Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,677 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 340 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-2588 | Multiple buffer overflows in the Office Viewer OCX ActiveX control (oa.ocx) 3.2 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long argument to the (1) HttpDownloadFile, (2) Open, (3) OpenWebFile,… | EXPLOIT ✓HIGH 9.3EPSS 7.04% | 10 May 2007 |
| CVE-2007-2586 | The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that… | EXPLOIT ✓HIGH 9.3EPSS 14.4% | 10 May 2007 |
| CVE-2007-2585 | Stack-based buffer overflow in the Verify function in the BarCodeWiz ActiveX control 2.0 and 2.52 (BarcodeWiz.dll) allows remote attackers to execute arbitrary code via a long argument. | EXPLOIT ×2 ✓HIGH 9.3EPSS 6.54% | 10 May 2007 |
| CVE-2007-2584 | Buffer overflow in the IsOldAppInstalled function in the McSubMgr.McSubMgr Subscription Manager ActiveX control (MCSUBMGR.DLL) in McAfee SecurityCenter before 6.0.25 and 7.x before 7.2.147 allows remote attackers to execute arbitrary code via a crafted… | EXPLOIT ✓HIGH 10.0EPSS 9.74% | 10 May 2007 |
| CVE-2007-2583 | The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer… | EXPLOIT ✓MEDIUM 4.0EPSS 11.3% | 10 May 2007 |
| CVE-2007-1280 | Cross-site scripting (XSS) vulnerability in Adobe RoboHelp X5, 6, and Server 6 allows remote attackers to inject arbitrary web script or HTML via a URL after a # (hash) in the URL path, as demonstrated using en/frameset-7.html, and possibly other… | EXPLOIT ✓MEDIUM 4.3EPSS 5.59% | 10 May 2007 |
| CVE-2006-7196 | Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via… | EXPLOIT ✓MEDIUM 4.3EPSS 72.2% | 10 May 2007 |
| CVE-2007-2581 | Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in… | EXPLOIT ✓MEDIUM 4.3EPSS 36.2% | 9 May 2007 |
| CVE-2007-2580 | Unspecified vulnerability in Apple Safari allows local users to obtain sensitive information (saved keychain passwords) via the document.loginform.password.value JavaScript parameter loaded from an AppleScript script. | EXPLOIT ✓LOW 1.9EPSS 0.74% | 9 May 2007 |
| CVE-2007-2576 | Buffer overflow in the East Wind Software advdaudio.ocx 1.5.1.1 ActiveX control allows user-assisted remote attackers to execute arbitrary code via a long OpenDVD property value. | EXPLOIT ✓MEDIUM 6.8EPSS 4.87% | 9 May 2007 |
| CVE-2007-2575 | PHP remote file inclusion vulnerability in watermark.php in the vm (aka Jean-Francois Laflamme) watermark 0.4.1 mod for Gallery allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.33% | 9 May 2007 |
| CVE-2007-2574 | Directory traversal vulnerability in index.php in Archangel Weblog 0.90.02 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.43% | 9 May 2007 |
| CVE-2007-2573 | PHP remote file inclusion vulnerability in plugin/HP_DEV/cms2.php in PHPtree 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_dir parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.79% | 9 May 2007 |
| CVE-2007-2572 | PHP remote file inclusion vulnerability in modules/noevents/templates/mfa_theme.php in NoAh (aka PHP Content Architect, phparch) 0.9 pre 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tpls[1] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.42% | 9 May 2007 |
| CVE-2007-2571 | SQL injection vulnerability in index.php in the wfquotes 1.0 0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 9 May 2007 |
| CVE-2007-2570 | PHP remote file inclusion vulnerability in handlers/page/show.php in Wikivi5 allows remote attackers to execute arbitrary PHP code via a URL in the sous_rep parameter. | EXPLOIT ✓HIGH 7.5EPSS 8.16% | 9 May 2007 |
| CVE-2007-2569 | Multiple PHP remote file inclusion vulnerabilities in Friendly 1.0d1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the friendly_path parameter to (1) core/data/yaml.inc.php, or _load.php in (2) core/data/, (3)… | EXPLOIT ✓HIGH 7.5EPSS 8.37% | 9 May 2007 |
| CVE-2007-2566 | The SaveBarCode function in the Taltech Tal Bar Code ActiveX control allows remote attackers to cause a denial of service (disk consumption) by uploading multiple bar codes, as demonstrated by a WSF package. | EXPLOIT ✓MEDIUM 5.0EPSS 2.73% | 9 May 2007 |
| CVE-2007-2565 | Cdelia Software ImageProcessing allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted BMP file. | EXPLOIT ✓HIGH 7.1EPSS 2.65% | 9 May 2007 |
| CVE-2007-2563 | Buffer overflow in the AddFile function in VersalSoft HTTP File Upload ActiveX control (UFileUploaderD.dll) allows remote attackers to execute arbitrary code via a long argument. | EXPLOIT ×2 ✓HIGH 9.3EPSS 7.22% | 9 May 2007 |
| CVE-2007-2561 | SQL injection vulnerability in index.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter, a different vector than CVE-2006-6115. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 9 May 2007 |
| CVE-2007-2560 | Directory traversal vulnerability in theme/acgv.php in ACGVannu 1.3 and earlier allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.73% | 9 May 2007 |
| CVE-2007-2556 | SQL injection vulnerability in Nuked-klaN 1.7.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For (X_FORWARDED_FOR) HTTP header, as demonstrated by a request to the /nk/ URI. | EXPLOIT ×2 ✓HIGH 7.5EPSS 3.45% | 9 May 2007 |
| CVE-2007-2553 | Unspecified vulnerability in dop in HP Tru64 UNIX 5.1B-4, 5.1B-3, and 5.1A PK6 allows local users to gain privileges via a large amount of data in the environment, as demonstrated by a long environment variable. | EXPLOIT ✓HIGH 7.2EPSS 0.94% | 9 May 2007 |
| CVE-2007-0609 | Directory traversal vulnerability in Advanced Guestbook 2.4.2 allows remote attackers to bypass .htaccess settings, and execute arbitrary PHP local files or read arbitrary local templates, via a .. | EXPLOIT ✓MEDIUM 5.1EPSS 7.51% | 9 May 2007 |
| CVE-2007-0605 | Cross-site scripting (XSS) vulnerability in picture.php in Advanced Guestbook 2.4.2 allows remote attackers to inject arbitrary web script or HTML via the picture parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.97% | 9 May 2007 |
| CVE-2007-2549 | SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) c or (2) quantity parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 9 May 2007 |
| CVE-2007-2547 | Cross-site scripting (XSS) vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to inject arbitrary web script or HTML via the l parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.57% | 9 May 2007 |
| CVE-2007-2545 | Multiple PHP remote file inclusion vulnerabilities in Persism CMS 0.9.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the system[path] parameter to (1) blocks/headerfile.php, (2) files/blocks/latest_files.php, (3)… | EXPLOIT ✓HIGH 7.5EPSS 68.8% | 9 May 2007 |
| CVE-2007-2544 | PHP remote file inclusion vulnerability in templates/default/tpl_message.php in PHP TopTree BBS 2.0.1a and earlier allows remote attackers to execute arbitrary PHP code via a URL in the right_file parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.16% | 9 May 2007 |
| CVE-2007-2543 | SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 9 May 2007 |
| CVE-2007-2542 | PHP remote file inclusion vulnerability in header.php in workbench survival guide 0.11 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.67% | 9 May 2007 |
| CVE-2007-2541 | PHP remote file inclusion vulnerability in includes/ajax_listado.php in Versado CMS 1.07 allows remote attackers to execute arbitrary PHP code via a URL in the urlModulo parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.16% | 9 May 2007 |
| CVE-2007-2540 | Multiple PHP remote file inclusion vulnerabilities in PMECMS 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the config[pathMod] parameter to index.php in (1) mod/image/, (2) mod/liens/, (3) mod/liste/, (4)… | EXPLOIT ✓HIGH 7.5EPSS 9.32% | 9 May 2007 |
| CVE-2007-2539 | The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadata) via unspecified vectors. | EXPLOIT ✓HIGH 7.8EPSS 7.91% | 9 May 2007 |
| CVE-2007-2538 | SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the executed_queries array parameter. | EXPLOIT ✓HIGH 7.5EPSS 4.83% | 9 May 2007 |
| CVE-2007-2537 | Multiple SQL injection vulnerabilities in mainfile.php in NPDS 5.10 and earlier allow remote authenticated users to execute arbitrary SQL commands via a (1) nickname or (2) Id in a cookie, or (3) the X-Forwarded-For (X_FORWARDED_FOR) HTTP header. | EXPLOIT ✓MEDIUM 6.5EPSS 1.05% | 9 May 2007 |
| CVE-2007-2536 | PicoZip allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. | EXPLOIT ✓HIGH 7.8EPSS 8.54% | 9 May 2007 |
| CVE-2007-2532 | Multiple cross-site scripting (XSS) vulnerabilities in Minh Nguyen Duong Obie Website Mini Web Shop 2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) to (1) sendmail.php or (2) order_form.php, different… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 3.72% | 9 May 2007 |
| CVE-2007-2531 | PHP remote file inclusion vulnerability in berylium-classes.php in Berylium2 2003-08-18 allows remote attackers to execute arbitrary PHP code via a URL in the beryliumroot parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.28% | 9 May 2007 |
| CVE-2007-2530 | Multiple PHP remote file inclusion vulnerabilities in Tropicalm Crowell Resource 4.5.2 allow remote attackers to execute arbitrary PHP code via a URL in the RESPATH parameter to (1) dosearch.php or (2) printfriendly.php. | EXPLOIT ✓HIGH 7.5EPSS 3.28% | 9 May 2007 |
| CVE-2007-1669 | zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows… | EXPLOIT ✓HIGH 7.8EPSS 12.2% | 9 May 2007 |
| CVE-2007-2527 | Multiple PHP remote file inclusion vulnerabilities in DynamicPAD before 1.03.31 allow remote attackers to execute arbitrary PHP code via a URL in the HomeDir parameter to (1) dp_logs.php or (2) index.php. | EXPLOIT ✓HIGH 7.5EPSS 3.64% | 8 May 2007 |
| CVE-2007-2526 | Heap-based buffer overflow in the ConnectAsyncEx function in VNC Viewer ActiveX control (scvncctrl.dll) in the SmartCode VNC Manager 3.6 allows remote attackers to execute arbitrary code via a long argument. | EXPLOIT ✓HIGH 9.3EPSS 6.98% | 8 May 2007 |
| CVE-2007-2524 | Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket Request System (OTRS) 2.0.x allows remote attackers to inject arbitrary web script or HTML via the Subaction parameter in an AgentTicketMailbox Action. | EXPLOIT ✓MEDIUM 4.3EPSS 4.54% | 8 May 2007 |
| CVE-2007-2508 | Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote attackers to execute arbitrary code via crafted data to (1) TCP port 5168, which triggers an overflow in the… | EXPLOIT ×3 ✓HIGH 10.0EPSS 77.2% | 8 May 2007 |
| CVE-2007-2221 | Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; or 7 on… | EXPLOIT ✓HIGH 9.3EPSS 34.9% | 8 May 2007 |
| CVE-2007-0213 | Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message. | EXPLOITHIGH 10.0EPSS 66.2% | 8 May 2007 |
| CVE-2007-2521 | PHP remote file inclusion vulnerability in common.php in E-GADS! before 2.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the locale parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.34% | 8 May 2007 |
| CVE-2007-2239 | Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControl.ocx in AXIS 2100, 2110, 2120, 2130 PTZ, 2420, 2420-IR, 2400, 2400+, 2401, 2401+, 2411, and Panorama PTZ allows… | EXPLOIT ✓HIGH 9.3EPSS 11.8% | 7 May 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.