Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,833 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 358 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-0577 | PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.85% | 30 January 2007 |
| CVE-2007-0576 | PHP remote file inclusion vulnerability in xt_counter.php in Xt-Stats 2.3.x up to 2.4.0.b3 allows remote attackers to execute arbitrary PHP code via a URL in the server_base_dir parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.58% | 30 January 2007 |
| CVE-2007-0575 | Multiple SQL injection vulnerabilities in the administrative login page (admin/login.asp) in ASPCode.net AdMentor allow remote attackers to execute arbitrary SQL commands via the (1) Userid and (2) Password fields. | EXPLOIT ✓HIGH 7.5EPSS 1.21% | 30 January 2007 |
| CVE-2007-0574 | SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.40 allows remote attackers to execute arbitrary SQL commands via the wcHeadlines parameter, a different vector than CVE-2006-4715. | EXPLOIT ✓HIGH 7.5EPSS 2.02% | 30 January 2007 |
| CVE-2007-0573 | PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the racineTBS parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.33% | 30 January 2007 |
| CVE-2007-0572 | PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Golem Gaming Portal 0.5.1 Alpha 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.49% | 30 January 2007 |
| CVE-2007-0571 | PHP remote file inclusion vulnerability in include/lib/lib_head.php in phpMyReports 3.0.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfgPathModule parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.34% | 30 January 2007 |
| CVE-2007-0570 | PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News Script (AINS) 0.02b allows remote attackers to execute arbitrary PHP code via a URL in the ains_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.72% | 30 January 2007 |
| CVE-2007-0569 | SQL injection vulnerability in xNews.php in xNews 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a shownews action. | EXPLOIT ✓HIGH 7.5EPSS 2.29% | 30 January 2007 |
| CVE-2007-0568 | PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the gl_root parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.22% | 30 January 2007 |
| CVE-2007-0567 | Cross-site scripting (XSS) vulnerability in admin.php in Interactive-Scripts.Com PHP Membership Manager 1.5 allows remote attackers to inject arbitrary web script or HTML via the _p parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.80% | 30 January 2007 |
| CVE-2007-0464 | The _CFNetConnectionWillEnqueueRequests function in CFNetwork 129.19 on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application crash) via a crafted HTTP 301 response, which results in a NULL pointer… | EXPLOIT ✓MEDIUM 5.0EPSS 14.8% | 30 January 2007 |
| CVE-2007-0566 | SQL injection vulnerability in news_detail.asp in ASP NEWS 3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.26% | 30 January 2007 |
| CVE-2007-0562 | Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .avi file, which triggers the crash when the user right clicks on the file. | EXPLOIT ✓MEDIUM 4.3EPSS 13.7% | 30 January 2007 |
| CVE-2007-0561 | Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) admin_linkdb.php, (2) admin_forum_prune.php, (3) admin_extensions.php, (4)… | EXPLOIT ✓HIGH 7.5EPSS 10.1% | 30 January 2007 |
| CVE-2007-0560 | SQL injection vulnerability in user.asp in ASP EDGE 1.2b and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.30% | 30 January 2007 |
| CVE-2007-0559 | PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the sql_language parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.49% | 30 January 2007 |
| CVE-2007-0558 | PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the MODULES_DIR parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.49% | 30 January 2007 |
| CVE-2007-0347 | The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a '… | EXPLOIT ✓MEDIUM 4.3EPSS 3.69% | 29 January 2007 |
| CVE-2007-0554 | SQL injection vulnerability in print.asp in Guo Xu Guos Posting System (GPS) 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.83% | 29 January 2007 |
| CVE-2007-0548 | KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number of requests for nonexistent objects. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 3.21% | 29 January 2007 |
| CVE-2007-0540 | WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable… | EXPLOIT ✓MEDIUM 5.0EPSS 7.59% | 29 January 2007 |
| CVE-2007-0463 | Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or… | EXPLOIT ✓MEDIUM 5.0EPSS 17.7% | 29 January 2007 |
| CVE-2006-6962 | PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for Joomla! allows attackers to execute arbitrary PHP code via the mosConfig_absolute_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 4.26% | 29 January 2007 |
| CVE-2006-6958 | Multiple PHP remote file inclusion vulnerabilities in phpBlueDragon 2.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter to (1) team_admin.php, (2) rss_admin.php, (3) manual_admin.php, and (4)… | EXPLOIT ✓HIGH 7.5EPSS 8.80% | 29 January 2007 |
| CVE-2007-0535 | Multiple eval injection vulnerabilities in Vote! | EXPLOIT ✓HIGH 7.5EPSS 3.64% | 26 January 2007 |
| CVE-2007-0528 | The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote… | EXPLOIT ✓HIGH 9.0EPSS 4.49% | 26 January 2007 |
| CVE-2007-0518 | Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded passwords via a direct request for pwd.txt. | EXPLOIT ✓HIGH 7.5EPSS 2.49% | 26 January 2007 |
| CVE-2007-0462 | The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a… | EXPLOIT ✓HIGH 10.0EPSS 6.65% | 26 January 2007 |
| CVE-2007-0515 | Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by… | EXPLOIT ×2 ✓HIGH 9.3EPSS 38.4% | 26 January 2007 |
| CVE-2007-0511 | Multiple PHP remote file inclusion vulnerabilities in phpXMLDOM (phpXD) 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) dom.php, (2) dtd.php, or (3) parser.php in include/. | EXPLOIT ✓MEDIUM 6.8EPSS 7.41% | 26 January 2007 |
| CVE-2007-0508 | PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitrary PHP code via a URL in the BBC_LANGUAGE_PATH parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.13% | 26 January 2007 |
| CVE-2007-0504 | Eval injection vulnerability in poll_frame.php in Vote! | EXPLOIT ✓HIGH 10.0EPSS 6.22% | 26 January 2007 |
| CVE-2007-0502 | SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID parameter, a different vector than CVE-2007-0492. | EXPLOIT ✓HIGH 7.5EPSS 1.11% | 25 January 2007 |
| CVE-2007-0501 | PHP remote file inclusion vulnerability in index.php in Mafia Scum Tools 2.0.0 in Matthew Wardrop Advanced Random Generators (adv-random-gen) allows remote attackers to execute arbitrary PHP code via a URL in the gen parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.41% | 25 January 2007 |
| CVE-2007-0500 | PHP remote file inclusion vulnerability in include/includes.php in Bradabra 2.0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.50% | 25 January 2007 |
| CVE-2007-0499 | PHP remote file inclusion vulnerability in config.php in Sangwan Kim phpIndexPage 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[inc_path] parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.42% | 25 January 2007 |
| CVE-2007-0498 | PHP remote file inclusion vulnerability in up.php in MySpeach 2.1 beta and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the my[root] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.19% | 25 January 2007 |
| CVE-2007-0497 | PHP remote file inclusion vulnerability in upload/top.php in Upload-Service 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the maindir parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 2.99% | 25 January 2007 |
| CVE-2007-0496 | PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the g_strRootDir parameter. | EXPLOIT ✓HIGH 10.0EPSS 3.76% | 25 January 2007 |
| CVE-2007-0495 | PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitrary PHP code via a URL in the racine parameter. | EXPLOIT ✓HIGH 10.0EPSS 3.78% | 25 January 2007 |
| CVE-2007-0491 | PHP remote file inclusion vulnerability in up.php in Sky GUNNING MySpeach 3.0.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the my_ms[root] parameter, a different vector than CVE-2006-4630. | EXPLOIT ✓MEDIUM 6.8EPSS 1.95% | 25 January 2007 |
| CVE-2007-0489 | PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 3.20% | 25 January 2007 |
| CVE-2007-0485 | PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP code via a URL in the WEBCHATPATH parameter. | EXPLOIT ✓HIGH 7.5EPSS 8.26% | 25 January 2007 |
| CVE-2006-6952 | Computer Associates Host Intrusion Prevention System (HIPS) drivers (1) Core kmxstart.sys 6.5.4.31 and (2) Firewall kmxfw.sys 6.5.4.10 allow local users to gain privileges by using certain privileged IOCTLs to modify callback function pointers. | EXPLOIT ×2 ✓HIGH 7.2EPSS 1.05% | 24 January 2007 |
| CVE-2007-0444 | Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and MetaFrame XP 1.0 allows local users and remote attackers to execute arbitrary code via long arguments to the… | EXPLOIT ✓HIGH 7.2EPSS 14.0% | 24 January 2007 |
| CVE-2007-0018 | Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. | EXPLOIT ×3 ✓HIGH 9.3EPSS 36.5% | 24 January 2007 |
| CVE-2007-0010 | The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image file. | EXPLOIT ✓LOW 2.1EPSS 0.93% | 24 January 2007 |
| CVE-2007-0023 | The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges via a malicious InputManager in Library/InputManagers in a user's home… | EXPLOIT ✓MEDIUM 6.9EPSS 1.59% | 24 January 2007 |
| CVE-2007-0020 | Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote attackers to execute arbitrary code via a long ftps:// URL. | EXPLOIT ✓HIGH 9.3EPSS 7.84% | 24 January 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.