SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,710 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026

25,049 results · page 345 of 501

CVESummaryPriorityPublished
CVE-2007-2005Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) contact_type.php, (2)…EXPLOIT ✓MEDIUM 6.8EPSS 6.68%12 April 2007
CVE-2007-2004Multiple SQL injection vulnerabilities in InoutMailingListManager 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to changename.php and other unspecified vectors.EXPLOIT ✓HIGH 7.5EPSS 1.02%12 April 2007
CVE-2007-2003InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check fails, which allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by…EXPLOIT ✓MEDIUM 6.8EPSS 2.01%12 April 2007
CVE-2007-2002InoutMailingListManager 3.1 and earlier allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by setting an arbitrary admin cookie.EXPLOIT ✓MEDIUM 6.8EPSS 2.01%12 April 2007
CVE-2007-2001Multiple direct static code injection vulnerabilities in admin/configurer2.php in Crea-Book 1.0 and earlier allow remote authenticated administrators to execute arbitrary PHP code via the "Fond de la page" (background color) field and other unspecified…EXPLOIT ✓MEDIUM 6.5EPSS 2.02%12 April 2007
CVE-2007-2000Multiple SQL injection vulnerabilities in admin/admin.php in Crea-Book 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pseudo or (2) passe parameter.EXPLOIT ✓HIGH 7.5EPSS 1.04%12 April 2007
CVE-2007-1999PHP remote file inclusion vulnerability in index.php in Weatimages 1.7.1 and earlier, when weatimages.ini is missing, allows remote attackers to execute arbitrary PHP code via a URL in the ini[langpack] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.79%12 April 2007
CVE-2007-1998Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP code via the Email field, which results in code execution through a direct request to gb.php.EXPLOIT ✓HIGH 7.5EPSS 8.75%12 April 2007
CVE-2007-1996PHP remote file inclusion vulnerability in codebreak.php in CodeBreak, probably 1.1.2 and earlier, allows remote attackers to execute arbitrary PHP code via a URL in the process_method parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.16%12 April 2007
CVE-2007-1992Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) EXIF_Makernote.php or (2) EXIF.php…EXPLOIT ✓HIGH 7.5EPSS 6.08%12 April 2007
CVE-2007-1989Multiple cross-site scripting (XSS) vulnerabilities in DotClear before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post_id parameter to ecrire/trackback.php or the (2) tool_url parameter to tools/thememng/index.php.EXPLOIT ×2 ✓MEDIUM 4.3EPSS 2.04%12 April 2007
CVE-2007-1986Multiple PHP remote file inclusion vulnerabilities in barnraiser AROUNDMe 0.7.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) language_path_core parameter to inc/core_profile.header.php, the (2) template_path_core parameter…EXPLOIT ✓HIGH 7.5EPSS 3.66%12 April 2007
CVE-2007-1983PHP remote file inclusion vulnerability in include/default_header.php in Cyboards PHP Lite 1.21 allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter, a different vector than CVE-2006-2871.EXPLOIT ✓HIGH 7.5EPSS 2.79%12 April 2007
CVE-2007-1982Multiple PHP remote file inclusion vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) __IncludeFilePHPClass, (2) __ClassPath, and (3) __class parameters…EXPLOIT ✓HIGH 7.5EPSS 9.91%12 April 2007
CVE-2007-1980SQL injection vulnerability in index.php in the Topliste 1.0 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.06%12 April 2007
CVE-2007-1979SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the postid parameter, possibly involving the get_blogid_from_postid function in…EXPLOIT ✓HIGH 7.5EPSS 2.17%12 April 2007
CVE-2007-1978SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view_game_list action.EXPLOIT ✓HIGH 7.5EPSS 1.03%12 April 2007
CVE-2007-1974SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as used in Xoops modules such as (1) Zmagazine 1.0, (2) Happy Linux XFsection 1.07 and earlier, and possibly other modules, allows…EXPLOIT ×3 ✓HIGH 7.5EPSS 5.53%12 April 2007
CVE-2007-1559Multiple stack-based buffer overflows in SonicDVDDashVRNav.dll in Roxio CinePlayer 3.2 allow remote attackers to execute arbitrary code via (1) unspecified long property values to SonicMediaPlayer.dll or (2) long arguments to unspecified methods in…EXPLOIT ×2 ✓HIGH 9.3EPSS 31.8%11 April 2007
CVE-2007-1364DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie information of arbitrary users via the id parameter in editlogcal.php, (2) add arbitrary links via…EXPLOIT ✓MEDIUM 6.4EPSS 2.25%11 April 2007
CVE-2007-1363Multiple SQL injection vulnerabilities in DropAFew before 0.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the delete action in (a) search.php or (b) search-pda.php, or the (2) calories parameter in a save…EXPLOIT ×2 ✓HIGH 7.5EPSS 1.07%11 April 2007
CVE-2007-1971SQL injection vulnerability in fotokategori.asp in Gazi Okul Sitesi 2007 allows remote attackers to execute arbitrary SQL commands via the query string.EXPLOIT ✓HIGH 7.5EPSS 0.98%11 April 2007
CVE-2007-1968PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the scoreid parameter.EXPLOIT ✓MEDIUM 6.8EPSS 3.32%11 April 2007
CVE-2007-1963SQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, as utilized by index.php, a related…EXPLOIT ✓HIGH 7.5EPSS 1.32%11 April 2007
CVE-2007-1962SQL injection vulnerability in index.php in the WF-Snippets 1.02 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action.EXPLOIT ✓HIGH 7.5EPSS 1.04%11 April 2007
CVE-2007-1961PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.34%11 April 2007
CVE-2007-1960SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS, and possibly other versions up to 1.10, allows remote attackers to execute arbitrary SQL commands via the lid parameter.EXPLOIT ✓HIGH 7.5EPSS 0.99%11 April 2007
CVE-2007-1956SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the C parameter.EXPLOIT ✓HIGH 7.5EPSS 0.98%11 April 2007
CVE-2007-1948Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as…EXPLOIT ✓HIGH 9.3EPSS 8.26%11 April 2007
CVE-2007-1947Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.04 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute…EXPLOIT ✓LOW 3.5EPSS 4.48%11 April 2007
CVE-2007-1943Integer overflow in ACDSee Photo Manager 9.0 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via large width image sizes in a crafted BMP image, as demonstrated by w3intof.bmp and w4intof.bmp.EXPLOIT ✓HIGH 9.3EPSS 9.37%11 April 2007
CVE-2007-1942Integer overflow in FastStone Image Viewer 2.9 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted BMP image, as demonstrated by wh3intof.bmp and wh4intof.bmp.EXPLOIT ✓HIGH 9.3EPSS 9.08%11 April 2007
CVE-2007-1357The atalk_sum_skb function in AppleTalk for Linux kernel 2.6.x before 2.6.21, and possibly 2.4.x, allows remote attackers to cause a denial of service (crash) via an AppleTalk frame that is shorter than the specified length, which triggers a BUG_ON call…EXPLOIT ✓HIGH 7.8EPSS 13.5%11 April 2007
CVE-2007-1937PHP remote file inclusion vulnerability in smilies.php in Scorp Book 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config parameter.EXPLOIT ✓MEDIUM 6.8EPSS 3.12%10 April 2007
CVE-2007-1934Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 2.48%10 April 2007
CVE-2007-1933Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 6.33%10 April 2007
CVE-2007-1932Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.51%10 April 2007
CVE-2007-1931SQL injection vulnerability in index.php in the slownik module in SmodCMS 2.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ssid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.03%10 April 2007
CVE-2007-1930Directory traversal vulnerability in download2.php in cattaDoc 2.21, and possibly other versions including 3.0, allows remote attackers to read arbitrary files via a ..EXPLOIT ✓HIGH 7.8EPSS 3.53%10 April 2007
CVE-2007-1929Directory traversal vulnerability in downloadpic.php in Beryo 2.0, and possibly other versions including 2.4, allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 3.44%10 April 2007
CVE-2007-1928Directory traversal vulnerability in index.php in witshare 0.9 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 2.94%10 April 2007
CVE-2007-1920SQL injection vulnerability in index.php in the aktualnosci module in SmodBIP 1.06 and earlier allows remote attackers to execute arbitrary SQL commands via the zoom parameter, possibly related to home.php.EXPLOIT ✓HIGH 7.5EPSS 1.18%10 April 2007
CVE-2007-1919Cross-site scripting (XSS) vulnerability in index.php in Arizona Dream Livre d'or (livor) 2.5 allows remote attackers to inject arbitrary web script or HTML via the page parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.50%10 April 2007
CVE-2007-1912Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file.EXPLOIT ✓MEDIUM 6.8EPSS 11.5%10 April 2007
CVE-2007-1911Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.EXPLOIT ✓HIGH 7.1EPSS 11.9%10 April 2007
CVE-2007-1910Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted document, as demonstrated by file789-1.doc.EXPLOIT ✓MEDIUM 6.8EPSS 24.9%10 April 2007
CVE-2007-1909SQL injection vulnerability in login.php in Ryan Haudenschilt Battle.net Clan Script for PHP 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) pass parameter.EXPLOIT ✓HIGH 7.5EPSS 1.06%10 April 2007
CVE-2007-1908PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the php121dir parameter, which is accessed by the file_exists…EXPLOIT ✓MEDIUM 6.8EPSS 3.12%10 April 2007
CVE-2007-1907PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.65%10 April 2007
CVE-2007-1906Directory traversal vulnerability in richedit/keyboard.php in eCardMAX HotEditor (Hot Editor) 4.0, and the HotEditor plugin for MyBB, allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓MEDIUM 6.8EPSS 3.23%10 April 2007

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.