Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,785 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 351 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-1383 | Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this counter, which causes the same variable to be destroyed twice, a related issue to CVE-2007-1286. | EXPLOIT ✓CRITICAL 9.8EPSS 15.2% | 10 March 2007 |
| CVE-2007-1382 | The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demonstrated by using the Run method of this object to execute cmd.exe, which bypasses PHP's safe mode. | EXPLOIT ✓MEDIUM 6.8EPSS 1.61% | 10 March 2007 |
| CVE-2007-1381 | The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and fixed on 20070304, calls strlcpy where strlcat was intended and uses improper arguments, which allows context-dependent attackers to… | EXPLOIT ✓HIGH 7.6EPSS 9.07% | 10 March 2007 |
| CVE-2007-1380 | The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-dependent attackers to obtain sensitive information (memory contents) via a serialized variable entry with a large length value,… | EXPLOIT ✓MEDIUM 5.0EPSS 9.08% | 10 March 2007 |
| CVE-2007-1377 | AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier that begins with search= followed… | EXPLOIT ✓MEDIUM 5.0EPSS 17.3% | 10 March 2007 |
| CVE-2007-1376 | The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments… | EXPLOIT ×2 ✓HIGH 7.5EPSS 10.0% | 10 March 2007 |
| CVE-2007-1375 | Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sensitive memory via a large value in the length argument, a different vulnerability than CVE-2006-1991. | EXPLOIT ✓MEDIUM 5.0EPSS 8.16% | 10 March 2007 |
| CVE-2007-1373 | Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers to execute arbitrary code via a long LOGIN command. | EXPLOIT ×3 ✓HIGH 10.0EPSS 58.7% | 10 March 2007 |
| CVE-2007-1372 | PHP remote file inclusion vulnerability in styles/internal/header.php in the PostGuestbook 0.6.1 module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the tpl_pgb_moddir parameter. | EXPLOIT ✓HIGH 10.0EPSS 4.03% | 10 March 2007 |
| CVE-2007-1371 | Multiple buffer overflows in Conquest 8.2a and earlier (1) allow local users to gain privileges by querying a metaserver that sends a long server entry processed by metaGetServerList and allow remote metaservers to execute arbitrary code via a long… | EXPLOIT ✓MEDIUM 6.9EPSS 4.10% | 10 March 2007 |
| CVE-2007-0005 | Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges. | EXPLOIT ✓MEDIUM 6.9EPSS 0.61% | 10 March 2007 |
| CVE-2007-1369 | ini_modifier (sgid-zendtech) in Zend Platform 2.2.3 and earlier allows local users to modify the system php.ini file by editing a copy of php.ini file using the -f parameter, and then performing a symlink attack using the directory that contains the… | EXPLOIT ✓MEDIUM 4.4EPSS 0.64% | 9 March 2007 |
| CVE-2007-1359 | Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contains an ASCIIZ (0x00) byte, which mod_security treats as a terminator even… | EXPLOIT ✓MEDIUM 6.8EPSS 6.62% | 8 March 2007 |
| CVE-2007-1347 | Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information,… | EXPLOIT ✓HIGH 7.1EPSS 30.3% | 8 March 2007 |
| CVE-2007-1340 | PHP remote file inclusion vulnerability in eintrag.php in Weltennetz News-Letterman 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the sqllog parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.53% | 8 March 2007 |
| CVE-2007-1339 | SQL injection vulnerability in index.php in Links Management Application 1.0 allows remote attackers to execute arbitrary SQL commands via the lcnt parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.37% | 8 March 2007 |
| CVE-2007-1331 | Multiple cross-site scripting (XSS) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to inject arbitrary web script or HTML via unspecified vectors that bypass the client-side protection scheme, one of which may be the… | EXPLOIT ✓MEDIUM 4.3EPSS 5.40% | 7 March 2007 |
| CVE-2007-1330 | Comodo Firewall Pro (CFP) (formerly Comodo Personal Firewall) 2.4.18.184 and earlier allows local users to bypass driver protections on the HKLM\SYSTEM\Software\Comodo\Personal Firewall registry key by guessing the name of a named pipe under… | EXPLOIT ✓MEDIUM 4.4EPSS 0.69% | 7 March 2007 |
| CVE-2007-1327 | The SILC_SERVER_CMD_FUNC function in apps/silcd/command.c in silc-server 1.0.2 allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a request without a cipher algorithm and an invalid HMAC algorithm. | EXPLOIT ✓HIGH 7.8EPSS 9.89% | 7 March 2007 |
| CVE-2006-7157 | Buffer overflow in Google Earth v4.0.2091 (beta) allows remote user-assisted attackers to cause a denial of service (crash) via a KML or KMZ file with a long href element. | EXPLOIT ✓HIGH 7.1EPSS 7.30% | 7 March 2007 |
| CVE-2006-7156 | PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a module for miniBB, allows remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter. | EXPLOIT ✓HIGH 10.0EPSS 4.83% | 7 March 2007 |
| CVE-2006-7152 | default.asp in ASP-Nuke Community 1.5 and earlier allows remote attackers to gain privileges by setting certain pseudo cookie values. | EXPLOIT ✓HIGH 8.5EPSS 2.50% | 7 March 2007 |
| CVE-2006-7148 | PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter. | EXPLOIT ✓HIGH 10.0EPSS 3.42% | 7 March 2007 |
| CVE-2006-7147 | PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 4.27% | 7 March 2007 |
| CVE-2006-7146 | PHP remote file inclusion vulnerability in bug.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than CVE-2006-5280. | EXPLOIT ✓HIGH 7.5EPSS 2.25% | 7 March 2007 |
| CVE-2006-7141 | Absolute path traversal vulnerability in Oracle Database Server, when utl_file_dir is set to a wildcard value or "CREATE ANY DIRECTORY to PUBLIC" privileges exist, allows remote authenticated users to read and modify arbitrary files via full filepaths… | EXPLOIT ✓MEDIUM 6.0EPSS 5.65% | 7 March 2007 |
| CVE-2006-7139 | Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, allows remote attackers to cause a denial of service (crash) via an HTML e-mail with certain table and frameset tags that trigger a segmentation fault, possibly involving invalid free… | EXPLOIT ✓LOW 2.6EPSS 3.03% | 7 March 2007 |
| CVE-2007-1308 | ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessing the content of an iframe with an ftp:// URI in the src attribute, probably due to a NULL pointer… | EXPLOIT ✓MEDIUM 4.3EPSS 8.19% | 7 March 2007 |
| CVE-2007-1306 | Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session Initiation Protocol (SIP) packet without a URI and SIP-version header, which results in a NULL pointer dereference. | EXPLOIT ✓HIGH 7.8EPSS 20.3% | 7 March 2007 |
| CVE-2007-1303 | Directory traversal vulnerability in rb.cgi in RRDBrowse 1.6 and earlier allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 3.61% | 7 March 2007 |
| CVE-2007-1301 | Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authenticated users to execute arbitrary code via a long argument to the APPEND command. | EXPLOIT ✓HIGH 9.0EPSS 12.2% | 7 March 2007 |
| CVE-2007-1299 | PHP remote file inclusion vulnerability in index.php in Mani Stats Reader 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ipath parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.67% | 7 March 2007 |
| CVE-2007-1298 | SQL injection vulnerability in subcat.php in AJ Auction 1.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.20% | 7 March 2007 |
| CVE-2007-1297 | SQL injection vulnerability in view_profile.php in AJDating 1.0 allows remote attackers to execute arbitrary SQL commands via the user_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.97% | 7 March 2007 |
| CVE-2007-1296 | SQL injection vulnerability in postingdetails.php in AJ Classifieds 1.0 allows remote attackers to execute arbitrary SQL commands via the postingid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.04% | 7 March 2007 |
| CVE-2007-1295 | SQL injection vulnerability in topic_title.php in AJ Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the td_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.22% | 7 March 2007 |
| CVE-2007-1294 | A certain ActiveX control in the DivXBrowserPlugin (npdivx32.dll) in DivX Web Player, as distributed with DivX Player 1.3.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via large values to DivxWP.Resize, related to… | EXPLOIT ✓HIGH 7.8EPSS 3.06% | 7 March 2007 |
| CVE-2007-1293 | SQL injection vulnerability in Rigter Portal System (RPS) 6.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the categoria parameter to the top-level URI (index.php), possibly related to ver_descarga.php. | EXPLOIT ✓MEDIUM 5.8EPSS 1.14% | 7 March 2007 |
| CVE-2007-1292 | SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote authenticated users to execute arbitrary SQL commands via the postids parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.28% | 7 March 2007 |
| CVE-2007-1291 | Multiple cross-site scripting (XSS) vulnerabilities in Tyger Bug Tracking System (TygerBT) 1.1.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) Login.php and (2) Register.php. | EXPLOIT ×2 ✓MEDIUM 5.8EPSS 1.93% | 7 March 2007 |
| CVE-2007-1289 | SQL injection vulnerability in ViewBugs.php in Tyger Bug Tracking System (TygerBT) 1.1.3 allows remote attackers to execute arbitrary SQL commands via the s parameter. | EXPLOIT ✓MEDIUM 6.4EPSS 1.21% | 7 March 2007 |
| CVE-2006-7136 | Multiple PHP remote file inclusion vulnerabilities in PHP Poll Creator (phpPC) 1.04 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter to (1) poll.php, (2) poll_kommentar.php, and (3) poll_sm.php,… | EXPLOIT ✓HIGH 10.0EPSS 8.66% | 7 March 2007 |
| CVE-2006-7135 | PHP remote file inclusion vulnerability in lib/functions.inc.php in PHP Poll Creator (phpPC) 1.04 allows remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter, a different vector and version than CVE-2005-1755. | EXPLOIT ✓HIGH 7.5EPSS 2.02% | 7 March 2007 |
| CVE-2007-1287 | A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct cross-site scripting (XSS) attacks via GET, POST, or COOKIE array values, which are not escaped in the phpinfo output, as originally… | EXPLOIT ✓MEDIUM 4.3EPSS 3.17% | 6 March 2007 |
| CVE-2007-1286 | Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long string to the unserialize function, which triggers the overflow in the ZVAL reference counter. | EXPLOIT ×3 ✓MEDIUM 6.8EPSS 40.4% | 6 March 2007 |
| CVE-2007-1285 | The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines. | EXPLOIT ✓HIGH 7.5EPSS 18.2% | 6 March 2007 |
| CVE-2007-1266 | Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote… | EXPLOIT ✓MEDIUM 5.0EPSS 5.05% | 6 March 2007 |
| CVE-2007-1264 | Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote… | EXPLOIT ✓MEDIUM 5.0EPSS 4.60% | 6 March 2007 |
| CVE-2007-1263 | GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP messages with multiple components, which might allow remote attackers to forge the contents of a… | EXPLOIT ✓MEDIUM 5.0EPSS 5.36% | 6 March 2007 |
| CVE-2006-7134 | Unrestricted file upload vulnerability in main_user.php in Upload Tool for PHP 1.0 allows remote attackers to upload and execute arbitrary files with executable extensions such as .php. | EXPLOIT ✓HIGH 10.0EPSS 3.41% | 6 March 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.