Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,957 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,392 results · page 294 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-5315 | PHP remote file inclusion vulnerability in common.php in LiveAlbum 0.9.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the livealbum_dir parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 38.6% | 9 October 2007 |
| CVE-2007-5301 | Buffer overflow in the vorbis_stream_info function in input/vorbis/vorbis_engine.c (aka the vorbis input plugin) in AlsaPlayer before 0.99.80-rc3 allows remote attackers to execute arbitrary code via a .OGG file with long comments. | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 10.2% | 9 October 2007 |
| CVE-2007-5271 | Multiple PHP remote file inclusion vulnerabilities in Trionic Cite CMS 1.2 rev9 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the bField[bf_data] parameter to (1) interface/editors/-custom.php or (2)… | EXPLOIT ✓MEDIUM 6.8EPSS 28.7% | 8 October 2007 |
| CVE-2007-4924 | The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length header field in Session Initiation Protocol (SIP)… | EXPLOIT ✓MEDIUM 5.0EPSS 10.7% | 8 October 2007 |
| CVE-2007-5257 | Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allows remote attackers to execute arbitrary code via long strings in the first and second arguments to the… | EXPLOIT ✓HIGH 10.0EPSS 15.2% | 6 October 2007 |
| CVE-2007-5244 | Stack-based buffer overflow in Borland InterBase LI 8.0.0.53 through 8.1.0.253 on Linux, and possibly unspecified versions on Solaris, allows remote attackers to execute arbitrary code via a long attach request on TCP port 3050 to the open_marker_file… | EXPLOIT ×2 ✓HIGH 9.3EPSS 37.5% | 6 October 2007 |
| CVE-2007-5243 | Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0.257, allow remote attackers to execute arbitrary code via (1) a long service attach request on TCP port 3050 to the (a) SVC_attach… | EXPLOIT ×12 ✓HIGH 9.3EPSS 40.1% | 6 October 2007 |
| CVE-2007-5234 | PHP remote file inclusion vulnerability in upload/common/footer.php in Ossigeno CMS 2.2 alpha3 allows remote attackers to execute arbitrary PHP code via a URL in the level parameter. | EXPLOIT ✓HIGH 7.5EPSS 42.3% | 5 October 2007 |
| CVE-2007-4990 | The swap_char2b function in X.Org X Font Server (xfs) before 1.0.5 allows context-dependent attackers to execute arbitrary code via (1) QueryXBitmaps and (2) QueryXExtents protocol requests with crafted size values that specify an arbitrary number of… | HIGH 7.5EPSS 10.7% | 5 October 2007 |
| CVE-2007-5219 | Directory traversal vulnerability in the CLAVSetting.CLSetting.1 ActiveX control in CLAVSetting.DLL 1.00.1829 in the CLAVSetting module in CyberLink PowerDVD 7.0 allows remote attackers to create or overwrite arbitrary files via a .. | EXPLOIT ✓MEDIUM 6.4EPSS 15.7% | 5 October 2007 |
| CVE-2007-5217 | Stack-based buffer overflow in the ADM4 ActiveX control in adm4.dll in Altnet Download Manager 4.0.0.6, as used in (1) Kazaa 3.2.7 and (2) Grokster, allows remote attackers to execute arbitrary code via a long argument to the Install method. | EXPLOIT ✓MEDIUM 6.8EPSS 30.0% | 5 October 2007 |
| CVE-2007-5186 | PHP remote file inclusion vulnerability in index.php in Segue CMS 1.8.4 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the themesdir parameter, a different vector than CVE-2006-5497. | EXPLOIT ✓MEDIUM 6.8EPSS 46.8% | 3 October 2007 |
| CVE-2007-5185 | Multiple PHP remote file inclusion vulnerabilities in phpWCMS XT 0.0.7 BETA and earlier allow remote attackers to execute arbitrary PHP code via a URL in the HTML_MENU_DirPath parameter to (1) config_HTML_MENU.php and (2) config_PHPLM.php in… | EXPLOIT ✓MEDIUM 6.8EPSS 42.3% | 3 October 2007 |
| CVE-2007-5184 | Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute arbitrary code via format string specifiers in a directory name. | EXPLOIT ✓HIGH 7.5EPSS 12.5% | 3 October 2007 |
| CVE-2007-5083 | Multiple integer overflows in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute arbitrary code via unspecified CsAgent service commands that trigger a heap-based buffer overflow. | HIGH 10.0EPSS 18.7% | 1 October 2007 |
| CVE-2007-5082 | Multiple stack-based buffer overflows in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute arbitrary code via unspecified CsAgent service commands with certain opcodes, related to… | EXPLOIT ×2 ✓HIGH 10.0EPSS 63.5% | 1 October 2007 |
| CVE-2007-5006 | Multiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer is authenticated, which allows remote attackers to add and delete users, and start client restores. | HIGH 10.0EPSS 21.2% | 1 October 2007 |
| CVE-2007-5003 | Multiple stack-based buffer overflows in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allow remote attackers to execute arbitrary code via a long (1) username or (2) password to the rxrLogin command in… | EXPLOIT ✓HIGH 10.0EPSS 67.2% | 1 October 2007 |
| CVE-2007-5158 | The focus handling for the onkeydown event in Microsoft Internet Explorer 6.0 allows remote attackers to change field focus and copy keystrokes via a certain use of a JavaScript htmlFor attribute, as demonstrated by changing focus from a textarea to a… | EXPLOIT ✓MEDIUM 4.3EPSS 15.0% | 1 October 2007 |
| CVE-2007-5145 | Multiple buffer overflows in system DLL files in Microsoft Windows XP, as used by Microsoft Windows Explorer (explorer.exe) 6.00.2900.2180, Don Ho Notepad++, unspecified Adobe Macromedia applications, and other programs, allow user-assisted remote… | MEDIUM 4.3EPSS 12.8% | 1 October 2007 |
| CVE-2007-5144 | Buffer overflow in the GDI engine in Windows Live Messenger, as used for Windows MSN Live 8.1, allows user-assisted remote attackers to cause a denial of service (application crash or system crash) and possibly execute arbitrary code by placing a… | MEDIUM 4.3EPSS 16.5% | 1 October 2007 |
| CVE-2007-4880 | Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via… | EXPLOIT ×2 ✓HIGH 10.0EPSS 75.9% | 28 September 2007 |
| CVE-2007-5135 | Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. | MEDIUM 6.8EPSS 16.1% | 27 September 2007 |
| CVE-2007-5133 | Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service (CPU consumption) via a certain PNG file with a large tEXt chunk that possibly triggers an integer overflow in PNG chunk size handling, as… | EXPLOIT ✓HIGH 7.1EPSS 22.9% | 27 September 2007 |
| CVE-2007-5107 | Stack-based buffer overflow in the AskJeevesToolBar.SettingsPlugin.1 ActiveX control in askBar.dll in IAC Search & Media ask.com Ask Toolbar 4.0.2.53 and earlier allows remote attackers to execute arbitrary code via a long ShortFormat property value. | EXPLOIT ×2 ✓HIGH 9.3EPSS 35.9% | 26 September 2007 |
| CVE-2007-5102 | PHP remote file inclusion vulnerability in config.inc.php in Wordsmith 1.0 RC1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the _path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 38.6% | 26 September 2007 |
| CVE-2007-5099 | PHP remote file inclusion vulnerability in show.php in David Watters Helplink 0.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. | EXPLOIT ✓HIGH 7.5EPSS 53.0% | 26 September 2007 |
| CVE-2007-5098 | Multiple PHP remote file inclusion vulnerabilities in DFD Cart 1.1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the set_depth parameter to (1)… | EXPLOIT ✓MEDIUM 6.8EPSS 46.0% | 26 September 2007 |
| CVE-2007-5095 | Microsoft Windows Media Player (WMP) 9 on Windows XP SP2 invokes Internet Explorer to render HTML documents contained inside some media files, regardless of what default web browser is configured, which might allow remote attackers to exploit… | HIGH 7.5EPSS 15.2% | 26 September 2007 |
| CVE-2007-5067 | Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long If-Modified-Since header to (1) xigui32.exe or (2) xitami.exe. | EXPLOIT ×2 ✓HIGH 7.5EPSS 73.2% | 24 September 2007 |
| CVE-2007-5065 | PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (com_slideshow) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. | EXPLOIT ✓HIGH 7.5EPSS 42.3% | 24 September 2007 |
| CVE-2007-5056 | Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open-Realty, allows remote attackers to execute arbitrary code via PHP… | EXPLOIT ×5 ✓MEDIUM 6.8EPSS 27.9% | 24 September 2007 |
| CVE-2007-5054 | Multiple PHP remote file inclusion vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the gsLanguage parameter to (1) search/search.php, (2) poll/inlinepoll.php, (3) poll/showpoll.php, (4)… | EXPLOIT ✓HIGH 7.5EPSS 42.3% | 24 September 2007 |
| CVE-2007-4991 | The SOCKS4 Proxy in Microsoft Internet Security and Acceleration (ISA) Server 2004 SP1 and SP2 allows remote attackers to obtain potentially sensitive information (the destination IP address of another user's session) via an empty packet. | MEDIUM 5.0EPSS 16.1% | 21 September 2007 |
| CVE-2007-0063 | Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build… | HIGH 10.0EPSS 20.4% | 21 September 2007 |
| CVE-2007-5020 | Unspecified vulnerability in Adobe Acrobat and Reader 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted PDF file, related to the mailto: option and Internet Explorer 7 on Windows XP. | HIGH 9.3EPSS 20.4% | 21 September 2007 |
| CVE-2007-5019 | Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attackers to have an unknown impact via a long argument to the dnsResolve (isInstalled.dnsResolve) method. | EXPLOIT ✓HIGH 10.0EPSS 10.5% | 20 September 2007 |
| CVE-2007-5015 | Multiple PHP remote file inclusion vulnerabilities in Streamline PHP Media Server 1.0-beta4 allow remote attackers to execute arbitrary PHP code via a URL in the sl_theme_unix_path parameter to (1) admin_footer.php, (2) info_footer.php, (3)… | EXPLOIT ✓MEDIUM 6.8EPSS 38.6% | 20 September 2007 |
| CVE-2007-5009 | PHP remote file inclusion vulnerability in language/lang_german/lang_main_album.php in phpBB Plus 1.53, and 1.53a before 20070922, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 45.0% | 20 September 2007 |
| CVE-2007-4983 | Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic and 7.0.3.3016 allows remote attackers to create or overwrite arbitrary local files via a ..\ (dot dot backslash) in the second… | EXPLOIT ✓HIGH 10.0EPSS 47.3% | 19 September 2007 |
| CVE-2007-4982 | Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Technologies QRCode ActiveX 3.0.0.1 and earlier allow remote attackers to create or overwrite arbitrary files via a full pathname in the… | EXPLOIT ✓HIGH 10.0EPSS 10.4% | 19 September 2007 |
| CVE-2007-4965 | Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the… | EXPLOIT ✓MEDIUM 5.8EPSS 14.0% | 18 September 2007 |
| CVE-2007-3010 | Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability | KEVEXPLOIT ×3 ✓CRITICAL 9.8EPSS 97.4% | 18 September 2007 |
| CVE-2007-2834 | Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which… | HIGH 9.3EPSS 12.0% | 18 September 2007 |
| CVE-2007-4955 | PHP remote file inclusion vulnerability in admin.joomlaflashfun.php in the Flash Fun! | EXPLOIT ✓MEDIUM 6.8EPSS 30.0% | 18 September 2007 |
| CVE-2007-4954 | PHP remote file inclusion vulnerability in admin.joom12pic.php in the joom12Pic (com_joom12pic) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 28.7% | 18 September 2007 |
| CVE-2007-4939 | Heap-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allows remote attackers to cause a denial of service… | EXPLOIT ✓HIGH 9.3EPSS 11.9% | 18 September 2007 |
| CVE-2007-4938 | Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and… | EXPLOIT ✓HIGH 7.6EPSS 16.0% | 18 September 2007 |
| CVE-2007-4934 | Multiple PHP remote file inclusion vulnerabilities in phpFFL 1.24 allow remote attackers to execute arbitrary PHP code via a URL in the PHPFFL_FILE_ROOT parameter to (1) program_files/livedraft/livedraft.php or (2) program_files/livedraft/admin.php. | EXPLOIT ✓MEDIUM 4.6EPSS 21.7% | 18 September 2007 |
| CVE-2007-4923 | PHP remote file inclusion vulnerability in admin.joomlaradiov5.php in the Joomla Radio 5 (com_joomlaradiov5) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 41.6% | 17 September 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.