Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,833 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 357 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-6966 | phpGraphy before 0.9.13a does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by uploading a… | EXPLOIT ✓HIGH 7.5EPSS 2.57% | 4 February 2007 |
| CVE-2007-0697 | index2.php in ACGVannu 1.3 and earlier allows remote attackers to change the password or profile of a user via a modified id parameter, related to templates/modif.html. | EXPLOIT ✓MEDIUM 6.4EPSS 2.87% | 3 February 2007 |
| CVE-2007-0688 | SQL injection vulnerability in oku.asp in Hunkaray Duyuru Scripti allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.30% | 3 February 2007 |
| CVE-2007-0687 | SQL injection vulnerability in i-search.php in Michelle's L2J Dropcalc 4 and earlier allows remote authenticated users to execute arbitrary SQL commands via the itemid parameter. | EXPLOIT ✓MEDIUM 6.5EPSS 0.94% | 3 February 2007 |
| CVE-2007-0686 | The Intel 2200BG 802.11 Wireless Mini-PCI driver 9.0.3.9 (w29n51.sys) allows remote attackers to cause a denial of service (system crash) via crafted disassociation packets, which triggers memory corruption of "internal kernel structures," a different… | EXPLOIT ✓HIGH 7.1EPSS 2.14% | 3 February 2007 |
| CVE-2007-0684 | PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 8.52% | 3 February 2007 |
| CVE-2007-0683 | PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 4.84% | 3 February 2007 |
| CVE-2007-0682 | PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the galleryfilesdir parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.36% | 3 February 2007 |
| CVE-2007-0681 | profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php. | EXPLOIT ✓CRITICAL 9.8EPSS 5.20% | 3 February 2007 |
| CVE-2007-0680 | PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 4.05% | 3 February 2007 |
| CVE-2007-0679 | PHP remote file inclusion vulnerability in lang/leslangues.php in Nicolas Grandjean PHPMyRing 4.1.3b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fichier parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.72% | 3 February 2007 |
| CVE-2007-0678 | SQL injection vulnerability in windows.asp in Fullaspsite Asp Hosting Sitesi allows remote attackers to execute arbitrary SQL commands via the kategori_id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.09% | 3 February 2007 |
| CVE-2007-0677 | PHP remote file inclusion vulnerability in fw/class.Quick_Config_Browser.php in Cadre PHP Framework 20020724 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][framework_path] parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.56% | 3 February 2007 |
| CVE-2007-0676 | SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 9.04% | 3 February 2007 |
| CVE-2007-0663 | SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter, a different vector than CVE-2007-0631. | EXPLOIT ✓HIGH 7.5EPSS 0.96% | 1 February 2007 |
| CVE-2007-0662 | PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.20% | 1 February 2007 |
| CVE-2007-0656 | PHP remote file inclusion vulnerability in includes/functions.php in phpBB2-MODificat 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 16.2% | 1 February 2007 |
| CVE-2007-0649 | Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via the… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 6.29% | 1 February 2007 |
| CVE-2007-0647 | Format string vulnerability in Help Viewer 3.0.0 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSBeginAlertSheet Apple AppKit function. | EXPLOIT ✓HIGH 7.1EPSS 2.63% | 1 February 2007 |
| CVE-2007-0646 | Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when… | EXPLOIT ✓HIGH 7.1EPSS 10.2% | 1 February 2007 |
| CVE-2007-0645 | Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling certain Apple AppKit functions. | EXPLOIT ✓MEDIUM 6.8EPSS 1.92% | 1 February 2007 |
| CVE-2007-0644 | Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in filenames that are not properly handled when calling the (1) NSLog and (2)… | EXPLOIT ✓HIGH 7.1EPSS 2.55% | 1 February 2007 |
| CVE-2007-0643 | Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file. | EXPLOIT ✓MEDIUM 4.3EPSS 6.97% | 31 January 2007 |
| CVE-2007-0641 | Buffer overflow in the EnumPrintersA function in dapcnfsd.dll 0.6.4.0 in Shaffer Solutions (SSC) DiskAccess NFS Client allows remote attackers to execute arbitrary code via a long argument, an issue similar to CVE-2006-5854 and CVE-2007-0444. | EXPLOIT ✓HIGH 7.5EPSS 4.40% | 31 January 2007 |
| CVE-2007-0639 | Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject arbitrary PHP code into a .inc file in the data/ directory via (1) a REMOTE_ADDR cookie or (2) a cookie specifying an element of the… | EXPLOIT ✓HIGH 7.5EPSS 7.14% | 31 January 2007 |
| CVE-2007-0638 | show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database contents) via a % (percent) character in the dbfieldv parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 3.12% | 31 January 2007 |
| CVE-2007-0637 | Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓HIGH 7.5EPSS 3.65% | 31 January 2007 |
| CVE-2007-0635 | Multiple PHP remote file inclusion vulnerabilities in EncapsCMS 0.3.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) config[path] parameter to (a) common_foot.php or (b) blogs.php, or (2) the config[theme] parameter to (c)… | EXPLOIT ✓HIGH 7.5EPSS 9.27% | 31 January 2007 |
| CVE-2007-0634 | Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system crash) via certain ICMP packets. | EXPLOIT ×2 ✓HIGH 7.8EPSS 9.35% | 31 January 2007 |
| CVE-2007-0633 | PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.20% | 31 January 2007 |
| CVE-2007-0631 | SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.23% | 31 January 2007 |
| CVE-2007-0623 | SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.81% | 31 January 2007 |
| CVE-2007-0620 | download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions, including .php, via a relative pathname in the fname parameter, as demonstrated by downloading config.php. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 3.61% | 31 January 2007 |
| CVE-2007-0614 | The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (persistent application crash) via a crafted phsh hash attribute in a TXT key. | EXPLOIT ✓HIGH 7.8EPSS 8.60% | 31 January 2007 |
| CVE-2007-0613 | The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does not check for duplicate entries when adding newly discovered available contacts, which allows remote attackers to cause a denial of… | EXPLOIT ✓MEDIUM 5.0EPSS 7.35% | 31 January 2007 |
| CVE-2007-0612 | Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in… | EXPLOIT ✓HIGH 7.8EPSS 43.9% | 31 January 2007 |
| CVE-2007-0467 | crashdump in Apple Mac OS X 10.4.8 allows local users in the admin group to modify arbitrary files or gain privileges via a symlink attack on application logs in /Library/Logs/CrashReporter/. | EXPLOIT ✓MEDIUM 6.2EPSS 1.80% | 31 January 2007 |
| CVE-2007-0466 | Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 allows remote attackers to execute arbitrary code via a crafted ASF_File_Properties_Object size field in a WMV file, which triggers memory corruption. | EXPLOIT ✓HIGH 10.0EPSS 6.20% | 31 January 2007 |
| CVE-2007-0465 | Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename. | EXPLOIT ✓HIGH 7.6EPSS 18.5% | 31 January 2007 |
| CVE-2007-0602 | Buffer overflow in libvsapi.so in the VSAPI library in Trend Micro VirusWall 3.81 for Linux, as used by IScan.BASE/vscan, allows local users to gain privileges via a long command line argument, a different vulnerability than CVE-2005-0533. | EXPLOIT ✓MEDIUM 6.9EPSS 0.91% | 30 January 2007 |
| CVE-2007-0600 | SQL injection vulnerability in news_page.asp in Martyn Kilbryde Newsposter Script (aka makit news/blog poster) 3 and earlier allows remote attackers to execute arbitrary SQL commands via the uid parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.07% | 30 January 2007 |
| CVE-2007-0598 | SQL injection vulnerability in forum/load.php in Aztek Forum 4.00 allows remote attackers to execute arbitrary SQL commands via the fid cookie to forum.php. | EXPLOIT ✓HIGH 7.5EPSS 1.06% | 30 January 2007 |
| CVE-2007-0591 | PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.84% | 30 January 2007 |
| CVE-2007-0590 | Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web script or HTML via the palavra parameter. | EXPLOIT ✓MEDIUM 5.8EPSS 1.55% | 30 January 2007 |
| CVE-2007-0589 | SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to info_user.asp. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 30 January 2007 |
| CVE-2007-0585 | include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain source code of files via the conffile parameter. | EXPLOIT ✓HIGH 9.3EPSS 3.97% | 30 January 2007 |
| CVE-2007-0584 | PHP remote file inclusion vulnerability in membres/membreManager.php in PhP Generic Library & Framework for comm (g-neric) allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 70.4% | 30 January 2007 |
| CVE-2007-0582 | SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands via the User (username) field. | EXPLOIT ✓HIGH 7.5EPSS 1.06% | 30 January 2007 |
| CVE-2007-0581 | PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.22% | 30 January 2007 |
| CVE-2007-0580 | PHP remote file inclusion vulnerability in menu.php in Foro Domus 2.10 allows remote attackers to execute arbitrary PHP code via a URL in the sesion_idioma parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.81% | 30 January 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.