SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,710 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026

25,049 results · page 343 of 501

CVESummaryPriorityPublished
CVE-2007-2256Cross-site scripting (XSS) vulnerability in you.php in TJSChat 0.95 allows remote attackers to inject arbitrary web script or HTML via the user parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.76%25 April 2007
CVE-2007-2252Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive information via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.76%25 April 2007
CVE-2007-2250admin.php in Phorum before 5.1.22 allows remote attackers to obtain the full path via the module[] parameter.EXPLOIT ✓MEDIUM 5.0EPSS 3.74%25 April 2007
CVE-2007-2249include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_ids POST parameter or (2) userdata array.EXPLOIT ✓MEDIUM 6.5EPSS 6.95%25 April 2007
CVE-2007-2248Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Phorum before 5.1.22 allow remote attackers to inject arbitrary web script or HTML via the (1) group_id parameter in the groups module or (2) the smiley_id parameter in the smileys…EXPLOIT ×2 ✓MEDIUM 4.3EPSS 2.31%25 April 2007
CVE-2007-2247SQL injection vulnerability in modules/news/article.php in phpMySpace Gold 8.10 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.16%25 April 2007
CVE-2007-2244Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DIB, or (3) RLE file.EXPLOIT ✓HIGH 9.3EPSS 31.7%25 April 2007
CVE-2007-2233cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (\r) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.EXPLOIT ✓MEDIUM 6.5EPSS 1.99%25 April 2007
CVE-2007-2232The CHECK command in Cosign 2.0.1 and earlier allows remote attackers to bypass authentication requirements via CR (\r) sequences in the cosign cookie parameter.EXPLOIT ✓HIGH 7.5EPSS 2.47%25 April 2007
CVE-2007-2212Multiple SQL injection vulnerabilities in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) month parameter.EXPLOIT ✓HIGH 7.5EPSS 0.91%24 April 2007
CVE-2007-2211SQL injection vulnerability in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a dayview action.EXPLOIT ✓HIGH 7.5EPSS 1.06%24 April 2007
CVE-2007-2210A certain ActiveX control in askPopStp.dll in Netsprint Ask IE Toolbar 1.1 allows remote attackers to cause a denial of service (Internet Explorer crash) via a long AddAllowed property value, related to "improper memory handling," possibly a buffer…EXPLOIT ✓HIGH 7.8EPSS 3.39%24 April 2007
CVE-2007-2209Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.20 and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted .CLP file.EXPLOIT ✓MEDIUM 6.8EPSS 11.6%24 April 2007
CVE-2007-2207SQL injection vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ripeformpost parameter.EXPLOIT ✓HIGH 7.5EPSS 1.69%24 April 2007
CVE-2007-2205PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643.EXPLOIT ✓HIGH 7.5EPSS 3.14%24 April 2007
CVE-2007-2204Multiple PHP remote file inclusion vulnerabilities in GPL PHP Board (GPB) unstable-2001.11.14-1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) db.mysql.inc.php or (2) gpb.inc.php in include/, or the (3)…EXPLOIT ✓HIGH 7.5EPSS 3.39%24 April 2007
CVE-2007-2202PHP remote file inclusion vulnerability in inc_ACVS/SOAP/Transport.php in Accueil et Conseil en Visites et Sejours Web Services (ACVSWS) PHP5 (ACVSWS_PHP5) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the CheminInclude parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.83%24 April 2007
CVE-2007-2201Multiple PHP remote file inclusion vulnerabilities in Post Revolution 6.6 and 7.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) common.php or (2) themes/default/preview_post_completo.php.EXPLOIT ✓HIGH 7.5EPSS 4.10%24 April 2007
CVE-2007-2200Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and possibly delete arbitrary files via a ..EXPLOIT ✓HIGH 10.0EPSS 10.5%24 April 2007
CVE-2007-2199PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla!EXPLOIT ×3 ✓MEDIUM 6.8EPSS 46.9%24 April 2007
CVE-2007-2195aMSN (aka Alvaro's Messenger) 0.96 and earlier allows remote attackers to cause a denial of service (application crash) by sending invalid data to TCP port 31337.EXPLOIT ✓MEDIUM 5.0EPSS 3.34%24 April 2007
CVE-2007-2194Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string.EXPLOIT ✓HIGH 10.0EPSS 18.9%24 April 2007
CVE-2007-2193Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build 195 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string.EXPLOIT ×2 ✓HIGH 9.3EPSS 36.6%24 April 2007
CVE-2007-2192Buffer overflow in Photofiltre Studio 8.1.1 allows user-assisted remote attackers to execute arbitrary code via a crafted .tif file.EXPLOIT ×2 ✓HIGH 9.3EPSS 7.19%24 April 2007
CVE-2007-2191Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other SIP protocol fields, which are stored in…EXPLOIT ✓MEDIUM 6.8EPSS 4.46%24 April 2007
CVE-2007-2189PHP remote file inclusion vulnerability in admin/admin_album_otf.php in the MX Smartor Full Album Pack (FAP) 2.0 RC1 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.EXPLOIT ✓MEDIUM 6.8EPSS 5.09%24 April 2007
CVE-2007-2187Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long DNS response.EXPLOIT ✓HIGH 10.0EPSS 6.82%24 April 2007
CVE-2007-2186Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.EXPLOIT ✓MEDIUM 5.0EPSS 7.56%24 April 2007
CVE-2007-2185Multiple PHP remote file inclusion vulnerabilities in Supasite 1.23b allow remote attackers to execute arbitrary PHP code via a URL in the supa[db_path] parameter to (1) common_functions.php, (2) admin_auth_cookies.php, (3) admin_mods.php, (4)…EXPLOIT ✓MEDIUM 6.8EPSS 7.03%24 April 2007
CVE-2007-2184Directory traversal vulnerability in imgsrv.php in jchit counter 1.0.0 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 2.77%24 April 2007
CVE-2007-2183SQL injection vulnerability in index.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9 allows remote attackers to execute arbitrary SQL commands via the ring parameter.EXPLOIT ✓HIGH 7.5EPSS 2.20%24 April 2007
CVE-2007-2182Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP files via a trailing %00 in a filename in the page parameter.EXPLOIT ✓MEDIUM 6.8EPSS 4.41%24 April 2007
CVE-2007-2181PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter, a different product and vector than CVE-2005-0748.EXPLOIT ✓MEDIUM 6.8EPSS 3.12%24 April 2007
CVE-2007-2180Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted WMV file.EXPLOIT ✓HIGH 7.1EPSS 3.39%24 April 2007
CVE-2007-2175Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbitrary code via parameters to the toQTPointer method in quicktime.util.QTHandleRef, which can be used to…EXPLOIT ×3 ✓HIGH 7.6EPSS 83.8%24 April 2007
CVE-2007-2169Static code injection vulnerability in add.php in Mozzers SubSystem 1.0 allows remote attackers to inject PHP code into subs.php via the (1) Sub-name or (2) Sub-url field.EXPLOIT ✓HIGH 7.5EPSS 5.95%22 April 2007
CVE-2007-2168Static code injection vulnerability in process.php in AimStats 3.2 and earlier allows remote attackers to inject PHP code into config.php via the databasehost parameter.EXPLOIT ✓HIGH 7.5EPSS 2.31%22 April 2007
CVE-2007-2167Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into config.php via the number parameter in an update action.EXPLOIT ✓HIGH 7.5EPSS 44.4%22 April 2007
CVE-2007-2166PHP remote file inclusion vulnerability in administration/user/lib/group.inc.php in OpenSurveyPilot (osp) 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfgPathToProjectAdmin parameter.EXPLOIT ✓MEDIUM 6.8EPSS 3.22%22 April 2007
CVE-2007-2158PHP remote file inclusion vulnerability in index.php in jGallery 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the G_JGALL[inc_path] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.44%19 April 2007
CVE-2007-2157Directory traversal vulnerability in upload/force_download.php in Zomplog 3.8 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓HIGH 7.8EPSS 3.51%19 April 2007
CVE-2007-2156Multiple PHP remote file inclusion vulnerabilities in Rezervi Generic 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) datumVonDatumBis.inc.php, (2) footer.inc.php, (3) header.inc.php, and (4)…EXPLOIT ✓HIGH 7.5EPSS 10.1%19 April 2007
CVE-2007-2155Directory traversal vulnerability in template.php in in phpFaber TopSites 3 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓HIGH 7.8EPSS 2.85%19 April 2007
CVE-2007-2154PHP remote file inclusion vulnerability in services/samples/inclusionService.php in Cabron Connector 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the CabronServiceFolder parameter.EXPLOIT ✓HIGH 7.5EPSS 2.79%19 April 2007
CVE-2007-2149Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier stores usernames and unencrypted passwords in (1) classes/vars.php and (2) classes/varstuff.php, and recommends 0666 or 0777 permissions for these files, which allows local users to gain…EXPLOIT ✓HIGH 10.0EPSS 3.09%19 April 2007
CVE-2007-2148Direct static code injection vulnerability in admin/save.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier allows remote authenticated administrators to inject PHP code into .html files via the html parameter, as demonstrated by head.html…EXPLOIT ✓MEDIUM 6.5EPSS 1.99%19 April 2007
CVE-2007-2147admin/options.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier does not check for administrative credentials, which allows remote attackers to read and modify the classes/vars.php and classes/varstuff.php configuration files via direct…EXPLOIT ✓HIGH 10.0EPSS 3.42%19 April 2007
CVE-2007-2146The imagecomments function in classes.php in MiniGal b13 allow remote attackers to inject arbitrary PHP code into a file in the thumbs/ directory via the (1) name or (2) email parameter.EXPLOIT ✓HIGH 7.5EPSS 1.98%19 April 2007
CVE-2007-2145The imagecomments function in classes.php in MiniGal b13 allows remote attackers to inject arbitrary PHP code into a file in the thumbs/ directory via the input parameter.EXPLOIT ✓HIGH 7.5EPSS 2.14%19 April 2007
CVE-2007-2144PHP remote file inclusion vulnerability in includes/CAltInstaller.php in the JoomlaPack (com_jpack) 1.0.4a2 RE component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.EXPLOIT ✓MEDIUM 6.8EPSS 4.84%19 April 2007

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.