SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-28 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

398,833 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026

25,049 results · page 359 of 501

CVESummaryPriorityPublished
CVE-2007-0449Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Desktop and Business Protection Suite r2, and Desktop Management Suite (DMS) r11.0 and r11.1 allow remote…EXPLOIT ×4 ✓HIGH 10.0EPSS 79.4%23 January 2007
CVE-2007-0430The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial of service (memory corruption) via a large mappingCount value.EXPLOIT ✓MEDIUM 4.9EPSS 0.68%23 January 2007
CVE-2007-0429DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the GoWindowed method for a certain instance of the ActiveX object.EXPLOIT ✓MEDIUM 5.0EPSS 2.92%23 January 2007
CVE-2006-6951Cross-site scripting (XSS) vulnerability in blog.php in OdysseusBlog allows remote attackers to inject arbitrary web script or HTML via the page parameter.EXPLOIT ✓MEDIUM 6.8EPSS 1.83%23 January 2007
CVE-2007-0427Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section.EXPLOIT ×2 ✓HIGH 9.3EPSS 31.2%23 January 2007
CVE-2007-0021Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI.EXPLOIT ✓HIGH 7.5EPSS 23.1%23 January 2007
CVE-2007-0399Multiple cross-site scripting (XSS) vulnerabilities in index.php in Simple Machines Forum (SMF) 1.1 RC3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) recipient or (2) BCC field when selecting send in a pm action.EXPLOIT ✓MEDIUM 6.0EPSS 2.12%22 January 2007
CVE-2007-0395PHP remote file inclusion vulnerability in libraries/grab_globals.lib.php in ComVironment 4.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.EXPLOIT ✓HIGH 7.5EPSS 2.72%19 January 2007
CVE-2007-0389Directory traversal vulnerability in ArsDigita Community System (ACS) 3.4.10 and earlier, and ArsDigita Community Education Solution (ACES) 1.1, allows remote attackers to read arbitrary files via .%252e/ (double-encoded dot dot slash) sequences in the…EXPLOIT ✓HIGH 7.8EPSS 2.97%19 January 2007
CVE-2007-0388SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQL commands via the boardids[1] and other boardids[] parameters.EXPLOIT ×3 ✓HIGH 7.5EPSS 1.09%19 January 2007
CVE-2007-0371A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP_BDc.SelectedFolder property value.EXPLOIT ✓MEDIUM 4.3EPSS 2.33%19 January 2007
CVE-2007-0370Unrestricted file upload vulnerability in index.php in phpBP RC3 (2.204) and earlier allows remote administrators to inject arbitrary PHP code into an upload/banners/ file via a banners add operation that uploads the PHP code through an image_form…EXPLOIT ✓HIGH 7.5EPSS 1.17%19 January 2007
CVE-2007-0369SQL injection vulnerability in phpBP RC3 (2.204) and earlier allows remote attackers to execute arbitrary SQL commands via the comment forum.EXPLOIT ✓HIGH 7.5EPSS 1.08%19 January 2007
CVE-2007-0368Stack-based buffer overflow in mbse-bbs 0.70 and earlier allows local users to execute arbitrary code via a long string in the MBSE_ROOT environment variable.EXPLOIT ✓HIGH 10.0EPSS 5.01%19 January 2007
CVE-2007-0019Multiple heap-based buffer overflows in rumpusd in Rumpus 5.1 and earlier (1) allow remote authenticated users to execute arbitrary code via a long LIST command and other unspecified requests to the FTP service, and (2) allow remote attackers to execute…EXPLOIT ✓MEDIUM 6.5EPSS 3.81%19 January 2007
CVE-2007-0364Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com INDEXU 5.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to (a) suggest_category.php; the (2) u parameter to (b)…EXPLOIT ×12 ✓MEDIUM 4.3EPSS 2.75%19 January 2007
CVE-2006-6943PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path via direct requests to (a) scripts/check_lang.php and (b) themes/darkblue_orange/layout.inc.php; and via the (1) lang[], (2) target[], (3) db[], (4) goto[], (5) table[],…EXPLOIT ✓MEDIUM 5.0EPSS 4.61%19 January 2007
CVE-2006-6942Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b)…EXPLOIT ×4 ✓MEDIUM 6.8EPSS 3.30%19 January 2007
CVE-2007-0361PHP remote file inclusion vulnerability in mep/frame.php in PHPMyphorum 1.5a allows remote attackers to execute arbitrary PHP code via a URL in the chem parameter.EXPLOIT ✓HIGH 7.5EPSS 2.49%19 January 2007
CVE-2007-0360PHP remote file inclusion vulnerability in lang/index.php in Oreon 1.2.3 RC4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.EXPLOIT ✓HIGH 7.5EPSS 3.34%19 January 2007
CVE-2007-0359PHP remote file inclusion vulnerability in frontpage.php in Uberghey CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the setup_folder parameter.EXPLOIT ✓HIGH 7.5EPSS 2.84%19 January 2007
CVE-2007-0357Directory traversal vulnerability in the AVM IGD CTRL Service in Fritz!DSL 02.02.29 allows remote attackers to read arbitrary files via ..%5C (URL-encoded dot dot backslash) sequences in a URI requested from the AR7 webserver.EXPLOIT ✓MEDIUM 5.0EPSS 3.54%19 January 2007
CVE-2007-0356The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP.RootFolder property value.EXPLOIT ✓MEDIUM 5.0EPSS 17.6%19 January 2007
CVE-2007-0355Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly remote attackers, to gain privileges and possibly execute arbitrary code via a registration request with…EXPLOIT ✓HIGH 7.2EPSS 6.64%19 January 2007
CVE-2007-0354SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 2.05%19 January 2007
CVE-2007-0353Cross-site scripting (XSS) vulnerability in (1) index.php and (2) login.php in myBloggie 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO string.EXPLOIT ×2 ✓MEDIUM 6.8EPSS 2.71%19 January 2007
CVE-2007-0352Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt file composed of lines that begin with an integer followed by a space and a long string.EXPLOIT ✓HIGH 9.3EPSS 36.6%19 January 2007
CVE-2006-6941index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to obtain sensitive information via an invalid action parameter in an info operation, which discloses the path in an error message.EXPLOIT ✓MEDIUM 5.0EPSS 2.39%19 January 2007
CVE-2007-0344Multiple format string vulnerabilities in (1) _invitedToRoom: and (2) _invitedToDirectChat: in Colloquy 2.1 and earlier allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string…EXPLOIT ✓HIGH 7.5EPSS 6.61%18 January 2007
CVE-2007-0342WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X…EXPLOIT ✓HIGH 7.5EPSS 2.27%18 January 2007
CVE-2007-0340SQL injection vulnerability in inc/header.inc.php in ThWboard 3.0b2.84-php5 and earlier allows remote attackers to execute arbitrary SQL commands via the board[styleid] parameter to index.php.EXPLOIT ✓HIGH 7.5EPSS 1.08%18 January 2007
CVE-2007-0338Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with a large number of format string specifiers, which triggers the overflow during processing of the Server Log.EXPLOIT ✓HIGH 7.5EPSS 4.74%18 January 2007
CVE-2007-0337Directory traversal vulnerability in sesskglogadmin.php in KGB 1.9 and earlier allows remote attackers to include and execute arbitrary local files via a ..EXPLOIT ✓HIGH 7.5EPSS 3.11%18 January 2007
CVE-2007-0335Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a ..EXPLOIT ×2 ✓MEDIUM 6.8EPSS 3.32%18 January 2007
CVE-2007-0333Agnitum Outpost Firewall PRO 4.0 allows local users to bypass access restrictions and insert Trojan horse drivers into the product's installation directory by creating links using FileLinkInformation requests with the ZwSetInformationFile function, as…EXPLOIT ✓HIGH 7.2EPSS 0.91%18 January 2007
CVE-2007-0329download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathname in the file parameter, as demonstrated by config/gallerysetup.php.EXPLOIT ✓MEDIUM 5.0EPSS 2.92%18 January 2007
CVE-2007-0316Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.010 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) xuser_name parameter to…EXPLOIT ✓HIGH 7.5EPSS 2.04%18 January 2007
CVE-2007-0314Multiple PHP remote file inclusion vulnerabilities in Article System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_DIR parameter to (1) forms.php, (2) issue_edit.php, (3) client.php, and (4) classes.php.EXPLOIT ✓HIGH 7.5EPSS 2.38%18 January 2007
CVE-2007-0311Texas Imperial Software WFTPD and WFTPD Pro Server 3.25 and earlier allow remote attackers to cause a denial of service (application crash) via a long SITE ADMIN command.EXPLOIT ✓MEDIUM 5.0EPSS 2.80%18 January 2007
CVE-2007-0309SQL injection vulnerability in blocks/block-Old_Articles.php in Francisco Burzi PHP-Nuke 7.9 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat parameter.EXPLOIT ✓HIGH 7.5EPSS 4.66%18 January 2007
CVE-2007-0307PHP remote file inclusion vulnerability in include/common.php in Poplar Gedcom Viewer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[rootPath] parameter.EXPLOIT ✓HIGH 7.5EPSS 2.73%18 January 2007
CVE-2007-0306SQL injection vulnerability in visu_user.asp in Digiappz DigiAffiliate 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.11%18 January 2007
CVE-2007-0305SQL injection vulnerability in etkinlikbak.asp in Okul Web Otomasyon Sistemi 4.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.31%18 January 2007
CVE-2007-0304SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.EXPLOIT ✓HIGH 7.5EPSS 1.09%18 January 2007
CVE-2007-0302Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to (a) Logon.aspx, and the (2) Username and (3) Update parameters to (b) Members1.aspx.EXPLOIT ×2 ✓MEDIUM 6.8EPSS 2.23%18 January 2007
CVE-2007-0301PHP remote file inclusion vulnerability in _admin/admin_menu.php in FdWeB Espace Membre 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.38%18 January 2007
CVE-2007-0300PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.EXPLOIT ✓MEDIUM 6.8EPSS 2.81%18 January 2007
CVE-2007-0243Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which…EXPLOIT ✓MEDIUM 6.8EPSS 11.3%17 January 2007
CVE-2007-0298PHP remote file inclusion vulnerability in show.php in LunarPoll, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the PollDir parameter.EXPLOIT ✓MEDIUM 6.8EPSS 3.71%17 January 2007
CVE-2007-0297Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.47.11 and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE03.EXPLOIT ✓MEDIUM 4.0EPSS 3.45%17 January 2007

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.