Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,710 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 342 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-2353 | Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message. | EXPLOIT ✓MEDIUM 5.0EPSS 27.7% | 30 April 2007 |
| CVE-2007-2347 | PHP remote file inclusion vulnerability in main/forum/komentar.php in OneClick CMS (aka Sisplet CMS) 05.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.79% | 27 April 2007 |
| CVE-2007-2346 | Multiple PHP remote file inclusion vulnerabilities in PHP-Generics 1.0 beta allow remote attackers to execute arbitrary PHP code via a URL in the _APP_RELATIVE_PATH parameter to (1) include.php, (2) dbcommon/include.php, and (3) exception/include.php. | EXPLOIT ✓HIGH 7.5EPSS 3.14% | 27 April 2007 |
| CVE-2007-2345 | PHP remote file inclusion vulnerability in include/include_stream.inc.php in CodeWand phpBrowse allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 6.08% | 27 April 2007 |
| CVE-2007-2342 | SQL injection vulnerability in error.asp in CreaScripts CreaDirectory 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-6083. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 27 April 2007 |
| CVE-2007-2341 | PHP remote file inclusion vulnerability in suite/index.php in phpBandManager 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.67% | 27 April 2007 |
| CVE-2007-2340 | Multiple PHP remote file inclusion vulnerabilities in inc/include_all.inc.php in phporacleview allow remote attackers to execute arbitrary PHP code via a URL in the (1) page_dir or (2) inc_dir parameters. | EXPLOIT ✓MEDIUM 6.8EPSS 42.4% | 27 April 2007 |
| CVE-2007-2339 | Multiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified recipients parameter name in (a) pm.php; (2) the curr parameter to the (b) badwords (aka censorlist) or (c)… | EXPLOIT ×3 ✓HIGH 7.5EPSS 1.87% | 27 April 2007 |
| CVE-2007-2338 | Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unauthorized banlist deletions as an administrator via the delete parameter. | EXPLOIT ✓HIGH 7.5EPSS 8.67% | 27 April 2007 |
| CVE-2007-2337 | Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS 0.96.6 Alpha and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (b) magpie_simple.php in… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.82% | 27 April 2007 |
| CVE-2007-2330 | PHP remote file inclusion vulnerability in includes_handler.php in DynaTracker 151 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 3.28% | 27 April 2007 |
| CVE-2007-2327 | PHP remote file inclusion vulnerability in _editor.php in HTMLeditbox 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the settings[app_dir] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.61% | 27 April 2007 |
| CVE-2007-2326 | Multiple PHP remote file inclusion vulnerabilities in HYIP Manager Pro allow remote attackers to execute arbitrary PHP code via a URL in the plugin_file parameter to (1) Smarty.class.php and (2) Smarty_Compiler.class.php in inc/libs/; (3)… | EXPLOIT ✓HIGH 7.5EPSS 2.98% | 27 April 2007 |
| CVE-2007-2325 | PHP remote file inclusion vulnerability in include.php in MyNewsGroups :) allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter. | EXPLOIT ✓HIGH 10.0EPSS 3.38% | 27 April 2007 |
| CVE-2007-2324 | Directory traversal vulnerability in file.php in JulmaCMS 1.4 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 2.99% | 27 April 2007 |
| CVE-2007-2320 | SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL commands via the menuid parameter, a different vector than CVE-2005-4478. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 26 April 2007 |
| CVE-2007-2319 | PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to mod_as_category.php in (1) modules/mod_as_category/… | EXPLOIT ✓MEDIUM 6.8EPSS 2.30% | 26 April 2007 |
| CVE-2007-2317 | Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other products, allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to… | EXPLOIT ✓HIGH 7.5EPSS 8.03% | 26 April 2007 |
| CVE-2007-2313 | PHP remote file inclusion vulnerability in getinfo1.php in the Shotcast 1.0 RC2 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 6.08% | 26 April 2007 |
| CVE-2007-2312 | Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the n parameter to extra/online.php and other unspecified scripts in extra/. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 26 April 2007 |
| CVE-2007-2310 | Cross-site scripting (XSS) vulnerability in plugins/spaw/img_popup.php in BloofoxCMS 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the img_url parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.52% | 26 April 2007 |
| CVE-2007-2308 | Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0 allows remote attackers to inject arbitrary web script or HTML via the rok parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.52% | 26 April 2007 |
| CVE-2007-2307 | PHP remote file inclusion vulnerability in engine/engine.inc.php in WebKalk2 1.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.67% | 26 April 2007 |
| CVE-2007-2305 | Multiple SQL injection vulnerabilities in authenticate.php in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 26 April 2007 |
| CVE-2007-2304 | Multiple directory traversal vulnerabilities in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.69% | 26 April 2007 |
| CVE-2007-2303 | Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 2.02% | 26 April 2007 |
| CVE-2007-2302 | PHP remote file inclusion vulnerability in autoindex.php in Expow 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_file parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.34% | 26 April 2007 |
| CVE-2007-2301 | Multiple PHP remote file inclusion vulnerabilities in audioCMS arash 0.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the arashlib_dir parameter to (1) edit.inc.php and (2) list_features.inc.php in arash_lib/include, and (3)… | EXPLOIT ✓HIGH 7.5EPSS 6.08% | 26 April 2007 |
| CVE-2007-2300 | Multiple cross-site scripting (XSS) vulnerabilities in Endy Kristanto Surat kabar / News Management Online (aka phpwebnews) 0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the m_txt parameter to (1) iklan.php, (2)… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 1.90% | 26 April 2007 |
| CVE-2007-2299 | Multiple SQL injection vulnerabilities in Frogss CMS 0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) dzial parameter to (a) katalog.php, or the (2) t parameter to (b) forum.php or (c) forum/viewtopic.php, different… | EXPLOIT ✓HIGH 7.5EPSS 1.23% | 26 April 2007 |
| CVE-2007-2298 | Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertoire_config parameter to index.php in (1) cpe/, (2) direction/, or (3) professeurs/. | EXPLOIT ✓HIGH 7.5EPSS 2.42% | 26 April 2007 |
| CVE-2007-2293 | Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 allow remote attackers to execute arbitrary code via a long (1) T38FaxRateManagement or (2) T38FaxUdpEC SDP… | EXPLOIT ×2 ✓HIGH 7.6EPSS 23.9% | 26 April 2007 |
| CVE-2007-1683 | Stack-based buffer overflow in the DoWebMenuAction function in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.dll) allows remote attackers to execute arbitrary code via unspecified vectors. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 37.7% | 26 April 2007 |
| CVE-2007-2290 | Multiple PHP remote file inclusion vulnerabilities in B2 Weblog and News Publishing Tool 0.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the b2inc parameter to (1) b2archives.php, (2) b2categories.php, or (3) b2mail.php. | EXPLOIT ×3 ✓HIGH 7.5EPSS 3.38% | 26 April 2007 |
| CVE-2007-2288 | PHP remote file inclusion vulnerability in info.php in Doruk100.net doruk100net allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.30% | 26 April 2007 |
| CVE-2007-2287 | PHP remote file inclusion vulnerability in accept.php in comus 2.0 Final allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.30% | 26 April 2007 |
| CVE-2007-2285 | Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 11.8% | 26 April 2007 |
| CVE-2007-2284 | Buffer overflow in ABC-View Manager 1.42 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file. | EXPLOIT ✓HIGH 9.3EPSS 6.73% | 26 April 2007 |
| CVE-2007-2283 | Buffer overflow in Fresh View 7.15 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file. | EXPLOIT ✓HIGH 9.3EPSS 6.73% | 26 April 2007 |
| CVE-2007-2274 | The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and application crash) via a malformed torrent file. | EXPLOIT ✓HIGH 7.8EPSS 8.20% | 25 April 2007 |
| CVE-2007-2273 | PHP remote file inclusion vulnerability in include/loading.php in Alessandro Lulli wavewoo 0.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_include parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.30% | 25 April 2007 |
| CVE-2007-2272 | PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the workdir parameter. | EXPLOIT ✓HIGH 7.5EPSS 5.95% | 25 April 2007 |
| CVE-2007-2271 | Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 9.4EPSS 8.43% | 25 April 2007 |
| CVE-2007-2270 | The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) character in the From header, and possibly certain other locations, in a SIP INVITE request. | EXPLOIT ×2 ✓HIGH 7.8EPSS 9.36% | 25 April 2007 |
| CVE-2007-2268 | Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.51% | 25 April 2007 |
| CVE-2007-2139 | Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite… | EXPLOIT ✓HIGH 10.0EPSS 78.0% | 25 April 2007 |
| CVE-2007-2262 | Multiple PHP remote file inclusion vulnerabilities in html/php/detail.php in Sinato jmuffin allow remote attackers to execute arbitrary PHP code via a URL in the (1) relPath and (2) folder parameters. | EXPLOIT ✓HIGH 7.5EPSS 3.31% | 25 April 2007 |
| CVE-2007-2259 | SQL injection vulnerability in forum.php in EsForum 3.0 allows remote attackers to execute arbitrary SQL commands via the idsalon parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 25 April 2007 |
| CVE-2007-2258 | PHP remote file inclusion vulnerability in includes/init.inc.php in PHPMyBibli allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 25 April 2007 |
| CVE-2007-2257 | PHP remote file inclusion vulnerability in subscp.php in Fully Modded phpBB2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.73% | 25 April 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.