Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,947 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
17,392 results · page 291 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-0352 | The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6 packet, possibly involving the Jumbo Payload hop-by-hop option (jumbogram). | EXPLOIT ✓HIGH 7.8EPSS 10.4% | 18 January 2008 |
| CVE-2008-0339 | Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB01. | EXPLOIT ✓HIGH 10.0EPSS 14.5% | 17 January 2008 |
| CVE-2008-0333 | Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓MEDIUM 5.0EPSS 11.7% | 17 January 2008 |
| CVE-2008-0027 | Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote… | HIGH 10.0EPSS 57.1% | 17 January 2008 |
| CVE-2007-6682 | Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifiers in the Connection parameter. | EXPLOIT ✓HIGH 7.5EPSS 15.1% | 17 January 2008 |
| CVE-2007-6681 | Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, and (3) Vplayer file. | EXPLOIT ✓HIGH 7.5EPSS 17.3% | 17 January 2008 |
| CVE-2008-0081 | Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different… | EXPLOIT ✓CRITICAL 9.8EPSS 57.9% | 16 January 2008 |
| CVE-2008-0296 | Heap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC Media Player 0.8.6d and earlier on Windows might allow remote RTSP servers to cause a denial of service (application crash) or execute arbitrary code via a long string. | EXPLOIT ✓HIGH 10.0EPSS 14.6% | 16 January 2008 |
| CVE-2008-0295 | Heap-based buffer overflow in modules/access/rtsp/real_sdpplin.c in the Xine library, as used in VideoLAN VLC Media Player 0.8.6d and earlier, allows user-assisted remote attackers to cause a denial of service (crash) or execute arbitrary code via long… | EXPLOIT ✓HIGH 8.5EPSS 11.1% | 16 January 2008 |
| CVE-2008-0122 | Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code… | HIGH 10.0EPSS 12.4% | 16 January 2008 |
| CVE-2008-0250 | Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with a long Project line. | EXPLOIT ×2 ✓HIGH 9.3EPSS 16.9% | 12 January 2008 |
| CVE-2008-0248 | Buffer overflow in an ActiveX control in ccpm_0237.dll for StreamAudio ChainCast ProxyManager allows remote attackers to execute arbitrary code via a long URL argument to the InternalTuneIn method. | EXPLOIT ✓HIGH 9.3EPSS 10.7% | 12 January 2008 |
| CVE-2008-0244 | SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other unspecified commands, which are executed when MaxDB invokes cons.exe. | EXPLOIT ✓HIGH 10.0EPSS 80.3% | 12 January 2008 |
| CVE-2008-0005 | mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding. | MEDIUM 4.3EPSS 14.7% | 12 January 2008 |
| CVE-2008-0237 | The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure SaveFile method. | EXPLOIT ✓MEDIUM 6.8EPSS 20.5% | 11 January 2008 |
| CVE-2008-0236 | An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary commands by invoking the DoCmd method. | EXPLOIT ✓MEDIUM 5.8EPSS 17.4% | 11 January 2008 |
| CVE-2008-0235 | The Microsoft VFP_OLE_Server ActiveX control allows remote attackers to execute arbitrary code by invoking the foxcommand method. | HIGH 10.0EPSS 29.2% | 11 January 2008 |
| CVE-2008-0234 | Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404… | EXPLOIT ×2 ✓HIGH 9.3EPSS 12.4% | 11 January 2008 |
| CVE-2008-0226 | Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in… | EXPLOIT ×3 ✓HIGH 7.5EPSS 91.6% | 10 January 2008 |
| CVE-2008-0225 | Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstract attribute in an RTSP session, related to the rmff_dump_header function… | EXPLOIT ✓MEDIUM 6.4EPSS 15.0% | 10 January 2008 |
| CVE-2008-0220 | Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allow remote attackers to execute arbitrary code via a long string in the (1) second or (2) fourth… | EXPLOIT ×2 ✓HIGH 7.5EPSS 15.7% | 10 January 2008 |
| CVE-2007-6250 | Stack-based buffer overflow in AOL AOLMediaPlaybackControl (AOLMediaPlaybackControl.exe), as used by AmpX ActiveX control (AmpX.dll), might allow remote attackers to execute arbitrary code via the AppendFileToPlayList method. | HIGH 9.3EPSS 24.3% | 9 January 2008 |
| CVE-2008-0153 | telnetd.exe in Pragma TelnetServer 7.0.4.589 allows remote attackers to cause a denial of service (process crash and resource exhaustion) via a crafted TELOPT PRAGMA LOGON telnet option, which triggers a NULL pointer dereference. | EXPLOIT ✓MEDIUM 5.0EPSS 13.1% | 9 January 2008 |
| CVE-2007-5360 | Buffer overflow in OpenPegasus Management server, when compiled to use PAM and with PEGASUS_USE_PAM_STANDALONE_PROC defined, as used in VMWare ESX Server 3.0.1 and 3.0.2, might allow remote attackers to execute arbitrary code via vectors related to PAM… | HIGH 7.5EPSS 15.3% | 8 January 2008 |
| CVE-2007-0069 | Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that… | HIGH 9.3EPSS 49.2% | 8 January 2008 |
| CVE-2007-0066 | The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds… | HIGH 7.1EPSS 31.5% | 8 January 2008 |
| CVE-2008-0144 | PHP remote file inclusion vulnerability in index.php in NetRisk 1.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 44.8% | 8 January 2008 |
| CVE-2008-0139 | Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the template parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 22.2% | 8 January 2008 |
| CVE-2007-6388 | Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML… | MEDIUM 4.3EPSS 75.9% | 8 January 2008 |
| CVE-2008-0095 | The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revision 95946, and Appliance s800i 1.0.x before 1.0.3.4 allows remote… | EXPLOITMEDIUM 5.0EPSS 25.4% | 8 January 2008 |
| CVE-2008-0090 | A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long argument to the SetPassword method. | EXPLOIT ✓MEDIUM 5.0EPSS 22.5% | 4 January 2008 |
| CVE-2007-6638 | March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, passwords, device names, and IP addresses via a direct request for scripts/logfiles.tar.gz. | EXPLOIT ✓HIGH 10.0EPSS 12.6% | 4 January 2008 |
| CVE-2007-6613 | Stack-based buffer overflow in the print_iso9660_recurse function in iso-info (src/iso-info.c) in GNU Compact Disc Input and Control Library (libcdio) 0.79 and earlier allows context-dependent attackers to cause a denial of service (core dump) and… | EXPLOIT ✓MEDIUM 5.0EPSS 12.7% | 3 January 2008 |
| CVE-2007-6534 | Multiple unspecified vulnerabilities in Microsoft Office Publisher allow user-assisted remote attackers to cause a denial of service (application crash) via a crafted PUB file, possibly involving wordart. | MEDIUM 6.8EPSS 11.1% | 27 December 2007 |
| CVE-2007-6533 | Buffer overflow in Zoom Player 6.00 beta 2 and earlier allows user-assisted remote attackers to execute arbitrary code via an HTTP link to a PLS file in a crafted ZPL file, which causes an overflow in Unicode handling when generating an error message. | EXPLOIT ✓HIGH 7.5EPSS 12.3% | 27 December 2007 |
| CVE-2007-6530 | Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote attackers to execute arbitrary code via a long… | EXPLOIT ×2 ✓HIGH 9.3EPSS 36.8% | 27 December 2007 |
| CVE-2007-4474 | Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an… | EXPLOIT ×4 ✓HIGH 9.3EPSS 44.2% | 27 December 2007 |
| CVE-2007-6514 | Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by… | EXPLOIT ✓MEDIUM 4.3EPSS 38.0% | 21 December 2007 |
| CVE-2007-6509 | Unspecified vulnerability in Appian Enterprise Business Process Management (BPM) Suite 5.6 SP1 allows remote attackers to cause a denial of service via a crafted packet to port 5400/tcp. | EXPLOIT ✓HIGH 7.8EPSS 55.2% | 21 December 2007 |
| CVE-2007-4567 | The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, which allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic)… | EXPLOIT ✓HIGH 7.8EPSS 14.3% | 21 December 2007 |
| CVE-2007-6507 | SpntSvc.exe daemon in Trend Micro ServerProtect 5.58 for Windows, before Security Patch 4, exposes unspecified dangerous sub-functions from StRpcSrv.dll in the DCE/RPC interface, which allows remote attackers to obtain "full file system access" and… | HIGH 10.0EPSS 36.6% | 20 December 2007 |
| CVE-2007-6506 | The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method,… | EXPLOIT ✓HIGH 9.3EPSS 16.3% | 20 December 2007 |
| CVE-2007-6494 | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username in the reseller parameter, followed by a request to AdminSettings/displays.asp with the DecideAction… | EXPLOIT ✓HIGH 10.0EPSS 11.8% | 20 December 2007 |
| CVE-2007-6485 | Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute arbitrary PHP code via a URL in the fileOreonConf parameter to (1) MakeXML.php or (2) MakeXML4statusCounter.php in… | EXPLOIT ✓HIGH 7.5EPSS 10.8% | 20 December 2007 |
| CVE-2007-6483 | Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier versions, and Sentinel Keys Server 1.0.3 and possibly earlier versions, allows remote attackers to read arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 10.4% | 20 December 2007 |
| CVE-2007-6335 | Integer overflow in libclamav in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MEW packed PE file, which triggers a heap-based buffer overflow. | EXPLOIT ✓HIGH 7.5EPSS 18.4% | 20 December 2007 |
| CVE-2007-6246 | Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0, when running on Linux, uses insecure permissions for memory, which might allow local users to gain privileges. | MEDIUM 4.4EPSS 11.8% | 20 December 2007 |
| CVE-2007-6244 | Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote attackers to inject arbitrary web script or HTML via (1) a SWF file that uses the asfunction: protocol or (2) the… | EXPLOIT ×2 ✓MEDIUM 4.3EPSS 12.9% | 20 December 2007 |
| CVE-2007-6242 | Unspecified vulnerability in Adobe Flash Player 9.0.48.0 and earlier might allow remote attackers to execute arbitrary code via unknown vectors, related to "input validation errors." | MEDIUM 6.8EPSS 30.1% | 20 December 2007 |
| CVE-2007-6454 | Heap-based buffer overflow in the handshakeHTTP function in servhs.cpp in PeerCast 0.1217 and earlier, and SVN 344 and earlier, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long SOURCE request. | EXPLOIT ✓HIGH 10.0EPSS 16.8% | 20 December 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.