SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,833 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026

25,049 results · page 356 of 501

CVESummaryPriorityPublished
CVE-2007-0867PHP remote file inclusion vulnerability in classes/menu.php in Site-Assistant 0990 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the paths[version] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.84%9 February 2007
CVE-2007-0865SQL injection vulnerability in comments.php in LushiNews 1.01 and earlier allows remote authenticated users to inject arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.23%9 February 2007
CVE-2007-0864SQL injection vulnerability in register.php in LushiWarPlaner 1.0 allows remote attackers to inject arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.23%9 February 2007
CVE-2007-0849scripts/cronscript.php in SysCP 1.2.15 and earlier does not properly quote pathnames in user home directories, which allows local users to gain privileges by placing shell metacharacters in a directory name, and then using the control panel to protect…EXPLOIT ✓HIGH 7.2EPSS 0.85%8 February 2007
CVE-2007-0848PHP remote file inclusion vulnerability in classes/class_mail.inc.php in Maian Recipe 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.EXPLOIT ✓HIGH 7.5EPSS 3.33%8 February 2007
CVE-2007-0847SQL injection vulnerability in mod/PM/reply.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to priv.php.EXPLOIT ✓HIGH 7.5EPSS 1.10%8 February 2007
CVE-2007-0846Cross-site scripting (XSS) vulnerability in forum.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to inject arbitrary HTML or web script via the name parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.88%8 February 2007
CVE-2007-0845admin/index.php in Advanced Poll 2.0.0 through 2.0.5-dev allows remote attackers to bypass authentication and gain administrator privileges by obtaining a valid session identifier and setting the uid parameter to 1.EXPLOIT ✓HIGH 7.5EPSS 6.75%8 February 2007
CVE-2006-6976PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.2 and earlier allows remote attackers to execute arbitrary code via a URL in the absolute_path parameter.EXPLOIT ✓HIGH 7.5EPSS 4.14%8 February 2007
CVE-2007-0839Multiple PHP remote file inclusion vulnerabilities in index/index_album.php in Valarsoft WebMatic 2.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) P_LIB and (2) P_INDEX parameters.EXPLOIT ✓HIGH 7.5EPSS 3.33%8 February 2007
CVE-2007-0837PHP remote file inclusion vulnerability in examples/inc/top.inc.php in AgerMenu 0.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter.EXPLOIT ✓HIGH 7.5EPSS 3.31%8 February 2007
CVE-2007-0836admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to include arbitrary local and possibly remote files via the (1) "Path to custom header include" and (2) "Path to custom footer include" form fields.EXPLOIT ✓MEDIUM 4.0EPSS 1.84%8 February 2007
CVE-2007-0828PHP remote file inclusion vulnerability in affichearticles.php3 in MySQLNewsEngine allows remote attackers to execute arbitrary PHP code via a URL in the newsenginedir parameter.EXPLOIT ✓HIGH 7.5EPSS 3.13%7 February 2007
CVE-2007-0827The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that invokes the Remove method with an invalid index argument, which is used as an offset for a function call.EXPLOIT ✓MEDIUM 6.8EPSS 4.31%7 February 2007
CVE-2007-0826SQL injection vulnerability in forum.asp in Kisisel Site 2007 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.EXPLOIT ✓HIGH 7.5EPSS 1.11%7 February 2007
CVE-2007-0825FlashFXP 3.4.0 build 1145 allows remote servers to cause a denial of service (CPU consumption) via a response to a PWD command that contains a long string with deeply nested directory structure, possibly due to a buffer overflow.EXPLOIT ✓HIGH 7.8EPSS 3.26%7 February 2007
CVE-2007-0824PHP remote file inclusion vulnerability in inhalt.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dateien[news] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.84%7 February 2007
CVE-2007-0821Multiple directory traversal vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to read arbitrary files via a ..EXPLOIT ×2 ✓MEDIUM 5.0EPSS 7.62%7 February 2007
CVE-2007-0820Multiple PHP remote file inclusion vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to execute arbitrary PHP code via a URL in the chemin parameter to (1) mod_news/index.php, (2) mod_news/goodies.php, or (3) mod_search/index.php.EXPLOIT ×4 ✓HIGH 7.5EPSS 8.29%7 February 2007
CVE-2007-0817Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Agent HTTP header, which is not sanitized before being displayed in an error page.EXPLOIT ✓MEDIUM 4.3EPSS 8.60%7 February 2007
CVE-2007-0816The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlier allows remote attackers to cause a denial of service (service crash) via a crafted TADDR2UADDR that triggers a null pointer…EXPLOIT ✓MEDIUM 5.0EPSS 11.4%7 February 2007
CVE-2007-0812SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authenticated users to execute arbitrary SQL commands via the pmid[0] parameter.EXPLOIT ✓HIGH 7.5EPSS 1.26%7 February 2007
CVE-2007-0811Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an…EXPLOIT ✓MEDIUM 4.3EPSS 18.1%7 February 2007
CVE-2007-0810PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_libraries] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.49%7 February 2007
CVE-2007-0809PHP remote file inclusion vulnerability in includes/class_template.php in Categories hierarchy (aka CH or mod-CH) 2.1.2 in ptirhiikmods allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.EXPLOIT ✓HIGH 7.5EPSS 3.34%7 February 2007
CVE-2007-0805The ps (/usr/ucb/ps) command on HP Tru64 UNIX 5.1 1885 allows local users to obtain sensitive information, including environment variables of arbitrary processes, via the "auxewww" argument, a similar issue to CVE-1999-1587.EXPLOIT ✓LOW 2.1EPSS 0.97%7 February 2007
CVE-2007-0804Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject arbitrary PHP code into arbitrary files via ".." sequences in the subpageName parameter, as demonstrated by injecting PHP code into…EXPLOIT ✓HIGH 7.5EPSS 2.54%7 February 2007
CVE-2007-0797PHP remote file inclusion vulnerability in theme/settings.php in bluevirus-design SMA-DB 0.3.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pfad_z parameter.EXPLOIT ✓HIGH 7.5EPSS 3.34%6 February 2007
CVE-2007-0790Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.EXPLOIT ✓HIGH 7.5EPSS 4.24%6 February 2007
CVE-2007-0786SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.26%6 February 2007
CVE-2007-0785PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.EXPLOIT ✓HIGH 7.5EPSS 68.8%6 February 2007
CVE-2007-0768Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo!EXPLOIT ✓MEDIUM 4.3EPSS 1.83%6 February 2007
CVE-2007-0766Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.EXPLOIT ✓HIGH 9.3EPSS 5.59%6 February 2007
CVE-2007-0765SQL injection vulnerability in news.php in dB Masters Curium CMS 1.03 and earlier allows remote attackers to execute arbitrary SQL commands via the c_id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.23%6 February 2007
CVE-2007-0764Unrestricted file upload vulnerability in F3Site 2.1 and earlier allows remote authenticated administrators to upload and execute arbitrary PHP scripts via GIF86 header in a file in the uplf parameter, which can be later accessed via a relative pathname…EXPLOIT ✓MEDIUM 6.5EPSS 2.17%6 February 2007
CVE-2007-0763Cross-site scripting (XSS) vulnerability in the news comment functionality in F3Site 2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the Autor field.EXPLOIT ✓MEDIUM 6.8EPSS 1.81%6 February 2007
CVE-2007-0762PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Build 100 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.EXPLOIT ✓HIGH 7.5EPSS 3.31%6 February 2007
CVE-2007-0761PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the ezconvert_dir parameter.EXPLOIT ✓HIGH 7.5EPSS 3.34%6 February 2007
CVE-2007-0760EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an admin/ URL, which allows remote attackers to read or modify account names and passwords via a spoofed Referer.EXPLOIT ✓HIGH 7.5EPSS 2.53%6 February 2007
CVE-2007-0759Multiple SQL injection vulnerabilities in EasyMoblog 0.5.1 allow remote attackers to execute arbitrary SQL commands via the (1) i or (2) post_id parameter to add_comment.php, which triggers an injection in libraries.inc.php; or (3) the i parameter to…EXPLOIT ✓HIGH 7.5EPSS 1.25%6 February 2007
CVE-2007-0758PHP remote file inclusion vulnerability in lang.php in PHPProbid 5.24 allows remote attackers to execute arbitrary PHP code via a URL in the SRC attribute of an HTML element in the lang parameter.EXPLOIT ✓HIGH 7.5EPSS 2.31%6 February 2007
CVE-2007-0757PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter.EXPLOIT ✓HIGH 7.5EPSS 3.31%6 February 2007
CVE-2007-0756Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large computer-name size value in a ServerInit packet, which triggers a failed malloc and a resulting NULL dereference.EXPLOIT ✓HIGH 7.8EPSS 4.42%6 February 2007
CVE-2007-0708cmdmon.sys in Comodo Firewall Pro (formerly Comodo Personal Firewall) before 2.4.16.174 does not validate arguments that originate in user mode for the (1) NtConnectPort and (2) NtCreatePort hooked SSDT functions, which allows local users to cause a…EXPLOIT ✓HIGH 7.2EPSS 0.67%4 February 2007
CVE-2007-0707Stack-based buffer overflow in GOM Player 2.0.12.3375 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the "ref href" tag.EXPLOIT ✓MEDIUM 6.8EPSS 3.88%4 February 2007
CVE-2007-0704PHP remote file inclusion vulnerability in install.php in Somery 0.4.6 allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter, a different vector than CVE-2006-4669.EXPLOIT ✓HIGH 7.5EPSS 2.62%4 February 2007
CVE-2007-0703PHP remote file inclusion vulnerability in library/StageLoader.php in WebBuilder 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[core][module_path] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.62%4 February 2007
CVE-2007-0702Multiple PHP remote file inclusion vulnerabilities in phpEventMan 1.0.2 allow remote attackers to execute arbitrary PHP code via a URL in the level parameter to (1) Shared/controller/text.ctrl.php or (2) UserMan/controller/common.function.php.EXPLOIT ✓HIGH 7.5EPSS 3.65%4 February 2007
CVE-2007-0701PHP remote file inclusion vulnerability in inc/common.inc.php in Epistemon 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.EXPLOIT ✓HIGH 7.5EPSS 3.20%4 February 2007
CVE-2007-0699PHP remote file inclusion vulnerability in includes/includes.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) before 2.5.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.EXPLOIT ✓HIGH 7.5EPSS 3.47%4 February 2007

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.