SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,785 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026

25,049 results · page 355 of 501

CVESummaryPriorityPublished
CVE-2007-1010Multiple PHP remote file inclusion vulnerabilities in ZebraFeeds 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the zf_path parameter to (1) aggregator.php and (2) controller.php in…EXPLOIT ✓MEDIUM 6.8EPSS 7.44%21 February 2007
CVE-2007-0325Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7.0 before Build 1344, OfficeScan 7.3 before Build 1241, and Client / Server / Messaging Security 3.0…EXPLOIT ✓HIGH 9.3EPSS 35.4%20 February 2007
CVE-2007-1008Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted XML list of radio stations, which results in memory corruption.EXPLOIT ✓LOW 2.6EPSS 2.25%20 February 2007
CVE-2006-5276Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrary code via crafted SMB traffic.EXPLOIT ×4 ✓HIGH 10.0EPSS 79.4%20 February 2007
CVE-2007-0710The Bonjour functionality in iChat in Apple Mac OS X 10.3.9 allows remote attackers to cause a denial of service (persistent application crash) via unspecified vectors, possibly related to CVE-2007-0614.EXPLOIT ✓LOW 2.1EPSS 3.37%16 February 2007
CVE-2007-0987Directory traversal vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 3.09%16 February 2007
CVE-2007-0986PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remote attackers to execute arbitrary PHP code via an ftp URL in the n parameter.EXPLOIT ✓MEDIUM 5.1EPSS 3.35%16 February 2007
CVE-2007-0985SQL injection vulnerability in nickpage.php in phpCC 4.2 beta and earlier allows remote attackers to execute arbitrary SQL commands via the npid parameter in a sign_gb action.EXPLOIT ✓HIGH 7.5EPSS 1.04%16 February 2007
CVE-2007-0984SQL injection vulnerability in admin_poll.asp in PollMentor 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to pollmentorres.asp.EXPLOIT ✓HIGH 7.5EPSS 1.21%16 February 2007
CVE-2007-0983PHP remote file inclusion vulnerability in _admin/nav.php in AT Contenator 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the Root_To_Script parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.85%16 February 2007
CVE-2007-0982Cross-site scripting (XSS) vulnerability in error.php in TaskFreak!EXPLOIT ✓MEDIUM 4.3EPSS 1.57%16 February 2007
CVE-2007-0981Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the…EXPLOIT ✓HIGH 7.5EPSS 12.5%16 February 2007
CVE-2007-0977IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible through Readviewentries and OpenDocument requests to the defaultview view, a different vector than…EXPLOIT ✓HIGH 7.1EPSS 19.9%16 February 2007
CVE-2007-0976Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary code via a long DVD_TOOLS.OpenDVD property value.EXPLOIT ×3 ✓HIGH 10.0EPSS 8.86%16 February 2007
CVE-2007-0972Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload arbitrary files by modifying the HTTP request to send an image content type, and to omit is_guest and is_user parameters.EXPLOIT ✓HIGH 7.5EPSS 3.33%16 February 2007
CVE-2007-0971Multiple SQL injection vulnerabilities in Jupiter CMS 1.1.5 allow remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header and certain other HTTP headers, which set the ip variable that is used in SQL queries performed by…EXPLOIT ✓HIGH 7.5EPSS 1.28%16 February 2007
CVE-2007-0970Multiple SQL injection vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to execute arbitrary SQL commands via the testID parameter to directions.php, and unspecified parameters to other files that accept GET or POST input.EXPLOIT ✓HIGH 7.5EPSS 1.80%16 February 2007
CVE-2007-0955The NTLM_UnPack_Type3 function in MENTLM.dll in MailEnable Professional 2.35 and earlier allows remote attackers to cause a denial of service (application crash) via certain base64-encoded data following an AUTHENTICATE NTLM command to the imap port…EXPLOIT ×2 ✓HIGH 7.8EPSS 5.50%15 February 2007
CVE-2007-0951SQL injection vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to execute arbitrary SQL commands via the cat parameter.EXPLOIT ✓HIGH 7.5EPSS 1.08%15 February 2007
CVE-2007-0950Cross-site scripting (XSS) vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to inject arbitrary web script or HTML via the cat parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.85%15 February 2007
CVE-2007-0949Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers to execute arbitrary code via a M3U playlist file that contains a long file name.EXPLOIT ×2 ✓HIGH 10.0EPSS 16.4%15 February 2007
CVE-2006-7024Multiple PHP remote file inclusion vulnerabilities in Harpia CMS 1.0.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) func_prog parameter to (a) preload.php and (b) index.php; (2) header_prog parameter to (c)…EXPLOIT ✓HIGH 7.5EPSS 2.33%15 February 2007
CVE-2006-7021PHP remote file inclusion vulnerability in manager/tools/link/dbinstall.php in Plume CMS 1.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the _PX_config[manager_path] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.65%15 February 2007
CVE-2006-7017Multiple PHP remote file inclusion vulnerabilities in Indexu 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the admin_template_path parameter to admin/ scripts (1) app_change_email.php, (2) app_change_pwd.php, (3)…EXPLOIT ✓HIGH 7.5EPSS 2.76%15 February 2007
CVE-2006-7012scart.cgi in SCart 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter of a show_text action.EXPLOIT ✓HIGH 10.0EPSS 5.16%15 February 2007
CVE-2007-0927Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a crafted announce header.EXPLOIT ✓HIGH 7.5EPSS 45.0%14 February 2007
CVE-2007-0925Cross-site scripting (XSS) vulnerability in search/SearchResults.aspx in Community Server allows remote attackers to inject arbitrary web script or HTML via the q parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.62%14 February 2007
CVE-2007-0920SQL injection vulnerability in philboard_forum.asp in Philboard 1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.09%14 February 2007
CVE-2007-0919Directory traversal vulnerability in Nickolas Grigoriadis Mini Web server (MiniWebsvr) 0.0.6 allows remote attackers to list the directory immediately above the web root via a ..%00 sequence in the URI.EXPLOIT ×2 ✓HIGH 7.8EPSS 3.76%14 February 2007
CVE-2007-0911Off-by-one error in the str_ireplace function in PHP 5.2.1 might allow context-dependent attackers to cause a denial of service (crash).EXPLOIT ✓HIGH 7.8EPSS 5.48%13 February 2007
CVE-2007-0908The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows context-dependent attackers to read stack memory via a wddxPacket element…EXPLOIT ✓MEDIUM 5.0EPSS 12.2%13 February 2007
CVE-2007-0217The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which…EXPLOIT ✓HIGH 10.0EPSS 58.4%13 February 2007
CVE-2007-0904SQL injection vulnerability in projects.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.08%13 February 2007
CVE-2007-0900Multiple PHP remote file inclusion vulnerabilities in TagIt!EXPLOIT ×16 ✓HIGH 7.5EPSS 10.3%13 February 2007
CVE-2007-0896Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability…EXPLOIT ✓MEDIUM 4.3EPSS 1.94%13 February 2007
CVE-2007-0890Cross-site scripting (XSS) vulnerability in scripts/passwdmysql in cPanel WebHost Manager (WHM) 11.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the password parameter.EXPLOIT ✓MEDIUM 4.3EPSS 1.82%12 February 2007
CVE-2007-0888Directory traversal vulnerability in the TFTP server in Kiwi CatTools before 3.2.0 beta allows remote attackers to read arbitrary files, and upload files to arbitrary locations, via ..// (dot dot) sequences in the pathname argument to an FTP (1) GET or…EXPLOIT ✓HIGH 10.0EPSS 5.13%12 February 2007
CVE-2007-0887axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a base64-encoded "*\x00" sequence on the imap port (143/tcp).EXPLOIT ✓HIGH 7.8EPSS 10.4%12 February 2007
CVE-2007-0886Heap-based buffer underflow in axigen 1.2.6 through 2.0.0b1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via certain base64-encoded data on the pop3 port (110/tcp), which triggers an…EXPLOIT ✓HIGH 10.0EPSS 8.74%12 February 2007
CVE-2006-7007Buffer overflow in Tiny FTPd 1.4 and earlier allows remote attackers to cause a denial of service (daemon crash) via a long USER command, a different vector than CVE-2000-0133.EXPLOIT ✓HIGH 7.8EPSS 3.81%12 February 2007
CVE-2006-7005SQL injection vulnerability in item.php in PSY Auction allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 0.97%12 February 2007
CVE-2006-7004Cross-site scripting (XSS) vulnerability in email_request.php in PSY Auction allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.76%12 February 2007
CVE-2007-0885Cross-site scripting (XSS) vulnerability in jira/secure/BrowseProject.jspa in Rainbow with the Zen (Rainbow.Zen) extension allows remote attackers to inject arbitrary web script or HTML via the id parameter.EXPLOIT ✓MEDIUM 6.8EPSS 5.75%12 February 2007
CVE-2007-0883Directory traversal vulnerability in portalgroups/portalgroups/getfile.cgi in IP3 NetAccess before firmware 4.1.9.6 allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 4.35%12 February 2007
CVE-2007-0882Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to…EXPLOIT ×3 ✓HIGH 10.0EPSS 98.0%12 February 2007
CVE-2007-0881PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the (1) config[oi_dir] and possibly (2) config[openi_dir] parameters to…EXPLOIT ✓MEDIUM 6.8EPSS 2.90%12 February 2007
CVE-2007-0873nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) config_edit.php, (2) template_edit.php, or (3) survey_edit.php in admin/.EXPLOIT ✓HIGH 7.5EPSS 8.04%12 February 2007
CVE-2007-0872Directory traversal vulnerability in the Plain Old Webserver (POW) add-on before 0.0.9 for Mozilla Firefox allows remote attackers to read arbitrary files via a ..EXPLOIT ✓MEDIUM 5.0EPSS 3.60%12 February 2007
CVE-2007-0871Unrestricted file upload vulnerability in eXtremePow eXtreme File Hosting allows remote attackers to upload arbitrary PHP code via a filename with a double extension such as (1) .rar.php or (2) .zip.php.EXPLOIT ✓HIGH 7.5EPSS 3.00%12 February 2007
CVE-2006-6995mycontacts.php in V3 Chat allows remote authenticated users to gain privileges as other users via a modified membername parameter.EXPLOIT ✓MEDIUM 6.0EPSS 1.62%12 February 2007

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.