SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,710 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026

25,049 results · page 344 of 501

CVESummaryPriorityPublished
CVE-2007-2143PHP remote file inclusion vulnerability in index.php in the Be2004-2 template for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.44%19 April 2007
CVE-2007-2142Multiple PHP remote file inclusion vulnerabilities in AjPortal2Php allow remote attackers to execute arbitrary PHP code via a URL in the PagePrefix parameter to (1) begin.inc.php, (2) connection.inc.php, (3) events.inc.php, (4) footer.inc.php, (5)…EXPLOIT ✓HIGH 7.5EPSS 9.65%19 April 2007
CVE-2007-2141Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote attackers to inject arbitrary PHP code into shouts.php via the shout parameter.EXPLOIT ✓HIGH 7.5EPSS 45.8%19 April 2007
CVE-2007-1691Stack-based buffer overflow in Second Sight Software ActiveMod ActiveX control (ActiveMod.ocx) allows remote attackers to execute arbitrary code via unspecified vectors.EXPLOIT ✓MEDIUM 6.8EPSS 5.85%19 April 2007
CVE-2007-1690Multiple stack-based buffer overflows in Second Sight Software ActiveGS ActiveX control (ActiveGS.ocx) allow remote attackers to execute arbitrary code via unspecified vectors.EXPLOIT ✓MEDIUM 6.8EPSS 5.85%19 April 2007
CVE-2007-2098Multiple cross-site scripting (XSS) vulnerabilities in showpic.php in Wabbit PHP Gallery 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) pic and (2) gal parameters.EXPLOIT ✓MEDIUM 6.8EPSS 1.90%18 April 2007
CVE-2007-2094PHP remote file inclusion vulnerability in index.php in Anthologia 0.5.2 allows remote attackers to execute arbitrary PHP code via a URL in the ads_file parameter.EXPLOIT ✓HIGH 7.5EPSS 3.14%18 April 2007
CVE-2007-2093Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote attackers to inject arbitrary PHP code into posts.txt via the message parameter.EXPLOIT ✓HIGH 7.5EPSS 45.7%18 April 2007
CVE-2007-2092Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) allows remote attackers to inject arbitrary PHP code into posts.txt via the name parameter.EXPLOIT ✓HIGH 7.5EPSS 1.93%18 April 2007
CVE-2007-2091PHP remote file inclusion vulnerability in blocks/tsdisplay4xoops_block2.php in tsdisplay4xoops (TSD4XOOPS, aka the TeamSpeak display module) 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the xoops_url parameter.EXPLOIT ✓HIGH 7.5EPSS 2.66%18 April 2007
CVE-2007-2090Cross-site scripting (XSS) vulnerability in index.php in TuMusika Evolution 1.6 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.67%18 April 2007
CVE-2007-2089Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to com_articles.php in (1)…EXPLOIT ✓MEDIUM 6.8EPSS 5.63%18 April 2007
CVE-2007-2087Multiple PHP remote file inclusion vulnerabilities in CNStats 2.12, when register_globals is enabled and .htaccess is not recognized, allow remote attackers to execute arbitrary PHP code via a URL in the bn parameter to (1) who_r.php or (2) who_s.php in…EXPLOIT ✓MEDIUM 6.8EPSS 1.92%18 April 2007
CVE-2007-2086Multiple PHP remote file inclusion vulnerabilities in CNStats 2.9 allow remote attackers to execute arbitrary PHP code via a URL in the bj parameter to (1) who_r.php or (2) who_s.php in reports/.EXPLOIT ✓MEDIUM 6.8EPSS 2.34%18 April 2007
CVE-2006-7194PHP remote file inclusion vulnerability in modules/Mysqlfinder/MysqlfinderAdmin.php in Agora 1.4 RC1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the _SESSION[PATH_COMPOSANT] parameter.EXPLOIT ✓MEDIUM 6.8EPSS 5.11%18 April 2007
CVE-2007-2083vsdatant.sys in Check Point Zone Labs ZoneAlarm Pro before 7.0.302.000 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (system crash) or possibly execute…EXPLOIT ✓MEDIUM 6.9EPSS 0.77%18 April 2007
CVE-2007-2081MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication requirements via the admin cookie parameter to certain admin files, as demonstrated by admin/settings.php.EXPLOIT ✓HIGH 7.5EPSS 6.55%18 April 2007
CVE-2007-2080Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL commands via unspecified vectors in certain test scripts.EXPLOIT ✓HIGH 7.5EPSS 0.97%18 April 2007
CVE-2007-2079The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the database server hostname, which allows remote attackers to trigger a library buffer overflow and execute arbitrary code via a long…EXPLOIT ✓HIGH 9.3EPSS 9.69%18 April 2007
CVE-2007-2070Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2) checkout.php.EXPLOIT ✓HIGH 7.5EPSS 9.42%18 April 2007
CVE-2007-2069Directory traversal vulnerability in scr/soustab.php in openMairie 1.11 and earlier allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 7.24%18 April 2007
CVE-2007-2068Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter to (1) mods/business_functions.php or (2) mods/ui_functions.php.EXPLOIT ✓MEDIUM 6.8EPSS 3.24%18 April 2007
CVE-2007-2067Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) index.php, (2) modules/pdf.php, (3)…EXPLOIT ✓HIGH 7.5EPSS 8.37%18 April 2007
CVE-2007-2065PHP remote file inclusion vulnerability in db/PollDB.php in Robert Ladstaetter ActionPoll 1.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG_DATAREADERWRITER parameter, a different vector than CVE-2001-1297.EXPLOIT ✓HIGH 7.5EPSS 2.11%18 April 2007
CVE-2007-2064Multiple PHP remote file inclusion vulnerabilities in Robert Ladstaetter ActionPoll 1.1.0, and possibly 1.1.1, allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_POLLDB parameter to actionpoll.php or (2) the CONFIG_DB…EXPLOIT ×2 ✓HIGH 7.5EPSS 3.09%18 April 2007
CVE-2007-2062Stack-based buffer overflow in VCDGear 3.55 and 3.56 BETA allows user-assisted remote attackers to execute arbitrary code via a long FILE argument in a CUE file.EXPLOIT ✓HIGH 9.3EPSS 5.76%18 April 2007
CVE-2007-2061Cross-site scripting (XSS) vulnerability in check_login.asp in AfterLogic MailBee WebMail Pro 3.4 allows remote attackers to inject arbitrary web script or HTML via the username parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.99%18 April 2007
CVE-2007-2059Multiple buffer overflows in the ESA protocol implementation in eIQnetworks Enterprise Security Analyzer (ESA) 2.5 allow remote attackers to execute arbitrary code via a long parameter to the (1) DELETESEARCHFOLDER, (2) DELTASK, (3) HMGR_CHECKHOSTSCSV,…EXPLOIT ✓HIGH 10.0EPSS 7.29%18 April 2007
CVE-2007-2057Stack-based buffer overflow in aircrack-ng airodump-ng 0.7 allows remote attackers to execute arbitrary code via crafted 802.11 authentication packets.EXPLOIT ✓HIGH 10.0EPSS 19.4%18 April 2007
CVE-2007-1674Stack-based buffer overflow in the Alert Service (aolnsrvr.exe) in LANDesk Management Suite 8.7 allows remote attackers to execute arbitrary code via a crafted packet to port 65535/UDP.EXPLOIT ×2 ✓HIGH 10.0EPSS 72.9%18 April 2007
CVE-2007-2052Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown…EXPLOIT ✓MEDIUM 5.0EPSS 13.6%16 April 2007
CVE-2007-2050Multiple directory traversal vulnerabilities in header.php in RicarGBooK 1.2.1 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 3.44%16 April 2007
CVE-2007-2049Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (com_calendar) 1.5.5 for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) com_calendar.php or (2) mod_calendar.php.EXPLOIT ✓MEDIUM 6.8EPSS 2.32%16 April 2007
CVE-2007-2048Directory traversal vulnerability in /console in the Management Console in webMethods Glue 6.5.1 and earlier allows remote attackers to read arbitrary system files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 3.83%16 April 2007
CVE-2007-2044PHP remote file inclusion vulnerability in mod_weather.php in the Antonis Ventouris Weather module for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.44%16 April 2007
CVE-2007-2043Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier module for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter…EXPLOIT ✓HIGH 7.5EPSS 6.73%16 April 2007
CVE-2007-2031Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote attackers to execute arbitrary code via crafted transparent requests.EXPLOIT ×3 ✓HIGH 10.0EPSS 15.3%16 April 2007
CVE-2007-2027Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be…EXPLOIT ✓MEDIUM 4.4EPSS 0.84%13 April 2007
CVE-2007-1873Cross-site scripting (XSS) vulnerability in Mephisto 0.7.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter to the search script.EXPLOIT ✓MEDIUM 4.3EPSS 2.22%13 April 2007
CVE-2007-1872Cross-site scripting (XSS) vulnerability in toendaCMS 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search id.EXPLOIT ✓MEDIUM 4.3EPSS 1.97%13 April 2007
CVE-2007-1748Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name…EXPLOIT ×5 ✓HIGH 10.0EPSS 77.7%13 April 2007
CVE-2007-2019PHP remote file inclusion vulnerability in init.gallery.php in phpGalleryScript 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the include_class parameter.EXPLOIT ✓HIGH 7.5EPSS 3.17%12 April 2007
CVE-2007-2015PHP remote file inclusion vulnerability in index.php in Request It 1.0b allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.EXPLOIT ✓MEDIUM 6.8EPSS 3.16%12 April 2007
CVE-2007-2014PHP remote file inclusion vulnerability in include/blocks/week_events.php in MyNews 4.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter, a different vector than CVE-2007-0633.EXPLOIT ✓HIGH 7.5EPSS 2.27%12 April 2007
CVE-2007-2013Cross-site scripting (XSS) vulnerability in index.php in JEx-Treme Einfacher Passworschutz allows remote attackers to inject arbitrary web script or HTML via the msg parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.77%12 April 2007
CVE-2007-2011Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.87%12 April 2007
CVE-2007-2009PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.83%12 April 2007
CVE-2007-2008Directory traversal vulnerability in admin.php in pL-PHP beta 0.9 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.44%12 April 2007
CVE-2007-2007admin.php in pL-PHP beta 0.9 allows remote attackers to bypass authentication by setting the is_admin parameter to 1.EXPLOIT ✓HIGH 7.5EPSS 2.66%12 April 2007
CVE-2007-2006Multiple SQL injection vulnerabilities in login.php in pL-PHP beta 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) pass parameter.EXPLOIT ✓HIGH 7.5EPSS 1.03%12 April 2007

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.