Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,740 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 349 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-1563 | The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an… | EXPLOIT ✓MEDIUM 6.8EPSS 4.85% | 21 March 2007 |
| CVE-2007-1562 | The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate… | EXPLOIT ✓MEDIUM 6.8EPSS 13.8% | 21 March 2007 |
| CVE-2007-1561 | The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one valid and one invalid IP address. | EXPLOIT ✓HIGH 7.8EPSS 14.5% | 21 March 2007 |
| CVE-2007-0348 | Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long… | EXPLOIT ✓HIGH 9.3EPSS 35.1% | 21 March 2007 |
| CVE-2007-1556 | SQL injection vulnerability in kommentare.php in Creative Files 1.2 allows remote attackers to execute arbitrary SQL commands via the dlid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.17% | 21 March 2007 |
| CVE-2007-1555 | SQL injection vulnerability in forum.php in the Minerva mod 2.0.21 build 238a and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the c parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.21% | 20 March 2007 |
| CVE-2007-1553 | admin/configuration.php in Guestbara 1.2 and earlier allows remote attackers to modify the e-mail, name, and password of the admin account by setting the zapis parameter to "ok" and providing modified admin_mail, login, and pass parameters. | EXPLOIT ✓MEDIUM 5.0EPSS 1.82% | 20 March 2007 |
| CVE-2007-1552 | Unrestricted file upload vulnerability in usercp.php in MetaForum 0.513 Beta restricts file types based on the MIME type in the Content-type HTTP header, which allows remote attackers to upload and execute arbitrary scripts via an image MIME type with a… | EXPLOIT ✓HIGH 7.5EPSS 5.46% | 20 March 2007 |
| CVE-2007-1550 | Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (1) image_id or (2) cat_id parameter to (a) gallery.php; the (3) news_id parameter to (b) news.php or (c) print.php; (4) the… | EXPLOIT ×5 ✓HIGH 7.5EPSS 2.05% | 20 March 2007 |
| CVE-2007-1548 | SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash… | EXPLOIT ✓HIGH 7.5EPSS 1.79% | 20 March 2007 |
| CVE-2007-1542 | Unspecified vulnerability in the Cisco IP Phone 7940 and 7960 running firmware before POS8-6-0 allows remote attackers to cause a denial of service via the Remote-Party-ID sipURI field in a SIP INVITE request. | EXPLOIT ✓MEDIUM 5.0EPSS 9.18% | 20 March 2007 |
| CVE-2007-1540 | Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to run arbitrary executables and bypass authentication via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 4.94% | 20 March 2007 |
| CVE-2007-1539 | Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to include arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 3.15% | 20 March 2007 |
| CVE-2006-7173 | Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP code via a crafted option_new[report_w_day] parameter in a preferenze action, which can be later accessed via… | EXPLOIT ✓HIGH 10.0EPSS 3.82% | 20 March 2007 |
| CVE-2006-7172 | Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers to execute arbitrary code via a leading dotted-quad IP address string in the (1) PC-REMOTE-ADDR HTTP header, which is inserted into… | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.26% | 20 March 2007 |
| CVE-2007-1536 | Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffer overflow. | EXPLOIT ✓HIGH 9.3EPSS 13.5% | 20 March 2007 |
| CVE-2007-1531 | Microsoft Windows XP and Vista overwrites ARP table entries included in gratuitous ARP, which allows remote attackers to cause a denial of service (loss of network access) by sending a gratuitous ARP for the address of the Vista host. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 22.8% | 20 March 2007 |
| CVE-2007-1525 | Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code via the cat parameter, which can be executed via a request to posts.php. | EXPLOIT ✓MEDIUM 6.8EPSS 37.0% | 20 March 2007 |
| CVE-2007-1524 | Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.20% | 20 March 2007 |
| CVE-2007-1522 | Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which calls… | EXPLOIT ✓MEDIUM 6.8EPSS 6.61% | 20 March 2007 |
| CVE-2007-1521 | Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a… | EXPLOIT ✓MEDIUM 6.8EPSS 8.49% | 20 March 2007 |
| CVE-2007-1518 | SQL injection vulnerability in usergroups.php in Woltlab Burning Board (wBB) 2.x allows remote attackers to execute arbitrary SQL commands via the array index of the applicationids array. | EXPLOIT ✓HIGH 7.5EPSS 0.98% | 20 March 2007 |
| CVE-2007-1517 | SQL injection vulnerability in comments.php in WSN Guest 1.02 and 1.21 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.26% | 20 March 2007 |
| CVE-2007-1516 | PHP remote file inclusion vulnerability in functions/update.php in Cicoandcico CcMail 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the functions_dir parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.65% | 20 March 2007 |
| CVE-2007-1515 | Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP H3 4.1.3, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via (1) the email Subject header in thread.php, (2) the edit_query parameter in search.php, or… | EXPLOIT ✓MEDIUM 4.3EPSS 2.37% | 20 March 2007 |
| CVE-2007-1514 | PHP remote file inclusion vulnerability in index.php in ViperWeb Portal alpha 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the modpath parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.42% | 20 March 2007 |
| CVE-2007-1513 | PHP remote file inclusion vulnerability in comanda.php in GraFX Company WebSite Builder (CWB) PRO 1.9.8, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 3.47% | 20 March 2007 |
| CVE-2007-1511 | Buffer overflow in FrontBase Relational Database Server 4.2.7 and earlier allows remote authenticated users, with privileges for creating a stored procedure, to execute arbitrary code via a CREATE PROCEDURE request with a long procedure name. | EXPLOIT ×2 ✓HIGH 7.1EPSS 5.44% | 20 March 2007 |
| CVE-2007-1510 | SQL injection vulnerability in post.php in Particle Blogger 1.0.0 through 1.2.0 allows remote attackers to execute arbitrary SQL commands via the postid parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.00% | 20 March 2007 |
| CVE-2007-1509 | Directory traversal vulnerability in enkrypt.php in Sascha Schroeder krypt (aka Holtstraeter Rot 13) allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 4.3EPSS 2.27% | 20 March 2007 |
| CVE-2007-1508 | Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin allows remote attackers to inject arbitrary web script or HTML via the RESULT parameter, a different vector than CVE-2006-5983. | EXPLOIT ✓MEDIUM 4.3EPSS 1.77% | 20 March 2007 |
| CVE-2006-7170 | Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) product_review.php; or the (6) orderNo parameter to (b)… | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.28% | 20 March 2007 |
| CVE-2006-7169 | PHP remote file inclusion vulnerability in includes/header_simple.php in Ultimate PHP Board (UPB) 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _CONFIG[skin_dir] parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 5.06% | 20 March 2007 |
| CVE-2006-7168 | PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 7.26% | 20 March 2007 |
| CVE-2006-7167 | Unspecified vulnerability in ProRat Server 1.9 Fix2 allows remote attackers to bypass the authentication mechanism for remote login via unspecified vectors. | EXPLOIT ✓HIGH 7.5EPSS 2.26% | 20 March 2007 |
| CVE-2007-1506 | Cross-site scripting (XSS) vulnerability in PORTAL.wwv_main.render_warning_screen in the Oracle Portal 10g allows remote attackers to inject arbitrary web script or HTML via the (1) p_oldurl and (2) p_newurl parameters. | EXPLOIT ✓MEDIUM 4.3EPSS 1.81% | 19 March 2007 |
| CVE-2007-1501 | Stack-based buffer overflow in Avant Browser 11.0 build 26 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Content-Type HTTP header. | EXPLOIT ✓HIGH 9.3EPSS 5.83% | 19 March 2007 |
| CVE-2007-1499 | Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location… | EXPLOIT ✓MEDIUM 4.3EPSS 29.8% | 17 March 2007 |
| CVE-2007-1493 | nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, which allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, due to an incomplete patch for… | EXPLOIT ×2 ✓HIGH 7.5EPSS 3.21% | 16 March 2007 |
| CVE-2007-1492 | winmm.dll in Microsoft Windows XP allows user-assisted remote attackers to cause a denial of service (infinite loop) via a large cch argument value to the mmioRead function, as demonstrated by a crafted WAV file. | EXPLOIT ✓HIGH 7.1EPSS 13.8% | 16 March 2007 |
| CVE-2007-0450 | Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 90.8% | 16 March 2007 |
| CVE-2007-1487 | Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.44% | 16 March 2007 |
| CVE-2007-1484 | The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operation… | EXPLOIT ✓MEDIUM 4.6EPSS 1.11% | 16 March 2007 |
| CVE-2007-1483 | Multiple PHP remote file inclusion vulnerabilities in WebCalendar 0.9.45 allow remote attackers to execute arbitrary PHP code via a URL in the includedir parameter to (1) login.php, (2) get_reminders.php, or (3) get_events.php. | EXPLOIT ✓HIGH 7.5EPSS 4.06% | 16 March 2007 |
| CVE-2007-1482 | Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script or HTML via the e_id parameter in a viewentry cmd. | EXPLOIT ✓MEDIUM 4.3EPSS 1.57% | 16 March 2007 |
| CVE-2007-1481 | SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_id parameter in a viewentry cmd. | EXPLOIT ✓HIGH 7.5EPSS 2.21% | 16 March 2007 |
| CVE-2007-1480 | Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD parameters set. | EXPLOIT ✓HIGH 7.5EPSS 2.36% | 16 March 2007 |
| CVE-2007-1479 | Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.55% | 16 March 2007 |
| CVE-2007-1478 | download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.50% | 16 March 2007 |
| CVE-2007-1476 | The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of… | EXPLOIT ✓LOW 1.9EPSS 0.86% | 16 March 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.