Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,785 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 352 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-7133 | Directory traversal vulnerability in upload/bin/download.php in Upload Tool for PHP 1.0 allows remote attackers to read arbitrary files via (1) ".." sequences or (2) absolute pathnames in the filename parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.76% | 6 March 2007 |
| CVE-2006-7132 | Directory traversal vulnerability in pmd-config.php in PHPMyDesk 1.0beta allows remote attackers to include arbitrary local files via the pmdlang parameter to viewticket.php. | EXPLOIT ✓HIGH 10.0EPSS 3.54% | 6 March 2007 |
| CVE-2006-7131 | PHP remote file inclusion vulnerability in extras/mt.php in Jinzora 2.6 allows remote attackers to execute arbitrary PHP code via the web_root parameter. | EXPLOIT ✓HIGH 10.0EPSS 3.96% | 6 March 2007 |
| CVE-2006-7130 | PHP remote file inclusion vulnerability in backend/primitives/cache/media.php in Jinzora 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter, a different vector than CVE-2006-6770. | EXPLOIT ✓HIGH 7.5EPSS 2.84% | 6 March 2007 |
| CVE-2006-7129 | ISS BlackICE PC Protection 3.6 cpj and cpu, and possibly earlier versions, allows local users to bypass the protection scheme by using the ZwDeleteFile API function to delete the critical filelock.txt file, which stores information about protected files. | EXPLOIT ✓LOW 2.1EPSS 0.76% | 6 March 2007 |
| CVE-2006-7128 | PHP remote file inclusion vulnerability in forum/forum.php JAF CMS 4.0 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the website parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 7.38% | 6 March 2007 |
| CVE-2006-7127 | Multiple PHP remote file inclusion vulnerabilities in JAF CMS 4.0 and 4.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the main_dir parameter to (1) forum/main.php and (2) forum/headlines.php. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 5.58% | 6 March 2007 |
| CVE-2006-7120 | PHP remote file inclusion vulnerability in lib/php/phphtmllib-2.5.4/examples/example6.php for maintain 3.0.0-RC2 allows remote attackers to execute arbitrary PHP code via a URL in the phphtmllib parameter. | EXPLOIT ✓HIGH 10.0EPSS 3.56% | 6 March 2007 |
| CVE-2006-7119 | PHP remote file inclusion vulnerability in kernel/system/startup.php in J. | EXPLOIT ✓HIGH 7.5EPSS 2.30% | 6 March 2007 |
| CVE-2006-7118 | SQL injection vulnerability in index.asp in DMXReady Site Engine Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the mid parameter. | EXPLOIT ✓HIGH 7.5EPSS 0.97% | 6 March 2007 |
| CVE-2006-7117 | Multiple directory traversal vulnerabilities in Kubix 0.7 and earlier allow remote attackers to (1) include and execute arbitrary local files via ".." sequences in the theme cookie to index.php, which is not properly handled by includes/head.php; and… | EXPLOIT ✓MEDIUM 6.8EPSS 1.93% | 6 March 2007 |
| CVE-2006-7116 | SQL injection vulnerability in includes/functions.php in Kubix 0.7 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the member_id parameter ($id variable) to index.php. | EXPLOIT ✓HIGH 7.5EPSS 1.12% | 6 March 2007 |
| CVE-2006-7114 | P-News 2.0 stores db/user.txt under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and password hashes via a direct request. | EXPLOIT ✓MEDIUM 5.0EPSS 2.42% | 6 March 2007 |
| CVE-2006-7112 | Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demonstrated by uploading a GIF image using AddDownload or injecting PHP code… | EXPLOIT ✓MEDIUM 6.0EPSS 1.61% | 6 March 2007 |
| CVE-2007-1277 | WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix… | EXPLOIT ×2 ✓HIGH 7.5EPSS 27.0% | 5 March 2007 |
| CVE-2007-0774 | Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary… | EXPLOIT ×2 ✓HIGH 7.5EPSS 81.5% | 4 March 2007 |
| CVE-2007-1260 | Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execute arbitrary code via a long string in the Content-Length HTTP header. | EXPLOIT ✓HIGH 7.5EPSS 5.36% | 3 March 2007 |
| CVE-2006-7107 | PHP remote file inclusion vulnerability in upgrade.php in Coalescent Systems freePBX 2.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the amp_conf[AMPWEBROOT] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.31% | 3 March 2007 |
| CVE-2006-7106 | PHP remote file inclusion vulnerability in config.inc.php3 in Power Phlogger 2.0.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rel_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.27% | 3 March 2007 |
| CVE-2006-7104 | PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a component for Mambo 4.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the… | EXPLOIT ✓HIGH 7.5EPSS 2.28% | 3 March 2007 |
| CVE-2006-7102 | Multiple PHP remote file inclusion vulnerabilities in phpBurningPortal quiz-modul 1.0.1, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the lang_path parameter to (1) quest_delete.php, (2) quest_edit.php, or (3)… | EXPLOIT ✓HIGH 7.5EPSS 2.27% | 3 March 2007 |
| CVE-2006-7101 | SQL injection vulnerability in admin.php in PHPWind 5.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the AdminUser cookie. | EXPLOIT ✓HIGH 7.5EPSS 1.00% | 3 March 2007 |
| CVE-2006-7100 | PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Insert User 0.1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.03% | 3 March 2007 |
| CVE-2007-1255 | Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticated administrators to execute arbitrary PHP code by uploading a crafted GIF smiley image with a .php extension via the uploadimage… | EXPLOIT ✓MEDIUM 6.0EPSS 0.87% | 3 March 2007 |
| CVE-2007-1254 | SQL injection vulnerability in part.userprofile.php in Connectix Boards 0.7 and earlier allows remote authenticated users to execute arbitrary SQL commands and obtain privileges via the p_skin parameter to index.php. | EXPLOIT ✓MEDIUM 6.5EPSS 0.95% | 3 March 2007 |
| CVE-2007-1251 | Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0, when EVENTLOG is enabled, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers… | EXPLOIT ✓HIGH 9.3EPSS 6.46% | 3 March 2007 |
| CVE-2007-1250 | SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.97% | 3 March 2007 |
| CVE-2007-1248 | Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) uid, and (3) nid parameters to (a) news.php, and the nid parameter to (b) rating.php. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.77% | 3 March 2007 |
| CVE-2007-1247 | Multiple PHP remote file inclusion vulnerabilities in aWeb Labs aWebNews 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the path_to_news parameter to (1) listing.php or (2) visview.php. | EXPLOIT ✓MEDIUM 6.8EPSS 3.37% | 3 March 2007 |
| CVE-2007-1244 | Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. | EXPLOIT ✓MEDIUM 6.8EPSS 7.32% | 3 March 2007 |
| CVE-2007-1243 | Audins Audiens 3.3 allows remote attackers to bypass authentication and perform certain privileged actions, possibly an uninstall of the product, by calling unistall.php with the values cnf=disinstalla and status=on. | EXPLOIT ✓HIGH 7.5EPSS 2.48% | 3 March 2007 |
| CVE-2007-1242 | SQL injection vulnerability in system/index.php in Audins Audiens 3.3 allows remote attackers to execute arbitrary SQL commands via the PHPSESSID cookie. | EXPLOIT ✓HIGH 7.5EPSS 0.98% | 3 March 2007 |
| CVE-2007-1241 | Cross-site scripting (XSS) vulnerability in setup.php in Audins Audiens 3.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | EXPLOIT ✓MEDIUM 5.8EPSS 1.55% | 3 March 2007 |
| CVE-2007-1240 | Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS 3.0.3 through 3.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the searchkey parameter to index.php, or the (2) sn or (3) ri parameter to… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 3.02% | 3 March 2007 |
| CVE-2007-1233 | PHP remote file inclusion vulnerability in downloadcounter.php in STWC-Counter 3.4.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the stwc_counter_verzeichniss parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.27% | 3 March 2007 |
| CVE-2007-1232 | Directory traversal vulnerability in SQLiteManager 1.2.0 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.1EPSS 37.5% | 3 March 2007 |
| CVE-2007-1231 | Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) database name, (2) table name, (3) ViewName, (4) view, (5) trigger, and (6) function fields in main.php… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.54% | 3 March 2007 |
| CVE-2006-7099 | Directory traversal vulnerability in index.php in SolarPay allows remote attackers to read certain files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.40% | 3 March 2007 |
| CVE-2006-7098 | The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program… | EXPLOIT ✓MEDIUM 6.6EPSS 0.56% | 3 March 2007 |
| CVE-2007-1229 | Cross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the top-level URI on the Incoming interface (port 8001/tcp), which is not properly handled in the… | EXPLOIT ✓MEDIUM 4.3EPSS 1.77% | 2 March 2007 |
| CVE-2007-1227 | VShieldCheck in McAfee VirusScan for Mac (Virex) before 7.7 patch 1 allow local users to change permissions of arbitrary files via a symlink attack on /Library/Application Support/Virex/VShieldExclude.txt, as demonstrated by symlinking to the root… | EXPLOIT ✓MEDIUM 6.6EPSS 0.76% | 2 March 2007 |
| CVE-2007-1225 | The connection log file implementation in Grok Developments NetProxy 4.03 does not record requests that omit http:// in a URL, which might allow remote attackers to conduct unauthorized activities and avoid detection. | EXPLOIT ✓HIGH 10.0EPSS 3.79% | 2 March 2007 |
| CVE-2007-1224 | Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from the URL and specifies the destination port (:80). | EXPLOIT ✓MEDIUM 5.0EPSS 2.63% | 2 March 2007 |
| CVE-2007-1219 | PHP remote file inclusion vulnerability in actions/del.php in Admin Phorum 3.3.1a allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.69% | 2 March 2007 |
| CVE-2007-1199 | Adobe Reader and Acrobat Trial allow remote attackers to read arbitrary files via a file:// URI in a PDF document, as demonstrated with <</URI(file:///C:/)/S/URI>>, a different issue than CVE-2007-0045. | EXPLOIT ✓MEDIUM 4.3EPSS 9.10% | 2 March 2007 |
| CVE-2007-1195 | Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unspecified vectors. | EXPLOIT ×2 ✓HIGH 7.5EPSS 4.98% | 2 March 2007 |
| CVE-2007-1192 | Pasawicz HyperBook Guestbook 1.30 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an admin password hash via a direct request for data/gbconfiguration.dat. | EXPLOIT ✓MEDIUM 5.0EPSS 2.46% | 2 March 2007 |
| CVE-2007-1190 | Unspecified vulnerability in the EmbeddedWB Web Browser ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors. | EXPLOIT ✓MEDIUM 6.8EPSS 2.98% | 2 March 2007 |
| CVE-2007-1189 | Integer overflow in the envwrite function in the Alcatel-Lucent Bell Labs Plan 9 kernel allows local users to overwrite certain memory addresses with kernel memory via a large n argument, as demonstrated by (1) modifying the iseve function to gain… | EXPLOIT ✓HIGH 7.2EPSS 0.77% | 2 March 2007 |
| CVE-2007-1172 | SQL injection vulnerability in nukesentinel.php in NukeSentinel 2.5.05, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, aka the "File Disclosure Exploit." | EXPLOIT ✓MEDIUM 6.4EPSS 1.09% | 2 March 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.