Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,677 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 337 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-2895 | Buffer overflow in a certain ActiveX control in LTRDF14e.DLL 14.5.0.44 in LeadTools Raster Dialog File Object allows remote attackers to execute arbitrary code via a long Directory property value. | EXPLOIT ✓HIGH 7.5EPSS 5.41% | 30 May 2007 |
| CVE-2007-2894 | The emulated floppy disk controller in Bochs 2.3 allows local users of the guest operating system to cause a denial of service (virtual machine crash) via unspecified vectors, resulting in a divide-by-zero error. | EXPLOIT ✓LOW 2.1EPSS 0.73% | 30 May 2007 |
| CVE-2007-2892 | Cross-site scripting (XSS) vulnerability in news.asp in ASP-Nuke 2.0.7 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.49% | 30 May 2007 |
| CVE-2007-2891 | Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_data[root] parameter to modules/bank/includes/design/main.inc.php, or the (2) fm_data[root] parameter to… | EXPLOIT ✓HIGH 7.5EPSS 8.03% | 30 May 2007 |
| CVE-2007-2890 | SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id_category parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 30 May 2007 |
| CVE-2007-2889 | SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the scormcontopen parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.16% | 30 May 2007 |
| CVE-2007-2888 | Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrary code via a long FILE string (filename) in a .cue file, a related issue to CVE-2007-2761. | EXPLOIT ×4 ✓HIGH 7.6EPSS 54.7% | 30 May 2007 |
| CVE-2007-2887 | Cross-site scripting (XSS) vulnerability in index.php in Web Icerik Yonetim Sistemi (WIYS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the No parameter in the Sayfa page. | EXPLOIT ✓MEDIUM 4.3EPSS 1.76% | 30 May 2007 |
| CVE-2007-2884 | Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption) or execute arbitrary code via a Visual Basic Project (vbp) file with a long (1) Description or (2)… | EXPLOIT ×2 ✓HIGH 9.3EPSS 36.2% | 30 May 2007 |
| CVE-2007-2879 | Cross-site scripting (XSS) vulnerability in mods.php in GTP GNUTurk Portal System 3G allows remote attackers to inject arbitrary web script or HTML via the month parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.53% | 29 May 2007 |
| CVE-2007-2878 | The VFAT compat ioctls in the Linux kernel before 2.6.21.2, when run on a 64-bit system, allow local users to corrupt a kernel_dirent struct and cause a denial of service (system crash) via unknown vectors. | EXPLOIT ✓MEDIUM 4.9EPSS 0.88% | 29 May 2007 |
| CVE-2007-2865 | Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server parameter. | EXPLOIT ✓HIGH 9.3EPSS 6.07% | 25 May 2007 |
| CVE-2007-2386 | Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet. | EXPLOIT ✓HIGH 9.4EPSS 50.0% | 24 May 2007 |
| CVE-2007-0753 | Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter. | EXPLOIT ×2 ✓HIGH 7.2EPSS 0.93% | 24 May 2007 |
| CVE-2007-0752 | The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check. | EXPLOIT ✓HIGH 7.2EPSS 0.72% | 24 May 2007 |
| CVE-2007-2857 | PHP remote file inclusion vulnerability in sample/xls2mysql in ABC Excel Parser Pro 4.0 allows remote attackers to execute arbitrary PHP code via a URL in the parser_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.07% | 24 May 2007 |
| CVE-2007-2856 | Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used, allows user-assisted remote attackers to execute arbitrary code via a long first argument to the QuickZip… | EXPLOIT ×2 ✓HIGH 9.3EPSS 7.17% | 24 May 2007 |
| CVE-2007-2854 | Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) style or (2) langue parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 24 May 2007 |
| CVE-2007-2853 | The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitrary commands via a command line in the first argument to the VCDLaunchAndWait function. | EXPLOIT ✓HIGH 10.0EPSS 4.72% | 24 May 2007 |
| CVE-2007-2851 | A certain ActiveX control in LeadTools Raster Variant Object Library (LTRVR14e.dll) 14.5.0.44 allows remote attackers to overwrite arbitrary files via the WriteDataToFile method. | EXPLOIT ✓HIGH 7.5EPSS 2.41% | 24 May 2007 |
| CVE-2007-2843 | Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demonstrated by a js script that accesses the location information of cross-domain web pages, probably… | EXPLOIT ✓HIGH 10.0EPSS 3.49% | 24 May 2007 |
| CVE-2007-0448 | The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files via a file path specified with an invalid URI, as demonstrated via the… | EXPLOIT ✓HIGH 10.0EPSS 7.11% | 24 May 2007 |
| CVE-2007-2832 | Cross-site scripting (XSS) vulnerability in the web application firewall in Cisco CallManager before 3.3(5)sr3, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allows remote attackers to inject arbitrary web script or HTML via the… | EXPLOIT ✓MEDIUM 4.3EPSS 6.49% | 24 May 2007 |
| CVE-2007-2827 | Heap-based buffer overflow in LEAD Technologies LEADTOOLS ISIS ActiveX Control (ltisi14E.ocx) 14.5.0.44 and earlier allows remote attackers to execute arbitrary code via a long DriverName property. | EXPLOIT ✓HIGH 9.3EPSS 6.42% | 22 May 2007 |
| CVE-2007-2826 | PHP remote file inclusion vulnerability in lib/addressbook.php in Madirish Webmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[basedir] parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 3.26% | 22 May 2007 |
| CVE-2007-2824 | SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commands via the pack parameter in a paypal action for index.php. | EXPLOIT ✓HIGH 10.0EPSS 1.81% | 22 May 2007 |
| CVE-2007-2822 | TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the (1) loggedIn and (2) activated parameters to (a) login.php, (b) headerLinks.php, (c) submit1.php, (d) myFav.php, and (e) userCP.php. | EXPLOIT ✓HIGH 9.3EPSS 4.42% | 22 May 2007 |
| CVE-2007-2821 | SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitrary SQL commands via the cookie parameter. | EXPLOIT ✓HIGH 7.5EPSS 5.20% | 22 May 2007 |
| CVE-2007-2820 | Multiple stack-based buffer overflows in the KSign KSignSWAT ActiveX Control (AxKSignSWAT.dll) 2.0.3.3 allow remote attackers to execute arbitrary code via long arguments to the (1) SWAT_Init, (2) SWAT_InitEx, (3) SWAT_InitEx2, (4) SWAT_InitEx3, and (5)… | EXPLOIT ✓HIGH 7.5EPSS 5.80% | 22 May 2007 |
| CVE-2007-2817 | SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.05% | 22 May 2007 |
| CVE-2007-2816 | Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) test1.php, (2) blackorange.php, (3) default.php, (4) frames1.php, (5) frames1_top.php,… | EXPLOIT ×2 ✓HIGH 7.5EPSS 10.1% | 22 May 2007 |
| CVE-2007-2815 | The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access… | EXPLOIT ✓HIGH 10.0EPSS 73.4% | 22 May 2007 |
| CVE-2007-2814 | Multiple stack-based buffer overflows in the Pegasus ImagN' ActiveX control (IMW32O40.OCX) 4.00.041 allow remote attackers to execute arbitrary code via (1) a long FileName parameter, or unspecified vectors involving the (2) BeginReport, (3)… | EXPLOIT ✓HIGH 7.5EPSS 5.48% | 22 May 2007 |
| CVE-2007-2810 | SQL injection vulnerability in down_indir.asp in Gazi Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 10.0EPSS 1.54% | 22 May 2007 |
| CVE-2007-2807 | Stack-based buffer overflow in mod/server.mod/servrmsg.c in Eggdrop 1.6.18, and possibly earlier, allows user-assisted, remote IRC servers to execute arbitrary code via a long private message. | EXPLOIT ✓MEDIUM 6.8EPSS 9.98% | 22 May 2007 |
| CVE-2007-2806 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in GaliX 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) galix_cat_detail, (2) galix_gal_detail, and (3) galix_cat_detail_sort parameters. | EXPLOIT ✓MEDIUM 5.8EPSS 1.55% | 22 May 2007 |
| CVE-2007-2805 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in ClientExec (CE) 3.0 beta2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) ticketID, (2) view, and (3) fuse parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.49% | 22 May 2007 |
| CVE-2007-2803 | SQL injection vulnerability in default.asp in Vizayn Urun Tanitim Sitesi 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a haberdetay action. | EXPLOIT ✓HIGH 7.5EPSS 1.15% | 22 May 2007 |
| CVE-2007-2686 | Cross-site scripting (XSS) vulnerability in index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter in a sendpwd task. | EXPLOIT ✓MEDIUM 4.3EPSS 1.76% | 22 May 2007 |
| CVE-2007-2519 | Directory traversal vulnerability in the installer in PEAR 1.0 through 1.5.3 allows user-assisted remote attackers to overwrite arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 7.66% | 22 May 2007 |
| CVE-2007-2793 | PHP remote file inclusion vulnerability in ImageImageMagick.php in Geeklog 2.x allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_system] parameter. | EXPLOIT ✓HIGH 7.5EPSS 64.5% | 22 May 2007 |
| CVE-2007-2792 | SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter to index.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 3.76% | 22 May 2007 |
| CVE-2007-2791 | Unspecified vulnerability in the Secure Shell (SSH) in HP Tru64 UNIX 5.1B-4 and 5.1B-3 allows remote attackers to identify valid users via unspecified vectors, probably related to timing attacks and AuthInteractiveFailureRandomTimeout. | EXPLOIT ✓HIGH 10.0EPSS 6.46% | 22 May 2007 |
| CVE-2007-2788 | Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14… | EXPLOIT ✓MEDIUM 6.8EPSS 18.2% | 22 May 2007 |
| CVE-2007-2787 | Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in LeadTools Raster Thumbnail Object Library 14.5.0.44 allows remote attackers to execute arbitrary code via a long argument. | EXPLOIT ×2 ✓HIGH 7.5EPSS 7.50% | 21 May 2007 |
| CVE-2007-2783 | Unspecified vulnerability in Rational Soft Hidden Administrator 1.7 and earlier allows remote attackers to bypass authentication and execute arbitrary code via unspecified vectors. | EXPLOIT ✓HIGH 10.0EPSS 7.12% | 21 May 2007 |
| CVE-2007-2780 | PsychoStats 3.0.6b and earlier allows remote attackers to obtain sensitive information via a request for server.php with a missing or invalid newtheme parameter, which reveals a path in an error message. | EXPLOIT ✓MEDIUM 5.0EPSS 3.02% | 21 May 2007 |
| CVE-2007-2779 | PHP remote file inclusion vulnerability in template_csv.php in Libstats 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rInfo[content] parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.60% | 21 May 2007 |
| CVE-2007-2778 | Multiple directory traversal vulnerabilities in MolyX BOARD 2.5.0 allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 3.75% | 21 May 2007 |
| CVE-2007-2777 | Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under… | EXPLOIT ✓HIGH 7.5EPSS 6.32% | 21 May 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.