Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,677 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 339 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-2675 | SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.76% | 14 May 2007 |
| CVE-2007-2674 | SQL injection vulnerability in detail.php in Pre Shopping Mall 1.0 allows remote attackers to execute arbitrary SQL commands via the prodid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.30% | 14 May 2007 |
| CVE-2007-2673 | SQL injection vulnerability in includes/funcs_vendors.php in Censura 1.15.04, and other versions before 1.16.04, allows remote attackers to execute arbitrary SQL commands via the vendorid parameter in a vendor_info cmd action to censura.php. | EXPLOIT ✓HIGH 7.5EPSS 2.38% | 14 May 2007 |
| CVE-2007-2672 | SQL injection vulnerability in index.php in PHP Coupon Script 3.0 allows remote attackers to execute arbitrary SQL commands via the bus parameter in a viewbus page. | EXPLOIT ✓HIGH 7.5EPSS 2.52% | 14 May 2007 |
| CVE-2007-2671 | Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in an HREF attribute in an A element, which triggers an out-of-bounds memory access. | EXPLOIT ✓HIGH 7.1EPSS 3.19% | 14 May 2007 |
| CVE-2007-2668 | Buffer overflow in webdesproxy 0.0.1 allows remote attackers to execute arbitrary code via a long URL, possibly involving the process_connection_request function in webdesproxy.c. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 4.08% | 14 May 2007 |
| CVE-2007-2667 | Buffer overflow in the DB Software Laboratory VImpX ActiveX control in VImpX.ocx 4.7.3 allows remote attackers to execute arbitrary code via a long LogFile parameter. | EXPLOIT ✓HIGH 9.3EPSS 6.00% | 14 May 2007 |
| CVE-2007-2666 | Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code via certain Ruby (.rb) files with long lines. | EXPLOIT ✓HIGH 7.6EPSS 15.5% | 14 May 2007 |
| CVE-2007-2665 | PHP remote file inclusion vulnerability in block.php in PhpFirstPost 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the Include parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.49% | 14 May 2007 |
| CVE-2007-2664 | PHP remote file inclusion vulnerability in includes/common.php in Yaap 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter, possibly related to the __autoload function. | EXPLOIT ✓HIGH 7.5EPSS 2.80% | 14 May 2007 |
| CVE-2007-2663 | PHP remote file inclusion vulnerability in language/1/splash.lang.php in Beacon 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the languagePath parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.79% | 14 May 2007 |
| CVE-2007-2662 | SQL injection vulnerability in EfesTECH Haber 5.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to the top-level URI. | EXPLOIT ✓HIGH 7.5EPSS 1.07% | 14 May 2007 |
| CVE-2007-2661 | SQL injection vulnerability in archshow.asp in BlogMe 3.0 allows remote attackers to execute arbitrary SQL commands via the var parameter, a different vector than CVE-2006-5976. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 14 May 2007 |
| CVE-2007-2660 | PHP remote file inclusion vulnerability in pcltrace.lib.php in the PclTar module in Vincent Blavet PhpConcept Library, as used in CJG EXPLORER PRO 3.3 and earlier and probably other products, allows remote attackers to execute arbitrary PHP code via a… | EXPLOIT ✓MEDIUM 6.8EPSS 3.47% | 14 May 2007 |
| CVE-2007-2659 | Directory traversal vulnerability in index.php in PHP Advanced Transfer Manager (phpATM) 1.30 allows remote attackers to read arbitrary files and obtain script source code via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 6.83% | 14 May 2007 |
| CVE-2007-2658 | Unspecified vulnerability in the ID Automation Linear Barcode 1.6.0.5 ActiveX control in IDAutomationLinear6.dll allows remote attackers to cause a denial of service via a long argument to the SaveEnhWMF method. | EXPLOIT ✓HIGH 7.8EPSS 4.34% | 14 May 2007 |
| CVE-2007-2657 | Unspecified vulnerability in the PrecisionID Barcode 1.3 ActiveX control in PrecisionID_DataMatrix.DLL allows remote attackers to cause a denial of service via a long argument to the SaveBarCode method. | EXPLOIT ✓HIGH 7.8EPSS 4.10% | 14 May 2007 |
| CVE-2007-2656 | Stack-based buffer overflow in the Hewlett-Packard (HP) Magview ActiveX control in hpqvwocx.dll 1.0.0.309 allows remote attackers to cause a denial of service (application crash) and possibly have other impact via a long argument to the DeleteProfile… | EXPLOIT ✓HIGH 7.8EPSS 4.43% | 14 May 2007 |
| CVE-2007-2648 | Stack-based buffer overflow in the Clever Database Comparer 2.2 ActiveX control (comparerax.ocx) allows remote attackers to execute arbitrary code via a long argument to the ConnectToDatabase function. | EXPLOIT ✓HIGH 9.3EPSS 6.98% | 14 May 2007 |
| CVE-2007-2647 | Static code injection vulnerability in admin/admin_configuration.php in Monalbum 0.8.7 allows remote authenticated users to inject arbitrary PHP code into the conf/config.inc.php file via the (1) gadm_pass, (2) gadm_user, (3) gcfgHote, (4) gcfgPass, (5)… | EXPLOIT ✓MEDIUM 6.5EPSS 2.69% | 14 May 2007 |
| CVE-2007-2645 | Integer overflow in the exif_data_load_data_entry function in exif-data.c in libexif before 0.6.14 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted EXIF data, involving the (1)… | EXPLOIT ✓HIGH 9.3EPSS 13.1% | 14 May 2007 |
| CVE-2007-2447 | The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled,… | EXPLOIT ✓MEDIUM 6.0EPSS 49.8% | 14 May 2007 |
| CVE-2007-2446 | Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX… | EXPLOIT ×4 ✓HIGH 10.0EPSS 77.7% | 14 May 2007 |
| CVE-2007-1903 | Cross-site scripting (XSS) vulnerability in search.php in SonicBB 1.0 allows remote attackers to inject arbitrary web script or HTML via the part parameter. | EXPLOIT ✓LOW 2.6EPSS 2.03% | 14 May 2007 |
| CVE-2007-1902 | Multiple SQL injection vulnerabilities in SonicBB 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) part and (2) by parameters to (a) search.php, or the (2) id parameter to (b) viewforum.php. | EXPLOIT ✓MEDIUM 6.8EPSS 1.61% | 14 May 2007 |
| CVE-2007-2644 | A certain ActiveX control in Morovia Barcode ActiveX Professional 3.3.1304 allows remote attackers to overwrite arbitrary files by calling the Save method with an arbitrary filename. | EXPLOIT ✓HIGH 9.4EPSS 4.65% | 13 May 2007 |
| CVE-2007-2643 | Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.74% | 13 May 2007 |
| CVE-2007-2642 | Directory traversal vulnerability in galeria.php in R2K Gallery 1.7 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 3.72% | 13 May 2007 |
| CVE-2007-2641 | SQL injection vulnerability in W1L3D4_bolum.asp in W1L3D4 Philboard 0.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter, a different vector than CVE-2007-0920. | EXPLOIT ✓HIGH 7.5EPSS 2.03% | 13 May 2007 |
| CVE-2007-2639 | Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside the TFTP root via unspecified vectors. | EXPLOIT ✓HIGH 10.0EPSS 3.62% | 13 May 2007 |
| CVE-2007-2634 | PHP remote file inclusion vulnerability in common/errormsg.php in aForum 1.32 and possibly earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the header parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.00% | 13 May 2007 |
| CVE-2007-2632 | Multiple cross-site scripting (XSS) vulnerabilities in PHP Multi User Randomizer (phpMUR) 2006.09.13 allow remote attackers to inject arbitrary web script or HTML via (1) the edit_plugin parameter to configure_plugin.tpl.php, or (2) certain array… | EXPLOIT ✓MEDIUM 6.8EPSS 3.99% | 13 May 2007 |
| CVE-2007-2628 | PHP remote file inclusion vulnerability in include/logout.php in Justin Koivisto SecurityAdmin for PHP (aka PHPSecurityAdmin, PSA) 4.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the PSA_PATH parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.61% | 11 May 2007 |
| CVE-2007-2623 | Multiple buffer overflows in RControl.dll in Remote Display Dev kit 1.2.1.0 allow remote attackers to cause a denial of service (Internet Explorer 7 crash) via (1) a long first argument to the connect function or (2) a long InternalServer property… | EXPLOIT ✓HIGH 7.8EPSS 4.34% | 11 May 2007 |
| CVE-2007-2622 | Multiple SQL injection vulnerabilities in TaskDriver 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to login.php or (2) the taskid parameter to notes.php. | EXPLOIT ✓HIGH 7.5EPSS 1.26% | 11 May 2007 |
| CVE-2007-2621 | SQL injection vulnerability in event_view.php in Thyme Calendar 1.3 allows remote attackers to execute arbitrary SQL commands via the eid parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.49% | 11 May 2007 |
| CVE-2007-2620 | PHP remote file inclusion vulnerability in inc/config.inc.php in Jakub Steiner (aka jimmac) original 0.11 allows remote attackers to execute arbitrary PHP code via a URL in the x[1] parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.28% | 11 May 2007 |
| CVE-2007-2617 | srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file permissions when opening files, which allows local users to read the first line of arbitrary files via the -d and -v options. | EXPLOIT ✓LOW 2.1EPSS 3.80% | 11 May 2007 |
| CVE-2007-2615 | Multiple PHP remote file inclusion vulnerabilities in Crie seu PHPLojaFacil 0.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the path_local parameter to (1) ftp.php, (2) libs/db.php, and (3) libs/ftp.php. | EXPLOIT ✓HIGH 7.5EPSS 3.40% | 11 May 2007 |
| CVE-2007-2611 | Multiple PHP remote file inclusion vulnerabilities in CGX 20050314 allow remote attackers to execute arbitrary PHP code via a URL in the pathCGX parameter to (1) mtdialogo.php, (2) ltdialogo.php, (3) login.php, and (4) logingecon.php in inc/; and… | EXPLOIT ✓MEDIUM 6.8EPSS 7.82% | 11 May 2007 |
| CVE-2007-2609 | Multiple PHP remote file inclusion vulnerabilities in gnuedu 1.3b2 allow remote attackers to execute arbitrary PHP code via a URL in the (a) ETCDIR parameter to (1) libs/lom.php; (2) lom_update.php, (3) check-lom.php, and (4) weigh_keywords.php in… | EXPLOIT ✓HIGH 7.5EPSS 9.68% | 11 May 2007 |
| CVE-2007-2608 | PHP remote file inclusion vulnerability in lib/smarty/SmartyFU.class.php in Miplex2 Alpha 1 allows remote attackers to execute arbitrary PHP code via a URL in the system[smarty][dir] parameter. | EXPLOIT ✓HIGH 7.5EPSS 8.18% | 11 May 2007 |
| CVE-2007-2607 | PHP remote file inclusion vulnerability in views/print/printbar.php in LaVague 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the views_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 70.6% | 11 May 2007 |
| CVE-2007-2600 | Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the… | EXPLOIT ✓MEDIUM 6.8EPSS 2.78% | 11 May 2007 |
| CVE-2007-2599 | Multiple SQL injection vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to… | EXPLOIT ✓HIGH 7.5EPSS 3.73% | 11 May 2007 |
| CVE-2007-2598 | SQL injection vulnerability in print.php in SimpleNews 1.0.0 FINAL allows remote attackers to execute arbitrary SQL commands via the news_id parameter. | EXPLOIT ✓HIGH 10.0EPSS 1.90% | 11 May 2007 |
| CVE-2007-2597 | Multiple PHP remote file inclusion vulnerabilities in telltarget CMS 1.3.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) ordnertiefe parameter to site_conf.php; or the (2) tt_docroot parameter to (a) class.csv.php, (b)… | EXPLOIT ✓HIGH 7.5EPSS 10.1% | 11 May 2007 |
| CVE-2007-2596 | PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CommonAbsDir parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.28% | 11 May 2007 |
| CVE-2007-2594 | PHP remote file inclusion vulnerability in inc/articles.inc.php in phpMyPortal 3.0.0 RC3 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[CHEMINMODULES] parameter. | EXPLOIT ✓HIGH 7.5EPSS 7.79% | 11 May 2007 |
| CVE-2007-2523 | CA Anti-Virus for the Enterprise r8 and Threat Manager r8 before 20070510 use weak permissions (NULL security descriptor) for the Task Service shared file mapping, which allows local users to modify this mapping and gain privileges by triggering a… | EXPLOIT ✓HIGH 7.2EPSS 1.38% | 11 May 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.