2939 | Multiple PHP remote file inclusion vulnerabilities in Mazen's PHP Chat 3.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the basepath parameter to (1) ITX.php, (2) IT_Error.php, or (3) IT.php in include/pear/. | EXPLOIT ✓MEDIUM 6.8EPSS 64.0% | 31 May 2007 |
| CVE-2007-2938 | Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6, when Internet Explorer 6 is used, allows remote attackers to execute arbitrary code via a long argument to the (1) Send485CMD method,… | EXPLOIT ✓HIGH 10.0EPSS 40.5% | 31 May 2007 |
| CVE-2007-2937 | PHP remote file inclusion vulnerability in admin/admin.php in TROforum 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_url parameter. | EXPLOIT ✓HIGH 7.5EPSS 64.4% | 31 May 2007 |
| CVE-2007-2936 | Multiple PHP remote file inclusion vulnerabilities in Frequency Clock 0.1b (Beta 0.1) allow remote attackers to execute arbitrary PHP code via a URL in the securelib parameter to (1) conf.php or (2) cp2.php. | EXPLOIT ✓HIGH 7.5EPSS 7.01% | 31 May 2007 |
| CVE-2007-2935 | core/spellcheck/spellcheck.php in Fundanemt before 2.2.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the dict parameter. | EXPLOIT ✓HIGH 7.5EPSS 9.57% | 31 May 2007 |
| CVE-2007-2934 | Directory traversal vulnerability in skins/common.css.php in Vistered Little 1.6a allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 2.81% | 31 May 2007 |
| CVE-2007-2933 | SQL injection vulnerability in index.php in the Phil-a-Form (com_philaform) 1.2.0.0 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the form_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.03% | 31 May 2007 |
| CVE-2007-2932 | Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web script or HTML via the blog parameter in a content search action. | EXPLOIT ✓MEDIUM 4.3EPSS 4.47% | 31 May 2007 |
| CVE-2007-0694 | Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1 allows remote attackers to inject arbitrary web script or HTML via the copyright parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.97% | 30 May 2007 |
| CVE-2007-0693 | SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.55% | 30 May 2007 |
| CVE-2007-2908 | Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin before 3.6.6 allows remote attackers to inject arbitrary web script or HTML via the title field in a single add action. | EXPLOIT ✓MEDIUM 4.3EPSS 1.77% | 30 May 2007 |
| CVE-2007-2903 | Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument. | EXPLOIT ✓MEDIUM 5.0EPSS 28.5% | 30 May 2007 |
| CVE-2007-2902 | SQL injection vulnerability in main/auth/my_progress.php in Dokeos 1.8.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the course parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.06% | 30 May 2007 |
| CVE-2007-2901 | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the img parameter to main/inc/lib/fckeditor/editor/plugins/ImageManager/editor.php and other unspecified… | EXPLOIT ✓MEDIUM 4.3EPSS 1.84% | 30 May 2007 |
| CVE-2007-2900 | Multiple PHP remote file inclusion vulnerabilities in Scallywag 2005-04-25 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to template.php in (1) skin/dark/, (2) skin/gold/, or (3) skin/original/. | EXPLOIT ✓MEDIUM 6.8EPSS 2.80% | 30 May 2007 |
| CVE-2007-2899 | Direct static code injection vulnerability in admin_config.php in NavBoard 2.6.0 allows remote attackers to inject arbitrary PHP code into data/config.php via multiple parameters, as demonstrated via the threadperpage parameter in an editconfig action. | EXPLOIT ✓HIGH 7.5EPSS 2.31% | 30 May 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.