Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,740 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 347 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-1791 | SQL injection vulnerability in wall.php in Picture-Engine 1.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.01% | 31 March 2007 |
| CVE-2007-1790 | Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to execute arbitrary PHP code via a URL in the install_root parameter to (1) support.inc.php, (2) function.inc.php, (3) rdal_object.inc.php,… | EXPLOIT ✓MEDIUM 6.8EPSS 7.03% | 31 March 2007 |
| CVE-2007-1787 | Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_dir or (2) lib_dir… | EXPLOIT ✓HIGH 9.3EPSS 4.86% | 31 March 2007 |
| CVE-2007-1785 | The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute arbitrary code via crafted xdr_handle_t data in RPC packets, which is used in calculating an address for a function call, as… | EXPLOIT ✓HIGH 7.1EPSS 15.4% | 31 March 2007 |
| CVE-2006-7185 | PHP remote file inclusion vulnerability in includes/user_standard.php in CMSmelborp Beta allows remote attackers to execute arbitrary PHP code via a URL in the relative_root parameter. | EXPLOIT ✓HIGH 9.3EPSS 3.24% | 30 March 2007 |
| CVE-2006-7184 | Multiple PHP remote file inclusion vulnerabilities in Exhibit Engine (EE) 1.22, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the toroot parameter to (1) fetchsettings.php or (2) fstyles.php. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 1.93% | 30 March 2007 |
| CVE-2006-7183 | PHP remote file inclusion vulnerability in styles.php in Exhibit Engine (EE) 1.22 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the toroot parameter. | EXPLOIT ✓HIGH 10.0EPSS 3.92% | 30 March 2007 |
| CVE-2007-0038 | Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih… | EXPLOIT ×15 ✓HIGH 9.3EPSS 72.9% | 30 March 2007 |
| CVE-2007-1778 | PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 10.0EPSS 4.21% | 30 March 2007 |
| CVE-2007-1777 | Integer overflow in the zip_read_entry function in PHP 4 before 4.4.5 allows remote attackers to execute arbitrary code via a ZIP archive that contains an entry with a length value of 0xffffffff, which is incremented before use in an emalloc call,… | EXPLOIT ✓HIGH 7.5EPSS 15.3% | 30 March 2007 |
| CVE-2007-1776 | SQL injection vulnerability in index.php in the DesignForJoomla.com D4J eZine (com_ezine) 2.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in a read action. | EXPLOIT ✓MEDIUM 6.8EPSS 1.13% | 30 March 2007 |
| CVE-2007-1773 | Multiple directory traversal vulnerabilities in aBitWhizzy allow remote attackers to list arbitrary directories via a .. | EXPLOIT ×2 ✓LOW 2.6EPSS 3.23% | 30 March 2007 |
| CVE-2007-1772 | The FTP service in HP JetDirect print servers allows remote attackers to cause a denial of service (engine crash) via a RETR command with a long pathname. | EXPLOIT ✓HIGH 7.1EPSS 2.89% | 30 March 2007 |
| CVE-2007-1771 | PHP remote file inclusion vulnerability in manage/javascript/formjavascript.php in Ay System Solutions Web Content System (WCS) 2.7.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[JavascriptEdit] parameter. | EXPLOIT ✓HIGH 9.3EPSS 4.70% | 30 March 2007 |
| CVE-2007-1770 | Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, allows remote attackers to cause a denial of service (giomgr crash) and… | EXPLOIT ✓HIGH 10.0EPSS 16.8% | 30 March 2007 |
| CVE-2007-1766 | PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter. | EXPLOIT ✓HIGH 10.0EPSS 5.11% | 30 March 2007 |
| CVE-2007-1765 | Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing… | EXPLOIT ×11 ✓HIGH 9.3EPSS 54.6% | 30 March 2007 |
| CVE-2007-1738 | TrueCrypt 4.3, when installed setuid root, allows local users to cause a denial of service (filesystem unavailability) or gain privileges by mounting a crafted TrueCrypt volume, as demonstrated using (1) /usr/bin or (2) another user's home directory, a… | EXPLOIT ✓MEDIUM 6.9EPSS 0.65% | 28 March 2007 |
| CVE-2007-1735 | Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute arbitrary code via a long printer selection (PRS) name in a Wordperfect document. | EXPLOIT ✓HIGH 9.3EPSS 8.65% | 28 March 2007 |
| CVE-2007-1734 | The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify the upper bounds of the optlen value, which allows local users running on certain architectures to read kernel memory or cause a… | EXPLOIT ×2 ✓HIGH 7.2EPSS 0.73% | 28 March 2007 |
| CVE-2007-1733 | Buffer overflow in InterVations NaviCOPA HTTP Server 2.01 allows remote attackers to execute arbitrary code via a long (1) /cgi-bin/ or (2) /cgi/ pathname in an HTTP GET request, probably a different issue than CVE-2006-5112. | EXPLOIT ✓HIGH 10.0EPSS 10.8% | 28 March 2007 |
| CVE-2007-1675 | Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service via a long username. | EXPLOIT ×3 ✓HIGH 10.0EPSS 61.2% | 28 March 2007 |
| CVE-2007-1730 | Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later allows local users to read kernel memory or cause a denial of service (oops) via a negative optlen value. | EXPLOIT ×2 ✓MEDIUM 6.6EPSS 0.77% | 28 March 2007 |
| CVE-2007-1726 | Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitrary files via the avatar function, which can later be accessed in uploads/. | EXPLOIT ✓MEDIUM 6.5EPSS 2.57% | 28 March 2007 |
| CVE-2007-1725 | SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL commands via the filename of an uploaded file to the avatar function, as demonstrated by setting admin privileges. | EXPLOIT ×2 ✓HIGH 9.3EPSS 1.80% | 28 March 2007 |
| CVE-2007-1721 | Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4)… | EXPLOIT ✓HIGH 10.0EPSS 13.3% | 28 March 2007 |
| CVE-2007-1720 | Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 3.01% | 28 March 2007 |
| CVE-2007-1719 | Buffer overflow in eject.c in Jason W. | EXPLOIT ✓HIGH 7.2EPSS 1.26% | 28 March 2007 |
| CVE-2007-1718 | CRLF injection vulnerability in the mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows remote attackers to inject arbitrary e-mail headers and possibly conduct spam attacks via a control character immediately following folding of… | EXPLOIT ✓HIGH 7.8EPSS 6.69% | 28 March 2007 |
| CVE-2007-1717 | The mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 truncates e-mail messages at the first ASCIIZ ('\0') byte, which might allow context-dependent attackers to prevent intended information from being delivered in e-mail messages. | EXPLOIT ✓MEDIUM 5.0EPSS 4.65% | 28 March 2007 |
| CVE-2007-1715 | PHP remote file inclusion vulnerability in frontpage.php in Free Image Hosting 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.44% | 27 March 2007 |
| CVE-2007-1714 | Cross-site scripting (XSS) vulnerability in index.php in CcCounter 2.0 allows remote attackers to inject arbitrary web script or HTML via dir parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.09% | 27 March 2007 |
| CVE-2007-1712 | SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Auction Pro 7.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.05% | 27 March 2007 |
| CVE-2007-1711 | Double free vulnerability in the unserializer in PHP 4.4.5 and 4.4.6 allows context-dependent attackers to execute arbitrary code by overwriting variables pointing to (1) the GLOBALS array or (2) the session data in _SESSION. | EXPLOIT ✓MEDIUM 6.8EPSS 7.63% | 27 March 2007 |
| CVE-2007-1709 | Buffer overflow in the confirm_phpdoc_compiled function in the phpDOC extension (PECL phpDOC) in PHP 5.2.1 allows context-dependent attackers to execute arbitrary code via a long argument string. | EXPLOIT ✓MEDIUM 4.3EPSS 1.98% | 27 March 2007 |
| CVE-2007-1708 | PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.79% | 27 March 2007 |
| CVE-2007-1707 | PHP remote file inclusion vulnerability in index.php in Net Side Content Management System (Net-Side.net CMS) allows remote attackers to execute arbitrary PHP code via a URL in the cms parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.44% | 27 March 2007 |
| CVE-2007-1706 | SQL injection vulnerability in eWebQuiz.asp in eWebQuiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.05% | 27 March 2007 |
| CVE-2007-1705 | SQL injection vulnerability in default.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.17% | 27 March 2007 |
| CVE-2007-1704 | SQL injection vulnerability in index.php in the Car Manager (com_resman) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.06% | 27 March 2007 |
| CVE-2007-1703 | SQL injection vulnerability in index.php in the RWCards (com_rwcards) 2.4.3 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.21% | 27 March 2007 |
| CVE-2007-1702 | PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 4.96% | 27 March 2007 |
| CVE-2007-1701 | PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as demonstrated by calling… | EXPLOIT ✓MEDIUM 6.8EPSS 9.23% | 27 March 2007 |
| CVE-2007-1700 | The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute… | EXPLOIT ✓HIGH 7.5EPSS 9.02% | 27 March 2007 |
| CVE-2007-1699 | Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to… | EXPLOIT ✓HIGH 10.0EPSS 10.6% | 27 March 2007 |
| CVE-2007-1698 | download.php in Philex 0.2.3 and earlier allows remote attackers to read arbitrary files and source code, and obtain sensitive information via the file parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.50% | 27 March 2007 |
| CVE-2007-1697 | PHP remote file inclusion vulnerability in header.inc.php in Philex 0.2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CssFile parameter. | EXPLOIT ✓HIGH 10.0EPSS 73.0% | 27 March 2007 |
| CVE-2007-1696 | SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsPaperID parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 27 March 2007 |
| CVE-2007-1678 | Cross-site scripting (XSS) vulnerability in the Fizzle 0.5 extension for Firefox allows remote attackers to inject arbitrary web script or HTML via RSS feeds, which are executed by the chrome: URI handler. | EXPLOIT ✓MEDIUM 4.3EPSS 3.73% | 26 March 2007 |
| CVE-2007-1465 | Stack-based buffer overflow in dproxy.c for dproxy 0.1 through 0.5 allows remote attackers to execute arbitrary code via a long DNS query packet to UDP port 53. | EXPLOIT ✓HIGH 10.0EPSS 8.32% | 24 March 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.