SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,833 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026

25,049 results · page 358 of 501

CVESummaryPriorityPublished
CVE-2007-0577PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.85%30 January 2007
CVE-2007-0576PHP remote file inclusion vulnerability in xt_counter.php in Xt-Stats 2.3.x up to 2.4.0.b3 allows remote attackers to execute arbitrary PHP code via a URL in the server_base_dir parameter.EXPLOIT ✓HIGH 7.5EPSS 3.58%30 January 2007
CVE-2007-0575Multiple SQL injection vulnerabilities in the administrative login page (admin/login.asp) in ASPCode.net AdMentor allow remote attackers to execute arbitrary SQL commands via the (1) Userid and (2) Password fields.EXPLOIT ✓HIGH 7.5EPSS 1.21%30 January 2007
CVE-2007-0574SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.40 allows remote attackers to execute arbitrary SQL commands via the wcHeadlines parameter, a different vector than CVE-2006-4715.EXPLOIT ✓HIGH 7.5EPSS 2.02%30 January 2007
CVE-2007-0573PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the racineTBS parameter.EXPLOIT ✓HIGH 7.5EPSS 3.33%30 January 2007
CVE-2007-0572PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Golem Gaming Portal 0.5.1 Alpha 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.49%30 January 2007
CVE-2007-0571PHP remote file inclusion vulnerability in include/lib/lib_head.php in phpMyReports 3.0.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfgPathModule parameter.EXPLOIT ✓HIGH 7.5EPSS 3.34%30 January 2007
CVE-2007-0570PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News Script (AINS) 0.02b allows remote attackers to execute arbitrary PHP code via a URL in the ains_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.72%30 January 2007
CVE-2007-0569SQL injection vulnerability in xNews.php in xNews 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a shownews action.EXPLOIT ✓HIGH 7.5EPSS 2.29%30 January 2007
CVE-2007-0568PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the gl_root parameter.EXPLOIT ✓HIGH 7.5EPSS 3.22%30 January 2007
CVE-2007-0567Cross-site scripting (XSS) vulnerability in admin.php in Interactive-Scripts.Com PHP Membership Manager 1.5 allows remote attackers to inject arbitrary web script or HTML via the _p parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.80%30 January 2007
CVE-2007-0464The _CFNetConnectionWillEnqueueRequests function in CFNetwork 129.19 on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application crash) via a crafted HTTP 301 response, which results in a NULL pointer…EXPLOIT ✓MEDIUM 5.0EPSS 14.8%30 January 2007
CVE-2007-0566SQL injection vulnerability in news_detail.asp in ASP NEWS 3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.26%30 January 2007
CVE-2007-0562Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .avi file, which triggers the crash when the user right clicks on the file.EXPLOIT ✓MEDIUM 4.3EPSS 13.7%30 January 2007
CVE-2007-0561Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) admin_linkdb.php, (2) admin_forum_prune.php, (3) admin_extensions.php, (4)…EXPLOIT ✓HIGH 7.5EPSS 10.1%30 January 2007
CVE-2007-0560SQL injection vulnerability in user.asp in ASP EDGE 1.2b and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.EXPLOIT ✓HIGH 7.5EPSS 1.30%30 January 2007
CVE-2007-0559PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the sql_language parameter.EXPLOIT ✓HIGH 7.5EPSS 2.49%30 January 2007
CVE-2007-0558PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the MODULES_DIR parameter.EXPLOIT ✓HIGH 7.5EPSS 2.49%30 January 2007
CVE-2007-0347The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a '…EXPLOIT ✓MEDIUM 4.3EPSS 3.69%29 January 2007
CVE-2007-0554SQL injection vulnerability in print.asp in Guo Xu Guos Posting System (GPS) 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.83%29 January 2007
CVE-2007-0548KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number of requests for nonexistent objects.EXPLOIT ×2 ✓MEDIUM 5.0EPSS 3.21%29 January 2007
CVE-2007-0540WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable…EXPLOIT ✓MEDIUM 5.0EPSS 7.59%29 January 2007
CVE-2007-0463Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or…EXPLOIT ✓MEDIUM 5.0EPSS 17.7%29 January 2007
CVE-2006-6962PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for Joomla! allows attackers to execute arbitrary PHP code via the mosConfig_absolute_path parameter.EXPLOIT ✓MEDIUM 6.8EPSS 4.26%29 January 2007
CVE-2006-6958Multiple PHP remote file inclusion vulnerabilities in phpBlueDragon 2.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter to (1) team_admin.php, (2) rss_admin.php, (3) manual_admin.php, and (4)…EXPLOIT ✓HIGH 7.5EPSS 8.80%29 January 2007
CVE-2007-0535Multiple eval injection vulnerabilities in Vote!EXPLOIT ✓HIGH 7.5EPSS 3.64%26 January 2007
CVE-2007-0528The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote…EXPLOIT ✓HIGH 9.0EPSS 4.49%26 January 2007
CVE-2007-0518Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded passwords via a direct request for pwd.txt.EXPLOIT ✓HIGH 7.5EPSS 2.49%26 January 2007
CVE-2007-0462The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a…EXPLOIT ✓HIGH 10.0EPSS 6.65%26 January 2007
CVE-2007-0515Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by…EXPLOIT ×2 ✓HIGH 9.3EPSS 38.4%26 January 2007
CVE-2007-0511Multiple PHP remote file inclusion vulnerabilities in phpXMLDOM (phpXD) 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) dom.php, (2) dtd.php, or (3) parser.php in include/.EXPLOIT ✓MEDIUM 6.8EPSS 7.41%26 January 2007
CVE-2007-0508PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitrary PHP code via a URL in the BBC_LANGUAGE_PATH parameter.EXPLOIT ✓HIGH 7.5EPSS 3.13%26 January 2007
CVE-2007-0504Eval injection vulnerability in poll_frame.php in Vote!EXPLOIT ✓HIGH 10.0EPSS 6.22%26 January 2007
CVE-2007-0502SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID parameter, a different vector than CVE-2007-0492.EXPLOIT ✓HIGH 7.5EPSS 1.11%25 January 2007
CVE-2007-0501PHP remote file inclusion vulnerability in index.php in Mafia Scum Tools 2.0.0 in Matthew Wardrop Advanced Random Generators (adv-random-gen) allows remote attackers to execute arbitrary PHP code via a URL in the gen parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.41%25 January 2007
CVE-2007-0500PHP remote file inclusion vulnerability in include/includes.php in Bradabra 2.0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.EXPLOIT ✓HIGH 7.5EPSS 2.50%25 January 2007
CVE-2007-0499PHP remote file inclusion vulnerability in config.php in Sangwan Kim phpIndexPage 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[inc_path] parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.42%25 January 2007
CVE-2007-0498PHP remote file inclusion vulnerability in up.php in MySpeach 2.1 beta and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the my[root] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.19%25 January 2007
CVE-2007-0497PHP remote file inclusion vulnerability in upload/top.php in Upload-Service 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the maindir parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.99%25 January 2007
CVE-2007-0496PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the g_strRootDir parameter.EXPLOIT ✓HIGH 10.0EPSS 3.76%25 January 2007
CVE-2007-0495PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitrary PHP code via a URL in the racine parameter.EXPLOIT ✓HIGH 10.0EPSS 3.78%25 January 2007
CVE-2007-0491PHP remote file inclusion vulnerability in up.php in Sky GUNNING MySpeach 3.0.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the my_ms[root] parameter, a different vector than CVE-2006-4630.EXPLOIT ✓MEDIUM 6.8EPSS 1.95%25 January 2007
CVE-2007-0489PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.EXPLOIT ✓MEDIUM 6.8EPSS 3.20%25 January 2007
CVE-2007-0485PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP code via a URL in the WEBCHATPATH parameter.EXPLOIT ✓HIGH 7.5EPSS 8.26%25 January 2007
CVE-2006-6952Computer Associates Host Intrusion Prevention System (HIPS) drivers (1) Core kmxstart.sys 6.5.4.31 and (2) Firewall kmxfw.sys 6.5.4.10 allow local users to gain privileges by using certain privileged IOCTLs to modify callback function pointers.EXPLOIT ×2 ✓HIGH 7.2EPSS 1.05%24 January 2007
CVE-2007-0444Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and MetaFrame XP 1.0 allows local users and remote attackers to execute arbitrary code via long arguments to the…EXPLOIT ✓HIGH 7.2EPSS 14.0%24 January 2007
CVE-2007-0018Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function.EXPLOIT ×3 ✓HIGH 9.3EPSS 36.5%24 January 2007
CVE-2007-0010The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image file.EXPLOIT ✓LOW 2.1EPSS 0.93%24 January 2007
CVE-2007-0023The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges via a malicious InputManager in Library/InputManagers in a user's home…EXPLOIT ✓MEDIUM 6.9EPSS 1.59%24 January 2007
CVE-2007-0020Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote attackers to execute arbitrary code via a long ftps:// URL.EXPLOIT ✓HIGH 9.3EPSS 7.84%24 January 2007

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.