Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,740 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 348 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-1658 | Windows Mail in Microsoft Windows Vista might allow user-assisted remote attackers to execute certain programs via a link to a (1) local file or (2) UNC share pathname in which there is a directory with the same base name as an executable program at the… | EXPLOIT ✓HIGH 9.3EPSS 35.8% | 24 March 2007 |
| CVE-2007-1657 | Stack-based buffer overflow in the file_compress function in minigzip (Modules/zlib) in Python 2.5 allows context-dependent attackers to execute arbitrary code via a long file argument. | EXPLOIT ✓HIGH 7.5EPSS 4.67% | 24 March 2007 |
| CVE-2007-1649 | PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a serialized data input string beginning with S:, which does not properly track the number of input bytes being processed. | EXPLOIT ✓HIGH 7.8EPSS 7.21% | 24 March 2007 |
| CVE-2007-1648 | 0irc 1345 build 20060823 allows remote attackers to cause a denial of service (application crash) by operating an IRC server that sends a long string to a client, which triggers a NULL pointer dereference. | EXPLOIT ✓HIGH 7.8EPSS 7.09% | 24 March 2007 |
| CVE-2007-1647 | Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct… | EXPLOIT ✓HIGH 7.8EPSS 3.34% | 24 March 2007 |
| CVE-2007-1645 | Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69. | EXPLOIT ✓HIGH 10.0EPSS 13.1% | 24 March 2007 |
| CVE-2007-1644 | The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct… | EXPLOIT ✓HIGH 10.0EPSS 32.6% | 24 March 2007 |
| CVE-2007-1643 | Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG[directories][userpanel_dir] parameter to userpanel.php or the (2)… | EXPLOIT ✓HIGH 10.0EPSS 10.7% | 24 March 2007 |
| CVE-2007-1641 | SQL injection vulnerability in index.php in PortailPHP 2.0 allows remote attackers to execute arbitrary SQL commands via the idnews parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 23 March 2007 |
| CVE-2007-1640 | Multiple PHP remote file inclusion vulnerabilities in ClassWeb 2.03 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the BASE parameter to (1) language.php and (2) phpadmin/survey.php. | EXPLOIT ✓HIGH 10.0EPSS 4.75% | 23 March 2007 |
| CVE-2007-1636 | Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.95% | 23 March 2007 |
| CVE-2007-1635 | Static code injection vulnerability in admin/settings.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote authenticated users to inject arbitrary PHP code via the xtop parameter in a "ConfigSave" op to admin.php, which can later be… | EXPLOIT ✓HIGH 9.0EPSS 2.78% | 23 March 2007 |
| CVE-2007-1634 | Variable extraction vulnerability in grab_globals.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to conduct SQL injection attacks via the _FILES[DB][tmp_name] parameter to print.php, which overwrites the $DB variable… | EXPLOIT ✓HIGH 7.5EPSS 0.98% | 23 March 2007 |
| CVE-2007-1633 | Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.86% | 23 March 2007 |
| CVE-2007-1630 | SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Link Engine allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 23 March 2007 |
| CVE-2007-1629 | SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Photo Gallery allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 23 March 2007 |
| CVE-2007-1628 | Multiple PHP remote file inclusion vulnerabilities in Study planner (Studiewijzer) 0.15 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the SPL_CFG[dirroot] parameter to (1)… | EXPLOIT ✓HIGH 9.3EPSS 5.01% | 23 March 2007 |
| CVE-2007-1626 | PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. | EXPLOIT ✓HIGH 9.3EPSS 3.06% | 23 March 2007 |
| CVE-2007-1622 | Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATH_INFO in the… | EXPLOIT ✓MEDIUM 4.3EPSS 5.78% | 23 March 2007 |
| CVE-2007-1621 | PHP remote file inclusion vulnerability in templates/head.php in Active PHP Bookmark Notes (APB) 0.2.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the APB_SETTINGS[template_path] parameter. | EXPLOIT ✓HIGH 10.0EPSS 4.21% | 23 March 2007 |
| CVE-2007-1620 | Multiple PHP remote file inclusion vulnerabilities in PHP DB Designer 1.02 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SITE_PATH] parameter to (a) wind/help.php or (b) wind/about.php, or the (2)… | EXPLOIT ✓HIGH 10.0EPSS 11.0% | 23 March 2007 |
| CVE-2007-1619 | SQL injection vulnerability in viewcomments.php in ScriptMagix Photo Rating 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the phid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 23 March 2007 |
| CVE-2007-1618 | SQL injection vulnerability in index.php in ScriptMagix FAQ Builder 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.05% | 23 March 2007 |
| CVE-2007-1617 | SQL injection vulnerability in index.php in ScriptMagix Recipes 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.06% | 23 March 2007 |
| CVE-2007-1616 | SQL injection vulnerability in index.php in ScriptMagix Lyrics 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the recid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 23 March 2007 |
| CVE-2007-1615 | SQL injection vulnerability in index.php in ScriptMagix Jokes 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.27% | 23 March 2007 |
| CVE-2007-1613 | Directory traversal vulnerability in view.php in MPM Chat 2.5 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 2.42% | 23 March 2007 |
| CVE-2007-1612 | SQL injection vulnerability in index.php in Katalog Plyt Audio 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the kolumna parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 23 March 2007 |
| CVE-2007-1606 | Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary web script or HTML via (1) the showuser parameter to profile.php, the (2) search_forum or (3) search_user parameter to search.php, or… | EXPLOIT ×3 ✓MEDIUM 4.3EPSS 2.00% | 22 March 2007 |
| CVE-2007-1604 | Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute arbitrary PHP code (1) via a forum message with an attached file, which is stored under forums/hello/hello/notes/ or (2) by using… | EXPLOIT ✓HIGH 7.5EPSS 3.00% | 22 March 2007 |
| CVE-2007-1600 | PHP remote file inclusion vulnerability in module.php in Digital Eye Gallery 1.1 Beta (aka 0.1.1b) allows remote attackers to execute arbitrary PHP code via a URL in the menu parameter. | EXPLOIT ✓HIGH 9.3EPSS 3.49% | 22 March 2007 |
| CVE-2007-1596 | Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1)… | EXPLOIT ✓HIGH 9.3EPSS 7.76% | 22 March 2007 |
| CVE-2007-1590 | The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device crash) via SIP (1) INVITE, (2) CANCEL, or unspecified other messages with a WWW-Authenticate header… | EXPLOIT ✓HIGH 7.8EPSS 3.95% | 21 March 2007 |
| CVE-2007-1586 | ZynOS 3.40 allows remote attackers to cause a denial of service (link restart) by sending a request for the name \M via the SMB Mail Slot Protocol. | EXPLOIT ✓HIGH 7.8EPSS 3.09% | 21 March 2007 |
| CVE-2007-1584 | Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by passing an all-whitespace string to this function, which causes it to write '\0' characters in whitespace that precedes the string. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 5.25% | 21 March 2007 |
| CVE-2007-1583 | The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and does not disable it in certain cases when a script terminates, which allows remote attackers to invoke available PHP scripts with… | EXPLOIT ✓MEDIUM 6.8EPSS 5.24% | 21 March 2007 |
| CVE-2007-1582 | The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting certain functions in the GD (ext/gd) extension and unspecified other extensions via a userspace error… | EXPLOIT ✓MEDIUM 6.8EPSS 5.92% | 21 March 2007 |
| CVE-2007-1581 | The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file function via a userspace (1) error or (2) stream handler, which can then be used to destroy and modify… | EXPLOIT ✓HIGH 9.3EPSS 7.92% | 21 March 2007 |
| CVE-2007-1580 | FTPDMIN 0.96 allows remote attackers to cause a denial of service (daemon crash) via a LIST command for a Windows drive letter, as demonstrated using "//A:". | EXPLOIT ✓MEDIUM 6.3EPSS 2.40% | 21 March 2007 |
| CVE-2007-1579 | Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSCRIBE command. | EXPLOIT ✓HIGH 10.0EPSS 56.2% | 21 March 2007 |
| CVE-2007-1578 | Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, allow remote attackers to execute arbitrary code via a long NTLMSSP argument that triggers a stack-based buffer overflow. | EXPLOIT ✓HIGH 10.0EPSS 16.3% | 21 March 2007 |
| CVE-2007-1577 | Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.83% | 21 March 2007 |
| CVE-2007-1572 | SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter, a different vector than CVE-2007-1440. | EXPLOIT ✓MEDIUM 6.8EPSS 0.84% | 21 March 2007 |
| CVE-2007-1571 | PHP remote file inclusion vulnerability in includes/base.php in Radical Designs Activist Mobilization Platform (AMP) 3.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 5.63% | 21 March 2007 |
| CVE-2007-1570 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOIT ✓UnscoredEPSS — | 21 March 2007 |
| CVE-2007-1569 | Stack-based buffer overflow in NewsBin Pro 4.32 allows remote attackers to cause a denial of service or execute arbitrary code via a yEnc (yEncode) encoded article with a long filename, as demonstrated using a .nzb file. | EXPLOIT ✓HIGH 10.0EPSS 7.30% | 21 March 2007 |
| CVE-2007-1568 | Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via a yEnc (yEncode) encoded article with a long filename. | EXPLOIT ×2 ✓HIGH 10.0EPSS 7.79% | 21 March 2007 |
| CVE-2007-1567 | Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors, as demonstrated by warftp_165.tar by Immunity. | EXPLOIT ×3 ✓HIGH 10.0EPSS 50.5% | 21 March 2007 |
| CVE-2007-1566 | SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote attackers to execute arbitrary SQL commands via the NewsID parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.18% | 21 March 2007 |
| CVE-2007-1564 | The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response. | EXPLOIT ✓MEDIUM 6.8EPSS 3.78% | 21 March 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.