Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,785 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 350 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-1475 | Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument. | EXPLOIT ✓MEDIUM 5.4EPSS 2.37% | 16 March 2007 |
| CVE-2007-1474 | Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames. | EXPLOIT ✓MEDIUM 6.8EPSS 4.95% | 16 March 2007 |
| CVE-2007-1473 | Cross-site scripting (XSS) vulnerability in framework/NLS/NLS.php in Horde Framework before 3.1.4 RC1, when the login page contains a language selection box, allows remote attackers to inject arbitrary web script or HTML via the new_lang parameter to… | EXPLOIT ✓MEDIUM 4.3EPSS 5.15% | 16 March 2007 |
| CVE-2007-1472 | Variable overwrite vulnerability in groupit/base/groupit.start.inc in Groupit 2.00b5 allows remote attackers to conduct remote file inclusion attacks and execute arbitrary PHP code via arguments that are written to $_GLOBALS, as demonstrated using a URL… | EXPLOIT ✓MEDIUM 6.8EPSS 3.39% | 16 March 2007 |
| CVE-2007-1471 | admin/default.asp in Orion-Blog 2.0 allows remote attackers to bypass authentication controls and gain privileges via a direct URL request for admin/AdminBlogNewsEdit.asp. | EXPLOIT ✓HIGH 7.5EPSS 7.44% | 16 March 2007 |
| CVE-2007-1469 | SQL injection vulnerability in gallery.asp in Absolute Image Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 16 March 2007 |
| CVE-2007-1459 | Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the moddir parameter to (1) content/load.inc.php, (2) config/load.inc.php, (3) http/load.inc.php,… | EXPLOIT ✓MEDIUM 6.8EPSS 2.74% | 14 March 2007 |
| CVE-2007-1458 | Multiple PHP remote file inclusion vulnerabilities in CARE2X 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) inc_checkdate_lang.php, (2) inc_charset_fx.php, (3) inc_config_color.php, (4)… | EXPLOIT ✓MEDIUM 6.8EPSS 7.12% | 14 March 2007 |
| CVE-2007-1455 | Multiple absolute path traversal vulnerabilities in Fantastico, as used with cPanel 10.x, allow remote authenticated users to include and execute arbitrary local files via (1) the userlanguage parameter to includes/load_language.php or (2) the… | EXPLOIT ✓HIGH 9.0EPSS 6.60% | 14 March 2007 |
| CVE-2007-1453 | Buffer underflow in the PHP_FILTER_TRIM_DEFAULT macro in the filtering extension (ext/filter) in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by calling filter_var with certain modes such as FILTER_VALIDATE_INT, which causes… | EXPLOIT ✓HIGH 7.5EPSS 9.52% | 14 March 2007 |
| CVE-2007-1452 | The FDF support (ext/fdf) in PHP 5.2.0 and earlier does not implement the input filtering hooks for ext/filter, which allows remote attackers to bypass web site filters via an application/vnd.fdf formatted POST. | EXPLOIT ✓MEDIUM 5.0EPSS 5.15% | 14 March 2007 |
| CVE-2007-1446 | Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1beta allow remote attackers to execute arbitrary PHP code via a URL in the CONF_INCLUDE_PATH parameter to (1) lib-account.inc.php, (2) lib-file.inc.php, (3)… | EXPLOIT ✓HIGH 7.5EPSS 6.58% | 14 March 2007 |
| CVE-2007-1445 | SQL injection vulnerability in the heme preview feature for default.asp in BP Blog 7.0 through 7.0.2 allows remote attackers to execute arbitrary SQL commands via the layout parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 14 March 2007 |
| CVE-2007-1440 | SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 allows remote attackers to execute arbitrary SQL commands via the author parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 13 March 2007 |
| CVE-2007-1439 | PHP remote file inclusion vulnerability in ressourcen/dbopen.php in bitesser MySQL Commander 2.7 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the home parameter. | EXPLOIT ✓HIGH 9.3EPSS 5.53% | 13 March 2007 |
| CVE-2007-1438 | SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.17% | 13 March 2007 |
| CVE-2007-1435 | Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GET or (2) PUT request, which triggers memory corruption. | EXPLOIT ×2 ✓HIGH 10.0EPSS 42.8% | 13 March 2007 |
| CVE-2007-1434 | SQL injection vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) userdetail.php, id and (2) url parameter to (b) jump.php, and id variable… | EXPLOIT ✓HIGH 7.5EPSS 0.99% | 13 March 2007 |
| CVE-2007-1433 | Cross-site scripting (XSS) vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment fields to (1) scripts/addblog_comment.php and (2) detail.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.50% | 13 March 2007 |
| CVE-2007-1432 | Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to gain privileges via direct requests with modified arguments in (1) the user_permissions parameter to add_users.php, and unspecified parameters to (2) addblog.php, (3)… | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 13 March 2007 |
| CVE-2007-1430 | PHP remote file inclusion vulnerability in include/adodb-connection.inc.php in ClipShare 1.5.3 allows remote attackers to execute arbitrary PHP code via a URL in the cmd parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.27% | 13 March 2007 |
| CVE-2007-1428 | SQL injection vulnerability in search.php in PHP Labs JobSitePro 1.0 allows remote attackers to execute arbitrary SQL commands via the salary parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 13 March 2007 |
| CVE-2007-1427 | Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.91% | 13 March 2007 |
| CVE-2007-1425 | SQL injection vulnerability in index.php in Triexa SonicMailer Pro 3.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the list parameter in an archive action. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 13 March 2007 |
| CVE-2007-1424 | Multiple PHP remote file inclusion vulnerabilities in Softnews Media Group DataLife Engine allow remote attackers to execute arbitrary PHP code via a URL in the root_dir parameter to (1) init.php and (2) Ajax/editnews.php. | EXPLOIT ×2 ✓HIGH 7.5EPSS 2.58% | 13 March 2007 |
| CVE-2007-1423 | Multiple PHP remote file inclusion vulnerabilities in WORK system e-commerce 3.0.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the g_include parameter to include/include_top.php and certain other PHP scripts. | EXPLOIT ✓HIGH 9.3EPSS 4.00% | 13 March 2007 |
| CVE-2007-1422 | SQL injection vulnerability in goster.asp in fystyq Duyuru Scripti allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-0688. | EXPLOIT ✓HIGH 7.5EPSS 0.98% | 13 March 2007 |
| CVE-2007-1421 | Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions_kb.php, (2) themen_portal_mitte.php, or (3) logger_engine.php in… | EXPLOIT ×3 ✓HIGH 10.0EPSS 11.3% | 13 March 2007 |
| CVE-2007-1420 | MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized… | EXPLOIT ✓LOW 2.1EPSS 0.98% | 12 March 2007 |
| CVE-2007-1417 | SQL injection vulnerability in index.php in HC NEWSSYSTEM 1.0-4 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a komm aktion. | EXPLOIT ✓HIGH 7.5EPSS 1.24% | 12 March 2007 |
| CVE-2007-1416 | PHP remote file inclusion vulnerability in createurl.php in JCcorp (aka James Coyle) URLshrink allows remote attackers to execute arbitrary PHP code via a URL in the formurl parameter. | EXPLOIT ✓HIGH 10.0EPSS 4.94% | 12 March 2007 |
| CVE-2007-1415 | Multiple PHP remote file inclusion vulnerabilities in PMB Services 3.0.13 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) class_path parameter to (a) includes/resa_func.inc.php (b) admin/notices/perso.inc.php, or… | EXPLOIT ✓HIGH 7.5EPSS 9.29% | 12 March 2007 |
| CVE-2007-1413 | Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably other PHP 4 versions, allows context-dependent attackers to execute arbitrary code via a long value in the third argument (object id). | EXPLOIT ×3 ✓HIGH 7.5EPSS 11.1% | 12 March 2007 |
| CVE-2007-1412 | The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensitive information (script source code) via a long string in the second argument. | EXPLOIT ✓HIGH 7.8EPSS 5.84% | 12 March 2007 |
| CVE-2007-1000 | The ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglue.c in the Linux kernel before 2.6.20.2 allows local users to read arbitrary kernel memory via certain getsockopt calls that trigger a NULL dereference. | EXPLOIT ✓HIGH 7.2EPSS 1.10% | 12 March 2007 |
| CVE-2007-1411 | Buffer overflow in PHP 4.4.6 and earlier, and unspecified PHP 5 versions, allows local and possibly remote attackers to execute arbitrary code via long server name arguments to the (1) mssql_connect and (2) mssql_pconnect functions. | EXPLOIT ✓MEDIUM 6.8EPSS 7.42% | 10 March 2007 |
| CVE-2007-1410 | SQL injection vulnerability in kategori.asp in GaziYapBoz Game Portal allows remote attackers to execute arbitrary SQL commands via the kategori parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.19% | 10 March 2007 |
| CVE-2007-1404 | tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call. | EXPLOIT ×2 ✓HIGH 7.3EPSS 66.7% | 10 March 2007 |
| CVE-2007-1403 | Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a denial of service (Internet Explorer 7 crash) and possibly execute arbitrary code via a long (1) BGCOLOR, (2)… | EXPLOIT ✓HIGH 7.5EPSS 29.2% | 10 March 2007 |
| CVE-2007-1402 | The Rediff Toolbar 2.0 ActiveX control in redifftoolbar.dll allows remote attackers to cause a denial of service via unspecified manipulations, possibly involving improper initialization or blank arguments. | EXPLOIT ✓HIGH 7.5EPSS 2.27% | 10 March 2007 |
| CVE-2007-1401 | Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allow local users to gain privileges via a long argument to the crack_opendict function. | EXPLOIT ✓MEDIUM 6.9EPSS 0.74% | 10 March 2007 |
| CVE-2007-1399 | Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as demonstrated by actively triggering URL access from a… | EXPLOIT ✓CRITICAL 9.8EPSS 19.8% | 10 March 2007 |
| CVE-2007-1398 | The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip_conntrack module loaded, allows remote attackers to cause a denial of service (segmentation fault and application crash) via certain… | EXPLOIT ✓HIGH 7.1EPSS 5.57% | 10 March 2007 |
| CVE-2007-1397 | Multiple stack-based buffer overflows in the (1) ExtractRnick and (2) decrypt_topic_332 functions in FiSH allow remote attackers to execute arbitrary code via long strings. | EXPLOIT ×2 ✓HIGH 10.0EPSS 9.04% | 10 March 2007 |
| CVE-2007-1394 | Direct static code injection vulnerability in startsession.php in Flat Chat 2.0 allows remote attackers to execute arbitrary PHP code via the Chat Name field, which is inserted into online.txt and included by users.php. | EXPLOIT ✓HIGH 10.0EPSS 4.29% | 10 March 2007 |
| CVE-2007-1393 | PHP remote file inclusion vulnerability in mysave.php in Magic CMS 4.2.747 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. | EXPLOIT ✓HIGH 10.0EPSS 4.77% | 10 March 2007 |
| CVE-2007-1392 | Directory traversal vulnerability in down.php in netForo! | EXPLOIT ✓MEDIUM 5.0EPSS 2.75% | 10 March 2007 |
| CVE-2007-1391 | PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter. | EXPLOIT ✓HIGH 10.0EPSS 4.95% | 10 March 2007 |
| CVE-2007-1365 | Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets due to "incorrect mbuf handling for ICMP6 packets." NOTE: this was originally reported as a denial of service. | EXPLOIT ✓HIGH 10.0EPSS 17.8% | 10 March 2007 |
| CVE-2007-1388 | The do_ipv6_setsockopt function in net/ipv6/ipv6_sockglue.c in Linux kernel before 2.6.20, and possibly other versions, allows local users to cause a denial of service (oops) by calling setsockopt with the IPV6_RTHDR option name and possibly a zero… | EXPLOIT ✓MEDIUM 4.4EPSS 0.55% | 10 March 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.