Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,957 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,392 results · page 295 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-4921 | PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attackers to execute arbitrary PHP code via a URL in the approot parameter. | EXPLOIT ✓HIGH 7.5EPSS 52.8% | 17 September 2007 |
| CVE-2007-4916 | Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard… | EXPLOIT ×2 ✓HIGH 10.0EPSS 19.7% | 17 September 2007 |
| CVE-2007-4915 | The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from entering memory locations used for string constants, which allows remote attackers to change the admin password… | EXPLOIT ×2 ✓HIGH 10.0EPSS 68.2% | 17 September 2007 |
| CVE-2007-4906 | PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 38.4% | 17 September 2007 |
| CVE-2007-4897 | pwlib, as used by Ekiga 2.0.5 and possibly other products, allows remote attackers to cause a denial of service (application crash) via a long argument to the PString::vsprintf function, related to a "memory management flaw". | EXPLOIT ✓MEDIUM 5.0EPSS 10.9% | 14 September 2007 |
| CVE-2007-4891 | A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5) CABFileName, and (6) CABRunFile methods, which allows remote attackers… | EXPLOIT ✓MEDIUM 6.8EPSS 31.0% | 14 September 2007 |
| CVE-2007-4890 | Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1.0.0.0 in Microsoft Visual Studio 6.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the… | EXPLOIT ✓MEDIUM 5.8EPSS 16.4% | 14 September 2007 |
| CVE-2007-4465 | Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the… | MEDIUM 6.1EPSS 26.2% | 14 September 2007 |
| CVE-2007-4834 | Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP code via a URL in the MGR parameter to (1) index.php, (2) p_ins.php, and (3) u_ins.php in manager/admin/. | EXPLOIT ✓HIGH 7.5EPSS 58.5% | 12 September 2007 |
| CVE-2007-4727 | Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows remote attackers to overwrite arbitrary CGI variables and execute arbitrary code via an HTTP request with a long… | MEDIUM 6.8EPSS 12.9% | 12 September 2007 |
| CVE-2007-3040 | Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent… | EXPLOIT ✓HIGH 9.3EPSS 54.4% | 12 September 2007 |
| CVE-2007-4818 | Multiple PHP remote file inclusion vulnerabilities in Txx CMS 0.2 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root parameter to (1) addons/plugin.php, (2) addons/sidebar.php, (3) mail/index.php, or (4) mail/mailbox.php in… | EXPLOIT ✓HIGH 7.5EPSS 55.5% | 11 September 2007 |
| CVE-2007-4815 | Multiple PHP remote file inclusion vulnerabilities in WebED in Markus Iser ED Engine 0.8999 alpha allow remote attackers to execute arbitrary PHP code via a URL in the Codebase parameter to (1) channeledit.php, (2) post.php, (3) view.php, or (4)… | EXPLOIT ✓MEDIUM 6.8EPSS 39.4% | 11 September 2007 |
| CVE-2007-4814 | Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.2004.00 in Microsoft SQL Server Enterprise Manager 8.05.2004 allows remote attackers to execute arbitrary code via a long second… | EXPLOIT ×2 ✓HIGH 7.5EPSS 45.7% | 11 September 2007 |
| CVE-2007-4809 | Multiple PHP remote file inclusion vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 allow remote attackers to execute arbitrary PHP code via a URL in the DOC_ROOT parameter to (1) lib/functions.php or (2) lib/header.php. | EXPLOIT ✓HIGH 7.5EPSS 56.4% | 11 September 2007 |
| CVE-2007-4790 | Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the Microsoft Visual FoxPro 6.0 fpole 1.0 Type Library; and Internet Explorer 5.01, 6 SP1 and SP2, and 7; allows remote attackers to… | EXPLOIT ✓HIGH 7.5EPSS 54.9% | 10 September 2007 |
| CVE-2007-4776 | Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a Visual Basic project (vbp) file containing a long Reference line, related to VBP_Open and OLE. | EXPLOIT ×3 ✓HIGH 9.3EPSS 49.0% | 10 September 2007 |
| CVE-2007-4757 | PHP remote file inclusion vulnerability in menu.php in phpMytourney allows remote attackers to execute arbitrary PHP code via a URL in the functions_file parameter. | EXPLOIT ✓HIGH 7.5EPSS 64.7% | 8 September 2007 |
| CVE-2007-4744 | PHP remote file inclusion vulnerability in environment.php in AnyInventory 1.9.1 and 2.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DIR_PREFIX parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 60.1% | 6 September 2007 |
| CVE-2007-4738 | Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) db_conf or (2) ADODB_DIR parameter to utils/stphpimage_show.php; or a URL in the… | EXPLOIT ✓HIGH 7.5EPSS 10.7% | 6 September 2007 |
| CVE-2007-4722 | Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie07051001.dll 1.0.0.1 in Move Media Player allow remote attackers to execute arbitrary code via a long string to the (1) Play and (2) Buzzer… | EXPLOIT ×2 ✓MEDIUM 6.8EPSS 10.1% | 5 September 2007 |
| CVE-2007-4712 | PHP remote file inclusion vulnerability in index.php in eNetman 1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | EXPLOIT ✓HIGH 7.5EPSS 57.9% | 5 September 2007 |
| CVE-2007-3999 | Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some… | HIGH 10.0EPSS 11.0% | 5 September 2007 |
| CVE-2007-4476 | Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack." | EXPLOIT ✓HIGH 7.5EPSS 14.9% | 5 September 2007 |
| CVE-2007-3997 | The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir restrictions via MySQL LOCAL INFILE operations, as demonstrated by a query with LOAD DATA LOCAL INFILE. | EXPLOIT ✓HIGH 7.5EPSS 13.8% | 4 September 2007 |
| CVE-2007-4646 | Buffer overflow in the pop3 service in Hexamail Server 3.0.0.001 Lite allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long USER command. | EXPLOIT ✓HIGH 10.0EPSS 15.5% | 31 August 2007 |
| CVE-2007-4642 | Multiple buffer overflows in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allow remote attackers to execute arbitrary code via a long chat (PKT_CHAT) message that is not properly handled by the (1) D_NetPlayerEvent function in d_net.c or the (2)… | EXPLOIT ✓HIGH 10.0EPSS 16.3% | 31 August 2007 |
| CVE-2007-4636 | Multiple PHP remote file inclusion vulnerabilities in phpBG 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter to (1) intern/admin/other/backup.php, (2) intern/admin/, (3) intern/clan/member_add.php, (4)… | EXPLOIT ✓HIGH 7.5EPSS 71.1% | 31 August 2007 |
| CVE-2007-4515 | Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! | EXPLOIT ×2 ✓HIGH 9.3EPSS 33.0% | 31 August 2007 |
| CVE-2007-2954 | Multiple stack-based buffer overflows in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2 through SP4 for Windows allow remote attackers to execute arbitrary code via certain long arguments to the (1) RpcAddPrinterDriver, (2)… | HIGH 10.0EPSS 23.2% | 31 August 2007 |
| CVE-2007-2931 | Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat… | EXPLOIT ×2 ✓HIGH 9.3EPSS 55.5% | 31 August 2007 |
| CVE-2007-4607 | Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used in Postcast Server Pro 3.0.61 and other products, allows remote attackers to execute arbitrary code via a long argument to the… | EXPLOIT ×2 ✓HIGH 9.3EPSS 56.4% | 31 August 2007 |
| CVE-2007-4467 | Multiple stack-based buffer overflows in the Oracle JInitiator ActiveX control (beans.ocx) 1.1.8.16 and earlier, as used by Oracle Forms applications from Oracle and third parties, allow remote attackers to execute arbitrary code via unspecified… | HIGH 9.3EPSS 21.1% | 31 August 2007 |
| CVE-2007-4584 | Stack-based buffer overflow in BitchX 1.1 Final allows remote IRC servers to execute arbitrary code via a long string in a MODE command, related to the p_mode variable. | EXPLOIT ✓HIGH 10.0EPSS 14.7% | 29 August 2007 |
| CVE-2007-4566 | Multiple buffer overflows in the login mechanism in sidvault in Alpha Centauri Software SIDVault LDAP Server before 2.0f allow remote attackers to execute arbitrary code via crafted LDAP packets, as demonstrated by a long dc entry in an LDAP bind. | EXPLOIT ×4 ✓HIGH 10.0EPSS 15.3% | 28 August 2007 |
| CVE-2007-4560 | clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen call, involving the "recipient field of sendmail." | EXPLOIT ×3 ✓HIGH 7.6EPSS 83.5% | 28 August 2007 |
| CVE-2007-4559 | Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. | CRITICAL 9.8EPSS 27.1% | 28 August 2007 |
| CVE-2007-4556 | Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote… | MEDIUM 6.8EPSS 25.7% | 28 August 2007 |
| CVE-2007-4534 | Buffer overflow in the VThinker::BroadcastPrintf function in p_thinker.cpp in Vavoom 1.24 and earlier allows remote attackers to execute arbitrary code via (1) a long string in a chat message and possibly (2) a long name field. | EXPLOIT ✓HIGH 7.5EPSS 11.0% | 25 August 2007 |
| CVE-2007-3847 | The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer… | MEDIUM 5.0EPSS 12.9% | 23 August 2007 |
| CVE-2007-4498 | The Grandstream SIP Phone GXV-3000 with firmware 1.0.1.7, Loader 1.0.0.6, and Boot 1.0.0.18 allows remote attackers to force silent call completion, eavesdrop on the phone's local environment, and cause a denial of service (blocked call reception) via a… | EXPLOIT ✓HIGH 7.8EPSS 13.8% | 23 August 2007 |
| CVE-2007-4478 | Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6.0 and 7 allows user-assisted remote attackers to inject arbitrary web script or HTML in the local zone via a URI, when the document at the associated URL is saved to a local file,… | MEDIUM 4.3EPSS 10.7% | 22 August 2007 |
| CVE-2007-4219 | Integer overflow in the RPCFN_SYNC_TASK function in StRpcSrv.dll, as used by the ServerProtect service (SpntSvc.exe), in Trend Micro ServerProtect for Windows before 5.58 Security Patch 4 allows remote attackers to execute arbitrary code via a certain… | HIGH 10.0EPSS 10.5% | 22 August 2007 |
| CVE-2007-4218 | Multiple buffer overflows in the ServerProtect service (SpntSvc.exe) in Trend Micro ServerProtect for Windows before 5.58 Security Patch 4 allow remote attackers to execute arbitrary code via certain RPC requests to certain TCP ports that are processed… | HIGH 10.0EPSS 13.0% | 22 August 2007 |
| CVE-2007-4459 | Cisco IP Phone 7940 and 7960 with P0S3-08-6-00 firmware, and other SIP firmware before 8.7(0), allows remote attackers to cause a denial of service (device reboot) via (1) a certain sequence of 10 invalid SIP INVITE and OPTIONS messages; or (2) a… | EXPLOIT ×2 ✓HIGH 7.1EPSS 14.0% | 21 August 2007 |
| CVE-2007-4440 | Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AUTH CRAM-MD5 string. | EXPLOIT ×3 ✓HIGH 7.5EPSS 64.5% | 21 August 2007 |
| CVE-2007-4430 | Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. | EXPLOIT ✓MEDIUM 5.0EPSS 13.3% | 20 August 2007 |
| CVE-2007-4370 | Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbitrary code via a long string to UDP port 26000. | EXPLOIT ×3 ✓HIGH 7.5EPSS 59.2% | 15 August 2007 |
| CVE-2007-3891 | Unspecified vulnerability in Windows Vista Weather Gadgets in Windows Vista allows remote attackers to execute arbitrary code via crafted HTML attributes. | MEDIUM 6.8EPSS 25.2% | 14 August 2007 |
| CVE-2007-3386 | Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter… | EXPLOIT ✓MEDIUM 4.3EPSS 59.0% | 14 August 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.