SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,740 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026

25,049 results · page 349 of 501

CVESummaryPriorityPublished
CVE-2007-1563The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an…EXPLOIT ✓MEDIUM 6.8EPSS 4.85%21 March 2007
CVE-2007-1562The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate…EXPLOIT ✓MEDIUM 6.8EPSS 13.8%21 March 2007
CVE-2007-1561The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one valid and one invalid IP address.EXPLOIT ✓HIGH 7.8EPSS 14.5%21 March 2007
CVE-2007-0348Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long…EXPLOIT ✓HIGH 9.3EPSS 35.1%21 March 2007
CVE-2007-1556SQL injection vulnerability in kommentare.php in Creative Files 1.2 allows remote attackers to execute arbitrary SQL commands via the dlid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.17%21 March 2007
CVE-2007-1555SQL injection vulnerability in forum.php in the Minerva mod 2.0.21 build 238a and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the c parameter.EXPLOIT ✓HIGH 7.5EPSS 1.21%20 March 2007
CVE-2007-1553admin/configuration.php in Guestbara 1.2 and earlier allows remote attackers to modify the e-mail, name, and password of the admin account by setting the zapis parameter to "ok" and providing modified admin_mail, login, and pass parameters.EXPLOIT ✓MEDIUM 5.0EPSS 1.82%20 March 2007
CVE-2007-1552Unrestricted file upload vulnerability in usercp.php in MetaForum 0.513 Beta restricts file types based on the MIME type in the Content-type HTTP header, which allows remote attackers to upload and execute arbitrary scripts via an image MIME type with a…EXPLOIT ✓HIGH 7.5EPSS 5.46%20 March 2007
CVE-2007-1550Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (1) image_id or (2) cat_id parameter to (a) gallery.php; the (3) news_id parameter to (b) news.php or (c) print.php; (4) the…EXPLOIT ×5 ✓HIGH 7.5EPSS 2.05%20 March 2007
CVE-2007-1548SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash…EXPLOIT ✓HIGH 7.5EPSS 1.79%20 March 2007
CVE-2007-1542Unspecified vulnerability in the Cisco IP Phone 7940 and 7960 running firmware before POS8-6-0 allows remote attackers to cause a denial of service via the Remote-Party-ID sipURI field in a SIP INVITE request.EXPLOIT ✓MEDIUM 5.0EPSS 9.18%20 March 2007
CVE-2007-1540Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to run arbitrary executables and bypass authentication via a ..EXPLOIT ✓MEDIUM 4.3EPSS 4.94%20 March 2007
CVE-2007-1539Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to include arbitrary files via a ..EXPLOIT ✓MEDIUM 4.3EPSS 3.15%20 March 2007
CVE-2006-7173Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP code via a crafted option_new[report_w_day] parameter in a preferenze action, which can be later accessed via…EXPLOIT ✓HIGH 10.0EPSS 3.82%20 March 2007
CVE-2006-7172Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers to execute arbitrary code via a leading dotted-quad IP address string in the (1) PC-REMOTE-ADDR HTTP header, which is inserted into…EXPLOIT ×2 ✓HIGH 7.5EPSS 2.26%20 March 2007
CVE-2007-1536Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffer overflow.EXPLOIT ✓HIGH 9.3EPSS 13.5%20 March 2007
CVE-2007-1531Microsoft Windows XP and Vista overwrites ARP table entries included in gratuitous ARP, which allows remote attackers to cause a denial of service (loss of network access) by sending a gratuitous ARP for the address of the Vista host.EXPLOIT ×2 ✓MEDIUM 5.0EPSS 22.8%20 March 2007
CVE-2007-1525Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code via the cat parameter, which can be executed via a request to posts.php.EXPLOIT ✓MEDIUM 6.8EPSS 37.0%20 March 2007
CVE-2007-1524Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 3.20%20 March 2007
CVE-2007-1522Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which calls…EXPLOIT ✓MEDIUM 6.8EPSS 6.61%20 March 2007
CVE-2007-1521Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a…EXPLOIT ✓MEDIUM 6.8EPSS 8.49%20 March 2007
CVE-2007-1518SQL injection vulnerability in usergroups.php in Woltlab Burning Board (wBB) 2.x allows remote attackers to execute arbitrary SQL commands via the array index of the applicationids array.EXPLOIT ✓HIGH 7.5EPSS 0.98%20 March 2007
CVE-2007-1517SQL injection vulnerability in comments.php in WSN Guest 1.02 and 1.21 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.26%20 March 2007
CVE-2007-1516PHP remote file inclusion vulnerability in functions/update.php in Cicoandcico CcMail 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the functions_dir parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.65%20 March 2007
CVE-2007-1515Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP H3 4.1.3, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via (1) the email Subject header in thread.php, (2) the edit_query parameter in search.php, or…EXPLOIT ✓MEDIUM 4.3EPSS 2.37%20 March 2007
CVE-2007-1514PHP remote file inclusion vulnerability in index.php in ViperWeb Portal alpha 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the modpath parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.42%20 March 2007
CVE-2007-1513PHP remote file inclusion vulnerability in comanda.php in GraFX Company WebSite Builder (CWB) PRO 1.9.8, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter.EXPLOIT ✓MEDIUM 6.8EPSS 3.47%20 March 2007
CVE-2007-1511Buffer overflow in FrontBase Relational Database Server 4.2.7 and earlier allows remote authenticated users, with privileges for creating a stored procedure, to execute arbitrary code via a CREATE PROCEDURE request with a long procedure name.EXPLOIT ×2 ✓HIGH 7.1EPSS 5.44%20 March 2007
CVE-2007-1510SQL injection vulnerability in post.php in Particle Blogger 1.0.0 through 1.2.0 allows remote attackers to execute arbitrary SQL commands via the postid parameter.EXPLOIT ✓HIGH 7.5EPSS 2.00%20 March 2007
CVE-2007-1509Directory traversal vulnerability in enkrypt.php in Sascha Schroeder krypt (aka Holtstraeter Rot 13) allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 4.3EPSS 2.27%20 March 2007
CVE-2007-1508Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin allows remote attackers to inject arbitrary web script or HTML via the RESULT parameter, a different vector than CVE-2006-5983.EXPLOIT ✓MEDIUM 4.3EPSS 1.77%20 March 2007
CVE-2006-7170Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) product_review.php; or the (6) orderNo parameter to (b)…EXPLOIT ×2 ✓HIGH 7.5EPSS 1.28%20 March 2007
CVE-2006-7169PHP remote file inclusion vulnerability in includes/header_simple.php in Ultimate PHP Board (UPB) 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _CONFIG[skin_dir] parameter.EXPLOIT ✓MEDIUM 6.8EPSS 5.06%20 March 2007
CVE-2006-7168PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.EXPLOIT ✓HIGH 7.5EPSS 7.26%20 March 2007
CVE-2006-7167Unspecified vulnerability in ProRat Server 1.9 Fix2 allows remote attackers to bypass the authentication mechanism for remote login via unspecified vectors.EXPLOIT ✓HIGH 7.5EPSS 2.26%20 March 2007
CVE-2007-1506Cross-site scripting (XSS) vulnerability in PORTAL.wwv_main.render_warning_screen in the Oracle Portal 10g allows remote attackers to inject arbitrary web script or HTML via the (1) p_oldurl and (2) p_newurl parameters.EXPLOIT ✓MEDIUM 4.3EPSS 1.81%19 March 2007
CVE-2007-1501Stack-based buffer overflow in Avant Browser 11.0 build 26 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Content-Type HTTP header.EXPLOIT ✓HIGH 9.3EPSS 5.83%19 March 2007
CVE-2007-1499Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location…EXPLOIT ✓MEDIUM 4.3EPSS 29.8%17 March 2007
CVE-2007-1493nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, which allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, due to an incomplete patch for…EXPLOIT ×2 ✓HIGH 7.5EPSS 3.21%16 March 2007
CVE-2007-1492winmm.dll in Microsoft Windows XP allows user-assisted remote attackers to cause a denial of service (infinite loop) via a large cch argument value to the mmioRead function, as demonstrated by a crafted WAV file.EXPLOIT ✓HIGH 7.1EPSS 13.8%16 March 2007
CVE-2007-0450Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 90.8%16 March 2007
CVE-2007-1487Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 3.44%16 March 2007
CVE-2007-1484The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operation…EXPLOIT ✓MEDIUM 4.6EPSS 1.11%16 March 2007
CVE-2007-1483Multiple PHP remote file inclusion vulnerabilities in WebCalendar 0.9.45 allow remote attackers to execute arbitrary PHP code via a URL in the includedir parameter to (1) login.php, (2) get_reminders.php, or (3) get_events.php.EXPLOIT ✓HIGH 7.5EPSS 4.06%16 March 2007
CVE-2007-1482Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script or HTML via the e_id parameter in a viewentry cmd.EXPLOIT ✓MEDIUM 4.3EPSS 1.57%16 March 2007
CVE-2007-1481SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_id parameter in a viewentry cmd.EXPLOIT ✓HIGH 7.5EPSS 2.21%16 March 2007
CVE-2007-1480Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD parameters set.EXPLOIT ✓HIGH 7.5EPSS 2.36%16 March 2007
CVE-2007-1479Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.55%16 March 2007
CVE-2007-1478download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter.EXPLOIT ✓MEDIUM 5.0EPSS 2.50%16 March 2007
CVE-2007-1476The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of…EXPLOIT ✓LOW 1.9EPSS 0.86%16 March 2007

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.