Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,677 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 341 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-1861 | The nl_fib_lookup function in net/ipv4/fib_frontend.c in Linux Kernel before 2.6.20.8 allows attackers to cause a denial of service (kernel panic) via NETLINK_FIB_LOOKUP replies, which trigger infinite recursion and a stack overflow. | EXPLOIT ✓MEDIUM 4.9EPSS 1.02% | 7 May 2007 |
| CVE-2007-2507 | Directory traversal vulnerability in includes/download.php in Treble Designs 1024 CMS 0.7 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 3.48% | 4 May 2007 |
| CVE-2007-2506 | WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attackers to cause a denial of service (infinite loop and daemon hang) via a messenger URL that invokes _edit.r with no additional… | EXPLOIT ✓HIGH 7.8EPSS 3.97% | 4 May 2007 |
| CVE-2007-2503 | Directory traversal vulnerability in turbulence.php in PHP Turbulence 0.0.1 alpha allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 10.0EPSS 3.62% | 4 May 2007 |
| CVE-2007-2498 | libmp4v2.dll in Winamp 5.02 through 5.34 allows user-assisted remote attackers to execute arbitrary code via a certain .MP4 file. | EXPLOIT ✓HIGH 9.3EPSS 10.2% | 4 May 2007 |
| CVE-2007-2497 | RealNetworks RealPlayer 10 Gold allows remote attackers to cause a denial of service (memory consumption) via a certain .ra file. | EXPLOIT ✓HIGH 7.8EPSS 7.09% | 4 May 2007 |
| CVE-2007-2496 | The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) GotoPage, (6) Save, (7)… | EXPLOIT ✓HIGH 7.8EPSS 3.83% | 4 May 2007 |
| CVE-2007-2495 | Multiple stack-based buffer overflows in the ExcelOCX ActiveX control in ExcelViewer.ocx 3.1.0.6 allow remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4)… | EXPLOIT ✓HIGH 7.5EPSS 3.96% | 4 May 2007 |
| CVE-2007-2494 | Multiple stack-based buffer overflows in the PowerPointOCX ActiveX control in PowerPointViewer.ocx 3.1.0.3 allow remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3)… | EXPLOIT ✓HIGH 10.0EPSS 5.19% | 4 May 2007 |
| CVE-2007-2493 | PHP remote file inclusion vulnerability in faq.php in the FAQ & RULES 2.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | EXPLOIT ✓HIGH 10.0EPSS 4.03% | 4 May 2007 |
| CVE-2007-2492 | SQL injection vulnerability in index.php in the v4bJournal module for PostNuke allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a journal_comment action. | EXPLOIT ✓HIGH 7.5EPSS 1.23% | 4 May 2007 |
| CVE-2007-2487 | Stack-based buffer overflow in AtomixMP3 allows remote attackers to execute arbitrary code via a long filename in an MP3 file, a different vector than CVE-2006-6287. | EXPLOIT ✓HIGH 7.5EPSS 5.39% | 3 May 2007 |
| CVE-2007-2486 | Directory traversal vulnerability in download.asp in Motobit 1.3 and 1.5 (aka PStruh-CZ) allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 6.64% | 3 May 2007 |
| CVE-2007-2485 | PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter. | EXPLOIT ✓HIGH 7.5EPSS 54.9% | 3 May 2007 |
| CVE-2007-2484 | PHP remote file inclusion vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 45.4% | 3 May 2007 |
| CVE-2007-2483 | Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the wpPATH parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 6.50% | 3 May 2007 |
| CVE-2007-2482 | Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 8.60% | 3 May 2007 |
| CVE-2007-2481 | PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 40.1% | 3 May 2007 |
| CVE-2007-2474 | Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) include/payment/payflow_pro.php, (2) global.php, or (3)… | EXPLOIT ✓HIGH 7.5EPSS 6.16% | 2 May 2007 |
| CVE-2007-2473 | SQL injection vulnerability in stylesheet.php in CMS Made Simple 1.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the templateid parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.69% | 2 May 2007 |
| CVE-2007-2471 | Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrary files via a full pathname in the form parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.78% | 2 May 2007 |
| CVE-2007-2458 | Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter to psg.smarty.lib.php and certain include and library scripts, a… | EXPLOIT ✓HIGH 7.5EPSS 10.1% | 2 May 2007 |
| CVE-2007-2457 | PHP remote file inclusion vulnerability in resources/includes/class.Smarty.php in Pixaria Gallery before 1.4.3 allows remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter. | EXPLOIT ✓HIGH 7.5EPSS 11.8% | 2 May 2007 |
| CVE-2007-2456 | Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root parameter to (1) localize.php or (2) config.php in modules/admin/include/. | EXPLOIT ✓HIGH 7.5EPSS 9.46% | 2 May 2007 |
| CVE-2007-2437 | The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to cause a denial of service (daemon crash) via crafted values to the (1) XRenderCompositeTrapezoids and (2)… | EXPLOIT ✓MEDIUM 5.5EPSS 4.40% | 2 May 2007 |
| CVE-2007-2434 | Buffer overflow in asnsp.dll in Aventail Connect 4.1.2.13 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a malformed DNS query. | EXPLOIT ✓HIGH 10.0EPSS 14.4% | 2 May 2007 |
| CVE-2007-2431 | Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote attackers to conduct cross-site scripting (XSS) and possibly other attacks by modifying critical variables such as $_SERVER, as… | EXPLOIT ✓MEDIUM 6.8EPSS 5.10% | 2 May 2007 |
| CVE-2007-2430 | shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by placing file contents and directory traversal manipulations into a SessionUserLang cookie to public/code/index.php. | EXPLOIT ✓HIGH 7.8EPSS 3.70% | 2 May 2007 |
| CVE-2007-2429 | ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for the mysql program, as demonstrated by the "-port 2345" and "-u root" arguments. | EXPLOIT ✓HIGH 10.0EPSS 8.02% | 2 May 2007 |
| CVE-2007-2428 | Multiple PHP remote file inclusion vulnerabilities in page.php in Ahhp-Portal allow remote attackers to execute arbitrary PHP code via a URL in the (1) fp or (2) sc parameter. | EXPLOIT ✓HIGH 7.5EPSS 9.44% | 2 May 2007 |
| CVE-2007-2427 | SQL injection vulnerability in index.php in the pnFlashGames 1.5 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.60% | 2 May 2007 |
| CVE-2007-2426 | PHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.4b4 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the myPath parameter. | EXPLOIT ✓HIGH 7.5EPSS 62.9% | 2 May 2007 |
| CVE-2007-2425 | Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 7.83% | 2 May 2007 |
| CVE-2007-2424 | PHP remote file inclusion vulnerability in help/index.php in The Merchant (themerchant) 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the show parameter. | EXPLOIT ✓HIGH 7.5EPSS 9.86% | 2 May 2007 |
| CVE-2007-2423 | Cross-site scripting (XSS) vulnerability in index.php in MoinMoin 1.5.7 allows remote attackers to inject arbitrary web script or HTML via the do parameter in an AttachFile action, a different vulnerability than CVE-2007-0857. | EXPLOIT ✓MEDIUM 5.8EPSS 3.55% | 2 May 2007 |
| CVE-2007-2420 | SQL injection vulnerability in bry.asp in Burak Yilmaz Blog 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.13% | 2 May 2007 |
| CVE-2007-2416 | SQL injection vulnerability in home.php in E-Annu allows remote attackers to execute arbitrary SQL commands via the a parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.18% | 1 May 2007 |
| CVE-2007-2373 | SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.66% | 30 April 2007 |
| CVE-2007-2372 | admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject,… | EXPLOIT ✓HIGH 10.0EPSS 8.20% | 30 April 2007 |
| CVE-2007-2371 | admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows remote attackers to cause a denial of service (loss of configuration data), and possibly perform direct… | EXPLOIT ✓HIGH 10.0EPSS 8.04% | 30 April 2007 |
| CVE-2007-2370 | SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a jobsview action. | EXPLOIT ✓HIGH 7.5EPSS 2.88% | 30 April 2007 |
| CVE-2007-2369 | Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 8.43% | 30 April 2007 |
| CVE-2007-2368 | picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.29% | 30 April 2007 |
| CVE-2007-2367 | Buffer overflow in wserve_console.exe in Wserve HTTP Server (whttp) 4.6 allows remote attackers to cause a denial of service (forced application exit) via a long directory name in the URI. | EXPLOIT ✓HIGH 10.0EPSS 3.74% | 30 April 2007 |
| CVE-2007-2366 | Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file. | EXPLOIT ✓HIGH 7.4EPSS 33.9% | 30 April 2007 |
| CVE-2007-2365 | Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file. | EXPLOIT ✓HIGH 9.3EPSS 41.2% | 30 April 2007 |
| CVE-2007-2364 | Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) mysql.class.php or (2) postgres.class.php in lib/db/; or (3) authuser.php, (4)… | EXPLOIT ✓HIGH 7.5EPSS 8.53% | 30 April 2007 |
| CVE-2007-2363 | Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file. | EXPLOIT ×2 ✓HIGH 8.5EPSS 8.94% | 30 April 2007 |
| CVE-2007-2362 | Multiple buffer overflows in MyDNS 1.1.0 allow remote attackers to (1) cause a denial of service (daemon crash) and possibly execute arbitrary code via a certain update, which triggers a heap-based buffer overflow in update.c; and (2) cause a denial of… | EXPLOIT ✓HIGH 9.0EPSS 16.1% | 30 April 2007 |
| CVE-2007-2356 | Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attackers to execute arbitrary code via a crafted RAS file. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 15.7% | 30 April 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.