Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,947 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
17,392 results · page 293 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-5841 | PHP remote file inclusion vulnerability in admin/index.php in nuBoard 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the site parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 31.4% | 6 November 2007 |
| CVE-2007-5603 | Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allows remote attackers to execute arbitrary code via a long string in the second argument to the AddRouteEntry… | EXPLOIT ×2 ✓HIGH 9.3EPSS 38.0% | 5 November 2007 |
| CVE-2007-5800 | Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow remote attackers to execute arbitrary PHP code via a URL in the bkpwp_plugin_path parameter to (1) plugins/BackUp/Archive.php; and… | EXPLOIT ✓MEDIUM 6.8EPSS 36.5% | 3 November 2007 |
| CVE-2007-5660 | Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2008 allows remote attackers to execute arbitrary code via an unspecified "unsafe method," possibly… | EXPLOIT ×2 ✓HIGH 9.3EPSS 36.6% | 2 November 2007 |
| CVE-2007-5781 | PHP remote file inclusion vulnerability in inc/sige_init.php in Sige 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the SYS_PATH parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 38.6% | 1 November 2007 |
| CVE-2007-5779 | Buffer overflow in the GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 in Gretech Online Movie Player (GOM Player) 2.1.6.3499 allows remote attackers to execute arbitrary code via a long argument to the OpenUrl method. | EXPLOIT ×2 ✓HIGH 7.5EPSS 71.5% | 1 November 2007 |
| CVE-2007-5775 | Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. | EXPLOIT ✓CRITICAL 9.8EPSS 26.9% | 1 November 2007 |
| CVE-2007-5740 | The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code via an IMAP tag with a null byte followed by a format string specifier, which is not counted by the… | EXPLOIT ✓HIGH 7.5EPSS 12.4% | 31 October 2007 |
| CVE-2007-5728 | Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via certain input available in PHP_SELF in (1) redirect.php, possibly related to (2) login.php,… | EXPLOIT ✓MEDIUM 4.3EPSS 14.6% | 30 October 2007 |
| CVE-2007-5722 | Stack-based buffer overflow in a certain ActiveX control in GLChat.ocx 2.5.1.32 in GlobalLink 2.7.0.8, as used in Ourgame GLWorld and possibly other products, allows remote attackers to execute arbitrary code via a long first argument to the… | EXPLOIT ✓HIGH 7.5EPSS 11.7% | 30 October 2007 |
| CVE-2007-5709 | Stack-based buffer overflow in Sony SonicStage CONNECT Player (CP) 4.3 allows remote attackers to execute arbitrary code via a long file name in an M3U file. | EXPLOIT ✓HIGH 9.3EPSS 10.9% | 30 October 2007 |
| CVE-2007-5654 | LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new extension, as demonstrated by reading PHP source code via requests for .php%00.txt files, aka "Mime… | EXPLOIT ✓MEDIUM 5.0EPSS 41.1% | 23 October 2007 |
| CVE-2007-5641 | Multiple PHP remote file inclusion vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the full_path parameter to (1) certinfo/index.php, (2) emails/index.php, (3)… | EXPLOIT ✓MEDIUM 6.8EPSS 40.3% | 23 October 2007 |
| CVE-2007-5631 | Multiple PHP remote file inclusion vulnerabilities in PeopleAggregator 1.2pre6, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the current_blockmodule_path parameter to (1)… | EXPLOIT ✓MEDIUM 6.8EPSS 39.4% | 23 October 2007 |
| CVE-2007-5628 | PHP remote file inclusion vulnerability in src/scripture.php in The Online Web Library Site (TOWels) 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the pageHeaderFile parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 27.8% | 23 October 2007 |
| CVE-2007-5601 | Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and earlier versions including 10, RealOne Player, and RealOne Player 2, allows remote attackers to execute arbitrary code via certain… | EXPLOIT ×2 ✓HIGH 9.3EPSS 42.4% | 20 October 2007 |
| CVE-2007-5592 | Multiple PHP remote file inclusion vulnerabilities in awzMB 4.2 beta 1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the Setting[OPT_includepath] parameter to (1) adminhelp.php; and (2) admin.incl.php, (3) reg.incl.php,… | EXPLOIT ✓MEDIUM 6.8EPSS 28.7% | 19 October 2007 |
| CVE-2007-5574 | PHP remote file inclusion vulnerability in djpage.php in PHPDJ 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 27.6% | 18 October 2007 |
| CVE-2007-5511 | SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 allows attackers to execute arbitrary SQL commands via the FINDRICSET procedure in the LT package. | EXPLOIT ×3 ✓MEDIUM 6.5EPSS 31.8% | 17 October 2007 |
| CVE-2007-5467 | Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long USER command containing "%s" sequences to the pop3 port (110/tcp), which are expanded to "%%s" before… | EXPLOIT ×4 ✓HIGH 10.0EPSS 13.5% | 15 October 2007 |
| CVE-2007-5466 | Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strings to the IMAP port (143/tcp); (2) execute arbitrary code via a long string in an IMAP AUTHENTICATE PLAIN action,… | EXPLOIT ×3 ✓HIGH 10.0EPSS 19.9% | 15 October 2007 |
| CVE-2007-5461 | Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request… | EXPLOIT ×2 ✓LOW 3.5EPSS 39.7% | 15 October 2007 |
| CVE-2007-5457 | Multiple PHP remote file inclusion vulnerabilities in Michael Dempfle Joomla Flash Uploader (com_jfu or com_joomla_flash_uploader) 2.5.1 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path… | EXPLOIT ✓MEDIUM 6.8EPSS 37.6% | 14 October 2007 |
| CVE-2007-5456 | Microsoft Internet Explorer 7 and earlier allows remote attackers to bypass the "File Download - Security Warning" dialog box and download arbitrary .exe files by placing a '?' (question mark) followed by a non-.exe filename after the .exe filename, as… | HIGH 7.5EPSS 19.9% | 14 October 2007 |
| CVE-2007-5451 | PHP remote file inclusion vulnerability in admin.color.php in the com_colorlab (aka com_color) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 31.2% | 14 October 2007 |
| CVE-2007-4995 | Off-by-one error in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8f allows remote attackers to execute arbitrary code via unspecified vectors. | HIGH 9.3EPSS 10.5% | 13 October 2007 |
| CVE-2007-5330 | The cadbd RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to (1) execute arbitrary code via stack-based buffer overflows in unspecified RPC procedures, and (2) trigger memory… | HIGH 10.0EPSS 13.5% | 13 October 2007 |
| CVE-2007-5327 | Stack-based buffer overflow in the RPC interface for the Message Engine (mediasvr.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a long argument in the 0x10d… | HIGH 10.0EPSS 16.1% | 13 October 2007 |
| CVE-2007-5326 | Multiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote attackers to execute arbitrary code via unspecified vectors. | HIGH 10.0EPSS 11.9% | 13 October 2007 |
| CVE-2007-5325 | Multiple buffer overflows in (1) the Message Engine and (2) AScore.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote attackers to execute arbitrary code via unspecified vectors. | HIGH 10.0EPSS 11.9% | 13 October 2007 |
| CVE-2007-5208 | hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a from address, which is not properly handled when invoking… | EXPLOIT ✓HIGH 7.6EPSS 67.3% | 13 October 2007 |
| CVE-2007-5423 | tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function. | EXPLOIT ×2 ✓HIGH 7.5EPSS 76.7% | 12 October 2007 |
| CVE-2007-5412 | Multiple PHP remote file inclusion vulnerabilities in the Quoc-Huy MP3 Allopass (com_mp3_allopass) 1.0 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter to (1) allopass.php and (2)… | EXPLOIT ✓MEDIUM 6.8EPSS 37.5% | 12 October 2007 |
| CVE-2007-5407 | Multiple PHP remote file inclusion vulnerabilities in the JContentSubscription (com_jcs) 1.5.8 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) jcs.function.php; (2)… | EXPLOIT ✓MEDIUM 6.8EPSS 40.2% | 12 October 2007 |
| CVE-2007-5388 | Multiple PHP remote file inclusion vulnerabilities in WebDesktop 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) app parameter to apps/apps.php and the (2) wsk parameter to wsk/wsk.php. | EXPLOIT ✓MEDIUM 6.8EPSS 38.4% | 12 October 2007 |
| CVE-2007-5387 | PHP remote file inclusion vulnerability in active/components/xmlrpc/client.php in Pindorama 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the c[components] parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 28.9% | 12 October 2007 |
| CVE-2007-5381 | Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute arbitrary code by setting a long hostname on the target system, then causing an error message to… | EXPLOIT ✓HIGH 9.3EPSS 14.7% | 12 October 2007 |
| CVE-2007-5365 | Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon… | EXPLOIT ✓HIGH 7.2EPSS 80.3% | 11 October 2007 |
| CVE-2007-5169 | Stack-based buffer overflow in MAIPM6.dll in Adobe PageMaker 7.0.1 and 7.0.2 on Windows allows user-assisted remote attackers to execute arbitrary code via a long font name in a .PMD file. | HIGH 9.3EPSS 10.2% | 11 October 2007 |
| CVE-2007-5363 | PHP remote file inclusion vulnerability in admin.panoramic.php in the Panoramic Picture Viewer (com_panoramic) mambot (plugin) 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 31.4% | 11 October 2007 |
| CVE-2007-5362 | Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to… | EXPLOIT ✓MEDIUM 6.8EPSS 36.5% | 11 October 2007 |
| CVE-2007-3896 | The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as… | EXPLOIT ✓HIGH 9.3EPSS 53.8% | 11 October 2007 |
| CVE-2007-5322 | Insecure method vulnerability in the FPOLE.OCX 6.0.8450.0 ActiveX control in Microsoft Visual FoxPro 6.0 allows remote attackers to execute arbitrary programs by specifying them as an argument to the FoxDoCmd function. | EXPLOIT ✓HIGH 7.5EPSS 18.6% | 9 October 2007 |
| CVE-2007-4466 | Multiple stack-based buffer overflows in Electronic Arts (EA) SnoopyCtrl ActiveX control (NPSnpy.dll) allow remote attackers to execute arbitrary code via unspecified methods and parameters. | EXPLOIT ✓MEDIUM 6.8EPSS 30.9% | 9 October 2007 |
| CVE-2007-3899 | Unspecified vulnerability in Microsoft Word 2000 SP3, Word 2002 SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string in a Word file, aka "Word Memory Corruption Vulnerability." | HIGH 9.3EPSS 29.2% | 9 October 2007 |
| CVE-2007-3897 | Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary code via long NNTP responses that trigger memory corruption. | HIGH 9.3EPSS 54.6% | 9 October 2007 |
| CVE-2007-3893 | Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via unspecified vectors involving memory corruption from an unhandled error. | MEDIUM 6.8EPSS 24.2% | 9 October 2007 |
| CVE-2007-3892 | Microsoft Internet Explorer 5.01 through 7 allows remote attackers to spoof the URL address bar and other "trust UI" components via unspecified vectors, a different issue than CVE-2007-1091 and CVE-2007-3826. | HIGH 7.5EPSS 25.6% | 9 October 2007 |
| CVE-2007-2228 | rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service… | HIGH 7.8EPSS 43.3% | 9 October 2007 |
| CVE-2007-2217 | Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote attackers to execute arbitrary code via crafted image files that trigger memory corruption, as demonstrated by a certain .tif (TIFF)… | EXPLOIT ×2 ✓HIGH 9.3EPSS 41.4% | 9 October 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.