Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,785 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 353 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-1171 | SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 allows remote attackers to execute arbitrary SQL commands via an admin cookie. | EXPLOIT ✓HIGH 7.5EPSS 2.12% | 2 March 2007 |
| CVE-2007-1167 | inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and earlier allows remote attackers to obtain MySQL data via the inc/mysql.php value of the file parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 4.05% | 2 March 2007 |
| CVE-2007-1166 | SQL injection vulnerability in result.php in Nabopoll 1.2 allows remote attackers to execute arbitrary SQL commands via the surv parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.21% | 2 March 2007 |
| CVE-2007-1165 | Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the dbs_base_path parameter to (1) utils.php, (2) guestbook.php, or (3) views.php in includes/. | EXPLOIT ✓HIGH 7.5EPSS 3.17% | 2 March 2007 |
| CVE-2007-1164 | Multiple PHP remote file inclusion vulnerabilities in DBImageGallery 1.2.2 allow remote attackers to execute arbitrary PHP code via a URL in the donsimg_base_path parameter to (1) attributes.php, (2) images.php, or (3) scan.php in admin/; or (4)… | EXPLOIT ✓HIGH 7.5EPSS 9.40% | 2 March 2007 |
| CVE-2007-1163 | SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019, CVE-2006-5388, and CVE-2006-4783. | EXPLOIT ✓HIGH 7.5EPSS 1.08% | 2 March 2007 |
| CVE-2007-1162 | A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) IsFolderAvailable or (2) RootFolder… | EXPLOIT ✓HIGH 7.8EPSS 3.22% | 2 March 2007 |
| CVE-2007-1159 | Cross-site scripting (XSS) vulnerability in modules/out.php in Pyrophobia 2.1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.25% | 2 March 2007 |
| CVE-2007-1158 | Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 4.45% | 2 March 2007 |
| CVE-2007-1156 | JBrowser allows remote attackers to bypass authentication and access certain administrative capabilities via a direct request for _admin/. | EXPLOIT ✓HIGH 7.5EPSS 9.01% | 2 March 2007 |
| CVE-2007-1152 | Multiple directory traversal vulnerabilities in Pyrophobia 2.1.3.1 allow remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.87% | 2 March 2007 |
| CVE-2007-1151 | Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter to the top-level URI, possibly related to a SQL error. | EXPLOIT ✓MEDIUM 4.3EPSS 1.58% | 2 March 2007 |
| CVE-2007-1149 | Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 3.70% | 2 March 2007 |
| CVE-2007-1148 | PHP remote file inclusion vulnerability in install/index.php in LoveCMS 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the step parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.71% | 2 March 2007 |
| CVE-2007-1142 | Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the link_parameters parameter in (1) news.php and (2) n_layouts.php. | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 1.60% | 2 March 2007 |
| CVE-2007-1141 | PHP remote file inclusion vulnerability in preview.php in Magic News Plus 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the php_script_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 5.79% | 2 March 2007 |
| CVE-2007-1140 | Directory traversal vulnerability in edit.php in pheap allows remote attackers to read and modify arbitrary files via a .. | EXPLOIT ✓HIGH 9.4EPSS 3.11% | 2 March 2007 |
| CVE-2007-1138 | Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.65% | 2 March 2007 |
| CVE-2007-0001 | The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the… | EXPLOIT ✓MEDIUM 4.7EPSS 0.60% | 2 March 2007 |
| CVE-2006-7091 | PHP remote file inclusion vulnerability in config.php in phpht Topsites FREE 1.022b allows remote attackers to execute arbitrary PHP code via a URL in the fullpath parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.15% | 2 March 2007 |
| CVE-2006-7086 | The (1) dlback.php and (2) dlback.cgi scripts in Hot Links allow remote attackers to obtain sensitive information and download the database via a direct request with a modified dl parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 3.51% | 2 March 2007 |
| CVE-2006-7081 | Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code via the Include parameter to (1) Include/lib.inc.php3 and (2) Include/variables.php3. | EXPLOIT ✓HIGH 7.5EPSS 2.68% | 2 March 2007 |
| CVE-2006-7080 | Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 4.72% | 2 March 2007 |
| CVE-2006-7079 | Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute arbitrary code by modifying the… | EXPLOIT ✓CRITICAL 9.8EPSS 12.9% | 2 March 2007 |
| CVE-2006-7072 | Cross-site scripting (XSS) vulnerability in GeoClassifieds Enterprise 2.0.5.2 and earlier allows remote attackers to inject arbitrary web script and HTML via the (1) b[username] and (2) c parameters to (a) index.php, the b[username] parameter to (b)… | EXPLOIT ✓MEDIUM 4.3EPSS 2.29% | 2 March 2007 |
| CVE-2006-7071 | SQL injection vulnerability in classes/class_session.php in Invision Power Board (IPB) 2.1 up to 2.1.6 allows remote attackers to execute arbitrary SQL commands via the CLIENT_IP parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.34% | 2 March 2007 |
| CVE-2006-7070 | Unrestricted file upload vulnerability in manager/media/ibrowser/scripts/rfiles.php in Etomite CMS 0.6.1 and earlier allows remote attackers to upload and execute arbitrary files via an nfile[] parameter with a filename that contains a .php extension… | EXPLOIT ✓HIGH 7.5EPSS 4.02% | 2 March 2007 |
| CVE-2006-7069 | PHP remote file inclusion vulnerability in smarty_config.php in Socketwiz Bookmarks 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the root_dir parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.68% | 2 March 2007 |
| CVE-2006-7068 | PHP remote file inclusion vulnerability in CliServ Web Community 0.65 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cl_headers parameter to (1) menu.php3 and (2) login.php3. | EXPLOIT ✓HIGH 7.5EPSS 6.10% | 2 March 2007 |
| CVE-2006-7066 | Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating an object inside an iframe, deleting the frame by setting its location.href to about:blank, then accessing a property of the object… | EXPLOIT ✓HIGH 7.1EPSS 22.2% | 2 March 2007 |
| CVE-2006-7065 | Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet that triggers a crash in mshtml.dll when a refresh is called, probably a null pointer dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 20.9% | 2 March 2007 |
| CVE-2007-1133 | PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_fuss parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.22% | 27 February 2007 |
| CVE-2007-1131 | PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.73% | 27 February 2007 |
| CVE-2007-1130 | PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.73% | 27 February 2007 |
| CVE-2007-1127 | Directory traversal vulnerability in enc/stylecss.php in shopkitplus allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.4EPSS 3.05% | 27 February 2007 |
| CVE-2007-1126 | Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 5.64% | 27 February 2007 |
| CVE-2007-1125 | Cross-site scripting (XSS) vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to inject arbitrary web script or HTML via the f parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.89% | 27 February 2007 |
| CVE-2007-1124 | Directory traversal vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 2.90% | 27 February 2007 |
| CVE-2007-1118 | Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path_to_smf parameter to (1) bridges/SMF/logout.php or (2) get_session_vars.php. | EXPLOIT ✓MEDIUM 6.8EPSS 3.30% | 27 February 2007 |
| CVE-2007-1111 | Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6)… | EXPLOIT ×8 ✓MEDIUM 6.8EPSS 6.09% | 26 February 2007 |
| CVE-2007-1110 | Directory traversal vulnerability in data/showcode.php in ActiveCalendar 1.2.0 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 3.55% | 26 February 2007 |
| CVE-2007-1108 | PHP remote file inclusion vulnerability in index.php in Christian Schneider CS-Gallery 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the album parameter during a securealbum todo action. | EXPLOIT ✓MEDIUM 6.8EPSS 2.81% | 26 February 2007 |
| CVE-2007-1107 | SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users to execute arbitrary SQL commands via a cpg131_fav cookie. | EXPLOIT ✓HIGH 7.5EPSS 2.19% | 26 February 2007 |
| CVE-2007-1106 | PHP remote file inclusion vulnerability in includes/functions_nomoketos_rules.php in the NoMoKeTos Rules 0.0.1 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.70% | 26 February 2007 |
| CVE-2007-1105 | PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka phpBB Extreme) 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 2.43% | 26 February 2007 |
| CVE-2007-1104 | PHP remote file inclusion vulnerability in top.php in PHP Module Implementation (PHP-MIP) 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the laypath parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 2.37% | 26 February 2007 |
| CVE-2007-1101 | Multiple cross-site scripting (XSS) vulnerabilities in Photostand 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) message ("comment") or (2) name field, or the (3) q parameter in a search action in index.php. | EXPLOIT ✓MEDIUM 4.3EPSS 1.98% | 26 February 2007 |
| CVE-2007-1100 | Directory traversal vulnerability in download.php in Ahmet Sacan Pickle before 20070301 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 3.70% | 26 February 2007 |
| CVE-2007-1090 | Microsoft Windows Explorer on Windows XP and 2003 allows remote user-assisted attackers to cause a denial of service (crash) via a malformed WMF file, which triggers the crash when the user browses the folder. | EXPLOIT ✓HIGH 7.1EPSS 17.2% | 26 February 2007 |
| CVE-2006-7063 | Directory traversal vulnerability in profile.php in TinyPHPforum 3.6 and earlier allows remote attackers to include and execute arbitrary files via ".." sequences in the uname parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.40% | 24 February 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.