SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,785 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026

25,049 results · page 354 of 501

CVESummaryPriorityPublished
CVE-2006-7055PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922.EXPLOIT ✓MEDIUM 6.8EPSS 5.60%24 February 2007
CVE-2006-7052Multiple PHP remote file inclusion vulnerabilities in DotWidget For Articles (dotwidgeta) 0.2 allow remote attackers to execute arbitrary code via a URL in the (1) file_path parameter to (a) index.php, (b) showcatpicks.php, and (c) showarticle.php; and…EXPLOIT ×7 ✓HIGH 10.0EPSS 6.39%24 February 2007
CVE-2006-7051The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (memory consumption) and possibly bypass memory limits or cause other processes to be killed by creating a large number of posix…EXPLOIT ✓MEDIUM 4.9EPSS 0.93%24 February 2007
CVE-2006-7048Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarolineRepositorySys parameter to (a) atutor.inc.php (b) db-generic.inc.php (c) docebo.inc.php (d)…EXPLOIT ✓HIGH 7.5EPSS 3.94%24 February 2007
CVE-2006-7042Cross-site scripting (XSS) vulnerability in directory/index.php in Chipmunk directory allows remote attackers to inject arbitrary web script or HTML via the start parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.78%24 February 2007
CVE-2007-1085Cross-site scripting (XSS) vulnerability in Google Desktop allows remote attackers to bypass protection schemes and inject arbitrary web script or HTML, and possibly gain full access to the system, by using an XSS vulnerability in google.com to extract…EXPLOIT ✓HIGH 7.6EPSS 11.1%23 February 2007
CVE-2006-7032PHP remote file inclusion vulnerability in phpbb/getmsg.php in FlashBB 1.1.5 and earlier allows remote attackers to execute arbitrary code via a URL in the phpbb_root_path parameter.EXPLOIT ✓HIGH 10.0EPSS 6.19%23 February 2007
CVE-2006-7031Microsoft Internet Explorer 6.0.2900 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a table element with a CSS attribute that sets the position, which triggers an "unhandled exception" in mshtml.dll.EXPLOIT ✓MEDIUM 6.5EPSS 18.3%23 February 2007
CVE-2006-7026PHP remote file inclusion vulnerability in sources/join.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[path] parameter, a different vector…EXPLOIT ✓MEDIUM 6.8EPSS 4.33%23 February 2007
CVE-2007-0843The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using…EXPLOIT ✓MEDIUM 4.6EPSS 3.39%23 February 2007
CVE-2007-1082FTP Explorer 1.0.1 Build 047, and other versions before 1.0.1.52, allows remote servers to cause a denial of service (CPU consumption) via a long response to a PWD command.EXPLOIT ✓HIGH 7.1EPSS 2.51%22 February 2007
CVE-2007-1080Multiple heap-based buffer overflows in TurboFTP 5.30 Build 572 allow remote servers to cause a denial of service via (1) long filename in a response to a LIST command, and (2) a long response to a CWD command.EXPLOIT ✓HIGH 7.8EPSS 3.72%22 February 2007
CVE-2007-1079Stack-based buffer overflow in Rhino Software, Inc.EXPLOIT ✓HIGH 7.8EPSS 3.06%22 February 2007
CVE-2007-1078PHP remote file inclusion vulnerability in index.php in FlashGameScript 1.5.4 allows remote attackers to execute arbitrary PHP code via a URL in the func parameter.EXPLOIT ✓HIGH 7.5EPSS 3.29%22 February 2007
CVE-2007-1077SQL injection vulnerability in page.asp in Design4Online UserPages2 2.0 allows remote attackers to execute arbitrary SQL commands via the art_id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%22 February 2007
CVE-2007-1076Multiple directory traversal vulnerabilities in phpTrafficA 1.4.1, and possibly earlier, allow remote attackers to include arbitrary local files via a ..EXPLOIT ×2 ✓HIGH 7.5EPSS 4.18%22 February 2007
CVE-2007-1075TurboFTP 5.30 Build 572 allows remote servers to cause a denial of service (CPU consumption) via a response with a large number of newline characters.EXPLOIT ✓HIGH 7.8EPSS 3.05%22 February 2007
CVE-2007-1074Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long (1) DataPath or (2) DownloadPath attributed in a (a) NBI file, or (3) a long group field in a (b) NZB file.EXPLOIT ✓HIGH 9.3EPSS 7.48%22 February 2007
CVE-2007-1071Integer overflow in the gifGetBandProc function in ImageIO in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image that triggers the overflow during…EXPLOIT ✓HIGH 7.8EPSS 18.4%22 February 2007
CVE-2007-1061SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header (HTTP_REFERER variable).EXPLOIT ×3 ✓MEDIUM 6.8EPSS 61.8%22 February 2007
CVE-2007-1060Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl are enabled, allow remote attackers to execute arbitrary PHP code via a URL in the ROOTDIR parameter to (1)…EXPLOIT ✓MEDIUM 6.8EPSS 7.96%22 February 2007
CVE-2007-1059PHP remote file inclusion vulnerability in function.php in Ultimate Fun Book 1.02 allows remote attackers to execute arbitrary PHP code via a URL in the gbpfad parameter.EXPLOIT ✓MEDIUM 6.8EPSS 3.10%22 February 2007
CVE-2007-1058SQL injection vulnerability in user_pages/page.asp in Online Web Building 2.0 allows remote attackers to execute arbitrary SQL commands via the art_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.27%21 February 2007
CVE-2007-1057The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 1000 extracts and executes files with insecure permissions, which allows local users to exploit a race condition to replace a…EXPLOIT ✓MEDIUM 6.9EPSS 1.11%21 February 2007
CVE-2007-1050Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inject arbitrary web script or HTML via (1) the go parameter, (2) the keyword parameter in the search menu (go=search), or (3) the…EXPLOIT ✓MEDIUM 4.3EPSS 5.09%21 February 2007
CVE-2007-1049Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via…EXPLOIT ✓MEDIUM 4.3EPSS 6.47%21 February 2007
CVE-2007-1044Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in ".js." NOTE: it was later reported that this issue had been…EXPLOIT ✓MEDIUM 5.0EPSS 8.80%21 February 2007
CVE-2007-1043Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config.php.EXPLOIT ✓HIGH 7.5EPSS 8.35%21 February 2007
CVE-2007-1041Multiple stack-based buffer overflows in S&H Computer Systems News Rover 12.1 Rev 1 allow remote attackers to execute arbitrary code via a .nzb file with a long (1) group or (2) subject string.EXPLOIT ×2 ✓HIGH 9.3EPSS 6.95%21 February 2007
CVE-2007-1040Directory traversal vulnerability in archives.php in Xpression News (X-News) 1.0.1 allows remote attackers to include arbitrary files or obtain sensitive information via a ..EXPLOIT ✓HIGH 7.5EPSS 3.13%21 February 2007
CVE-2007-1037Stack-based buffer overflow in News File Grabber 4.1.0.1 and earlier allows remote attackers to execute arbitrary code via a .nzb file with a long subject field.EXPLOIT ×2 ✓HIGH 9.3EPSS 5.58%21 February 2007
CVE-2007-1070Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitrary code via crafted RPC requests to TmRpcSrv.dll that trigger overflows…EXPLOIT ×2 ✓HIGH 10.0EPSS 73.0%21 February 2007
CVE-2007-1036The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.EXPLOIT ×2 ✓HIGH 7.5EPSS 82.3%21 February 2007
CVE-2007-1034SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category_id parameter.EXPLOIT ×2 ✓HIGH 7.5EPSS 1.58%21 February 2007
CVE-2007-1031Directory traversal vulnerability in include/db_conn.php in SpoonLabs Vivvo Article Management CMS 3.4 allows remote attackers to include and execute arbitrary local files via the root parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.02%21 February 2007
CVE-2007-1029Stack-based buffer overflow in the Connect method in the IMAP4 component in Quiksoft EasyMail Objects before 6.5 allows remote attackers to execute arbitrary code via a long host name.EXPLOIT ✓HIGH 7.6EPSS 7.50%21 February 2007
CVE-2007-1026SQL injection vulnerability in view.php in XLAtunes 0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in view mode.EXPLOIT ✓HIGH 7.5EPSS 1.79%21 February 2007
CVE-2007-1025PHP remote file inclusion vulnerability in inc/functions_inc.php in VS-Link-Partner 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gb_pfad, or possibly script_pfad, parameter.EXPLOIT ✓HIGH 7.5EPSS 2.72%21 February 2007
CVE-2007-1024PHP remote file inclusion vulnerability in include.php in Meganoide's news 1.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter.EXPLOIT ✓HIGH 10.0EPSS 4.95%21 February 2007
CVE-2007-1023SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.06%21 February 2007
CVE-2007-1022SQL injection vulnerability in h_goster.asp in Turuncu Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.03%21 February 2007
CVE-2007-1021SQL injection vulnerability in inc_listnews.asp in CodeAvalanche News 1.x allows remote attackers to execute arbitrary SQL commands via the CAT_ID parameter.EXPLOIT ✓HIGH 10.0EPSS 1.66%21 February 2007
CVE-2007-1020Cross-site scripting (XSS) vulnerability in index.php in CedStat 1.31 allows remote attackers to inject arbitrary web script or HTML via the hier parameter.EXPLOIT ×2 ✓MEDIUM 6.8EPSS 4.97%21 February 2007
CVE-2007-1019SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the showonly parameter to index.php, a different vector than CVE-2006-5388.EXPLOIT ✓MEDIUM 6.8EPSS 1.19%21 February 2007
CVE-2007-1017PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the newsordner parameter.EXPLOIT ✓HIGH 9.3EPSS 4.21%21 February 2007
CVE-2007-1016SQL injection vulnerability in Aktueldownload Haber script allows remote attackers to execute arbitrary SQL commands via certain vectors related to the HaberDetay.asp and rss.asp components, and the id and kid parameters.EXPLOIT ✓HIGH 7.5EPSS 0.96%21 February 2007
CVE-2007-1015SQL injection vulnerability in HaberDetay.asp in Aktueldownload Haber script allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 10.0EPSS 3.17%21 February 2007
CVE-2007-1014Stack-based buffer overflow in VicFTPS before 5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long CWD command.EXPLOIT ✓HIGH 10.0EPSS 9.35%21 February 2007
CVE-2007-1013PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the ht_pfad parameter.EXPLOIT ✓HIGH 10.0EPSS 4.83%21 February 2007
CVE-2007-1011PHP remote file inclusion vulnerability in functions_inc.php in VS-Gastebuch 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gb_pfad parameter.EXPLOIT ✓HIGH 7.5EPSS 3.36%21 February 2007

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.