Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,677 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 338 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-2776 | AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject a credential variable setting and obtain administrative access via… | EXPLOIT ✓HIGH 10.0EPSS 8.62% | 21 May 2007 |
| CVE-2007-2775 | AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request to admin/managesettings.php. | EXPLOIT ✓HIGH 10.0EPSS 4.55% | 21 May 2007 |
| CVE-2007-2774 | Multiple PHP remote file inclusion vulnerabilities in SunLight CMS 5.3 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) _connect.php or (2) modules/startup.php. | EXPLOIT ✓HIGH 7.5EPSS 3.74% | 21 May 2007 |
| CVE-2007-2773 | SQL injection vulnerability in plugins/mp3playlist/mp3playlist.php in Zomplog 3.8 and earlier allows remote attackers to execute arbitrary SQL commands via the speler parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.21% | 21 May 2007 |
| CVE-2007-2772 | (1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 allow remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted RPC packet. | EXPLOIT ×2 ✓HIGH 7.8EPSS 12.1% | 21 May 2007 |
| CVE-2007-2771 | Stack-based buffer overflow in the LEAD Technologies LeadTools JPEG 2000 LEADJ2K.LEADJ2K.140 ActiveX control (LTJ2K14.ocx) 14.5.0.35 allows remote attackers to execute arbitrary code via a long BitmapDataPath property. | EXPLOIT ✓HIGH 9.3EPSS 9.04% | 21 May 2007 |
| CVE-2007-2770 | Stack-based buffer overflow in Eudora 7.1 allows user-assisted, remote SMTP servers to execute arbitrary code via a long SMTP reply. | EXPLOIT ✓HIGH 9.3EPSS 2.92% | 21 May 2007 |
| CVE-2007-2685 | Multiple SQL injection vulnerabilities in index.php in Jetbox CMS 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2) login parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.18% | 21 May 2007 |
| CVE-2007-1355 | Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers… | EXPLOIT ✓MEDIUM 4.3EPSS 58.2% | 21 May 2007 |
| CVE-2007-2763 | Buffer overflow in the UnlockSupport function in the LockModules subsystem in a certain ActiveX control in ltmm15.dll in Sienzo Digital Music Mentor (DMM) 2.6.0.4 allows remote attackers to execute arbitrary code via a long string in the second… | EXPLOIT ✓HIGH 10.0EPSS 7.76% | 18 May 2007 |
| CVE-2007-2762 | Multiple PHP remote file inclusion vulnerabilities in Build it Fast (bif3) 0.4.1 allow remote attackers to execute arbitrary PHP code via a URL in (1) the pear_dir parameter to Base/Application.php, or the (2) sys_dir parameter to (a) Footer.php, (b)… | EXPLOIT ✓HIGH 7.5EPSS 9.65% | 18 May 2007 |
| CVE-2007-2761 | Stack-based buffer overflow in MagicISO 5.4 build 239 and earlier allows remote attackers to execute arbitrary code via a long filename in a .cue file. | EXPLOIT ×2 ✓HIGH 7.5EPSS 6.12% | 18 May 2007 |
| CVE-2007-2757 | Multiple cross-site scripting (XSS) vulnerabilities in Redoable 1.2 allow remote attackers to inject arbitrary web script or HTML via the s parameter to (1) wp-content/themes/redoable/searchloop.php or (2) wp-content/themes/redoable/header.php. | EXPLOIT ✓MEDIUM 6.8EPSS 5.15% | 18 May 2007 |
| CVE-2007-2755 | The PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll, when Internet Explorer 6 is used, allows remote attackers to overwrite arbitrary files via a full pathname to the SaveToFile function, a different vulnerability than CVE-2007-2744. | EXPLOIT ✓HIGH 10.0EPSS 4.36% | 17 May 2007 |
| CVE-2007-2753 | RunawaySoft Haber portal 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/xice.mdb. | EXPLOIT ✓MEDIUM 5.0EPSS 5.16% | 17 May 2007 |
| CVE-2007-2752 | SQL injection vulnerability in devami.asp in RunawaySoft Haber portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 1.17% | 17 May 2007 |
| CVE-2007-2751 | Multiple PHP remote file inclusion vulnerabilities in PHPGlossar 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the format_menue parameter to (1) admin/inc/change_action.php or (2) admin/inc/add.php. | EXPLOIT ✓HIGH 7.5EPSS 3.28% | 17 May 2007 |
| CVE-2007-2750 | SQL injection vulnerability in print.php in SimpNews 2.40.01 and earlier allows remote attackers to execute arbitrary SQL commands via the newsnr parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 17 May 2007 |
| CVE-2007-2749 | SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrary SQL commands via the questionref parameter in a display action. | EXPLOIT ✓MEDIUM 5.0EPSS 1.00% | 17 May 2007 |
| CVE-2007-2747 | Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.51% | 17 May 2007 |
| CVE-2007-2744 | Stack-based buffer overflow in the PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll allows remote attackers to cause a denial of service (Internet Explorer 6 crash), and possibly execute arbitrary code, via a long argument to the… | EXPLOIT ✓HIGH 7.5EPSS 5.48% | 17 May 2007 |
| CVE-2007-2743 | PHP remote file inclusion vulnerability in custom_vars.php in GlossWord 1.8.1 allows remote attackers to execute arbitrary PHP code via a URL in the sys[path_addon] parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.14% | 17 May 2007 |
| CVE-2007-2738 | SQL injection vulnerability in glossaire-p-f.php in the Glossaire 1.7 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the sid parameter in an ImprDef action. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 17 May 2007 |
| CVE-2007-2737 | SQL injection vulnerability in index.php in the MyConference 1.0 module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.93% | 17 May 2007 |
| CVE-2007-2736 | PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter. | EXPLOIT ✓HIGH 10.0EPSS 4.09% | 17 May 2007 |
| CVE-2007-2735 | SQL injection vulnerability in edit_day.php in the ResManager 1.2.1 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id_reserv parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 17 May 2007 |
| CVE-2007-2732 | Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML via the (1) path parameter to view/search/; or the (2) companyname, (3) country, (4) email, (5) firstname, (6) middlename,… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 4.08% | 16 May 2007 |
| CVE-2007-2726 | BitsCast 0.13.0 allows remote attackers to cause a denial of service (application crash) via an RSS 2.0 feed item with certain invalid strings in a pubDate element, as demonstrated by repeated "../A" or "A/../" patterns. | EXPLOIT ✓HIGH 7.8EPSS 3.06% | 16 May 2007 |
| CVE-2007-2725 | The DB Software Laboratory DeWizardX (DEWizardAX.ocx) ActiveX control allows remote attackers to overwrite arbitrary files via the SaveToFile function. | EXPLOIT ✓HIGH 7.5EPSS 2.43% | 16 May 2007 |
| CVE-2007-2722 | Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instability) via certain invalid strings in the URL attribute of an ENCLOSURE element, as demonstrated by a "%s" sequence, a "%Y" sequence, a… | EXPLOIT ✓HIGH 7.8EPSS 3.20% | 16 May 2007 |
| CVE-2007-2568 | Multiple stack-based buffer overflows in VCDGear 3.55 allow user-assisted remote attackers to execute arbitrary code via a long (1) tag or (2) track type in a CUE file. | EXPLOIT ✓HIGH 9.3EPSS 6.22% | 16 May 2007 |
| CVE-2007-1898 | formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and subject parameters. | EXPLOIT ✓MEDIUM 5.8EPSS 2.54% | 16 May 2007 |
| CVE-2007-1689 | Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows remote attackers to execute arbitrary code via long arguments to the (1) Get and (2) Set functions. | EXPLOIT ✓HIGH 10.0EPSS 65.0% | 16 May 2007 |
| CVE-2007-2718 | Cross-site scripting (XSS) vulnerability in the WebMail system in Stalker CommuniGate Pro 5.1.8 and earlier, when using Microsoft Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via crafted STYLE tags. | EXPLOIT ✓MEDIUM 4.3EPSS 16.3% | 16 May 2007 |
| CVE-2007-2717 | SQL injection vulnerability in shop/page.php in iGeneric (iG) Shop 1.4 allows remote attackers to execute arbitrary SQL commands via the type_id[] parameter, a different vector than CVE-2005-0537. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 16 May 2007 |
| CVE-2007-2716 | Multiple cross-site scripting (XSS) vulnerabilities in EQdkp 1.3.2c and earlier allow remote attackers to inject arbitrary web script or HTML via the show parameter to (1) listmembers.php and (2) stats.php. | EXPLOIT ✓MEDIUM 6.8EPSS 4.16% | 16 May 2007 |
| CVE-2007-2441 | Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to obtain the system path via certain URLs associated with (1) deploying web applications or (2) displaying .xtp files. | EXPLOIT ✓MEDIUM 5.0EPSS 3.27% | 16 May 2007 |
| CVE-2007-2440 | Directory traversal vulnerability in Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to read certain files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.60% | 16 May 2007 |
| CVE-2007-2715 | Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password and password2 parameters in an edit action. | EXPLOIT ✓HIGH 10.0EPSS 10.4% | 16 May 2007 |
| CVE-2007-2714 | Unspecified vulnerability in akismet.php in Matt Mullenweg Akismet before 2.0.2, a WordPress plugin, has unknown impact and attack vectors. | EXPLOIT ✓HIGH 10.0EPSS 11.4% | 16 May 2007 |
| CVE-2007-2711 | Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long string to TCP port 113. | EXPLOIT ×2 ✓HIGH 10.0EPSS 63.3% | 16 May 2007 |
| CVE-2007-2710 | PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2.00-P00 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SETS[path][IT] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.27% | 16 May 2007 |
| CVE-2007-2709 | PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to execute arbitrary PHP code via a URL in the SETS[path][physical] parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.16% | 16 May 2007 |
| CVE-2007-2708 | PHP remote file inclusion vulnerability in newsadmin.php in Feindt Computerservice News (News-Script) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the action parameter. | EXPLOIT ✓HIGH 7.5EPSS 62.6% | 16 May 2007 |
| CVE-2007-2707 | PHP remote file inclusion vulnerability in linksnet_linkslog_rss.php in Linksnet Newsfeed 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dirpath_linksnet_newsfeed parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 68.1% | 16 May 2007 |
| CVE-2007-2706 | PHP remote file inclusion vulnerability in maint/ftpmedia.php in Media Gallery 1.4.8a and earlier for Geeklog allows remote attackers to execute arbitrary PHP code via a URL in the _MG_CONF[path_html] parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.28% | 16 May 2007 |
| CVE-2007-2683 | Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code via "&" characters in the GECOS field, which triggers the overflow during alias expansion. | EXPLOIT ✓LOW 3.5EPSS 0.80% | 15 May 2007 |
| CVE-2007-2678 | Buffer overflow in the isChecked function in toolbar.dll in Netsprint Toolbar 1.1 might allow remote attackers to execute arbitrary code via unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 3.60% | 15 May 2007 |
| CVE-2007-2677 | Multiple PHP remote file inclusion vulnerabilities in phpChess Community Edition 2.0 allow remote attackers to execute arbitrary PHP code via a URL in (1) the config parameter to includes/language.php, or the Root_Path parameter to (2)… | EXPLOIT ✓HIGH 7.5EPSS 9.52% | 14 May 2007 |
| CVE-2007-2676 | PHP remote file inclusion vulnerability in skins/header.php in Open Translation Engine (OTE) 0.7.8 allows remote attackers to execute arbitrary PHP code via a URL in the ote_home parameter. | EXPLOIT ✓HIGH 7.5EPSS 70.6% | 14 May 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.