Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 299 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-0446 | Stack-based buffer overflow in magentproc.exe for Hewlett-Packard Mercury LoadRunner Agent 8.0 and 8.1, Performance Center Agent 8.0 and 8.1, and Monitor over Firewall 8.1 allows remote attackers to execute arbitrary code via a packet with a long… | HIGH 10.0EPSS 44.7% | 8 February 2007 |
| CVE-2007-0816 | The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlier allows remote attackers to cause a denial of service (service crash) via a crafted TADDR2UADDR that triggers a null pointer… | EXPLOIT ✓MEDIUM 5.0EPSS 11.4% | 7 February 2007 |
| CVE-2007-0811 | Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an… | EXPLOIT ✓MEDIUM 4.3EPSS 18.1% | 7 February 2007 |
| CVE-2007-0796 | Blue Coat Systems WinProxy 6.1a and 6.0 r1c, and possibly earlier, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long HTTP CONNECT request, which triggers heap corruption. | HIGH 7.5EPSS 12.7% | 6 February 2007 |
| CVE-2007-0785 | PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 68.8% | 6 February 2007 |
| CVE-2007-0675 | A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista, when the Speech Recognition feature is enabled, allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized… | HIGH 7.6EPSS 17.7% | 3 February 2007 |
| CVE-2007-0674 | Pictures and Videos on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows user-assisted remote attackers to cause a denial of service (device hang) via a malformed JPEG file. | HIGH 7.1EPSS 16.5% | 3 February 2007 |
| CVE-2007-0671 | Microsoft Office Excel Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 43.2% | 3 February 2007 |
| CVE-2007-0656 | PHP remote file inclusion vulnerability in includes/functions.php in phpBB2-MODificat 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 16.2% | 1 February 2007 |
| CVE-2007-0646 | Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when… | EXPLOIT ✓HIGH 7.1EPSS 10.2% | 1 February 2007 |
| CVE-2007-0612 | Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in… | EXPLOIT ✓HIGH 7.8EPSS 43.9% | 31 January 2007 |
| CVE-2007-0465 | Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename. | EXPLOIT ✓HIGH 7.6EPSS 18.5% | 31 January 2007 |
| CVE-2007-0584 | PHP remote file inclusion vulnerability in membres/membreManager.php in PhP Generic Library & Framework for comm (g-neric) allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter. | EXPLOIT ✓HIGH 7.5EPSS 70.4% | 30 January 2007 |
| CVE-2007-0464 | The _CFNetConnectionWillEnqueueRequests function in CFNetwork 129.19 on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application crash) via a crafted HTTP 301 response, which results in a NULL pointer… | EXPLOIT ✓MEDIUM 5.0EPSS 14.8% | 30 January 2007 |
| CVE-2007-0455 | Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded… | HIGH 7.5EPSS 11.9% | 30 January 2007 |
| CVE-2007-0562 | Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .avi file, which triggers the crash when the user right clicks on the file. | EXPLOIT ✓MEDIUM 4.3EPSS 13.7% | 30 January 2007 |
| CVE-2007-0561 | Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) admin_linkdb.php, (2) admin_forum_prune.php, (3) admin_extensions.php, (4)… | EXPLOIT ✓HIGH 7.5EPSS 10.1% | 30 January 2007 |
| CVE-2007-0463 | Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or… | EXPLOIT ✓MEDIUM 5.0EPSS 17.7% | 29 January 2007 |
| CVE-2006-6956 | Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723. | MEDIUM 4.3EPSS 10.5% | 29 January 2007 |
| CVE-2007-0515 | Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by… | EXPLOIT ×2 ✓HIGH 9.3EPSS 38.4% | 26 January 2007 |
| CVE-2007-0494 | ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that… | MEDIUM 4.3EPSS 44.4% | 25 January 2007 |
| CVE-2007-0493 | Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that… | HIGH 7.8EPSS 12.5% | 25 January 2007 |
| CVE-2007-0444 | Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and MetaFrame XP 1.0 allows local users and remote attackers to execute arbitrary code via long arguments to the… | EXPLOIT ✓HIGH 7.2EPSS 14.0% | 24 January 2007 |
| CVE-2007-0018 | Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. | EXPLOIT ×3 ✓HIGH 9.3EPSS 36.5% | 24 January 2007 |
| CVE-2007-0468 | Stack-based buffer overflow in rcdll.dll in msdev.exe in Visual C++ (MSVC) in Microsoft Visual Studio 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a long file path in the "1 TYPELIB MOVEABLE PURE" option in an RC file. | MEDIUM 6.8EPSS 24.8% | 24 January 2007 |
| CVE-2007-0449 | Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Desktop and Business Protection Suite r2, and Desktop Management Suite (DMS) r11.0 and r11.1 allow remote… | EXPLOIT ×4 ✓HIGH 10.0EPSS 79.4% | 23 January 2007 |
| CVE-2007-0427 | Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section. | EXPLOIT ×2 ✓HIGH 9.3EPSS 31.2% | 23 January 2007 |
| CVE-2007-0021 | Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI. | EXPLOIT ✓HIGH 7.5EPSS 23.1% | 23 January 2007 |
| CVE-2007-0373 | Multiple SQL injection vulnerabilities in Joomla! | MEDIUM 6.8EPSS 12.0% | 19 January 2007 |
| CVE-2007-0356 | The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP.RootFolder property value. | EXPLOIT ✓MEDIUM 5.0EPSS 17.6% | 19 January 2007 |
| CVE-2007-0352 | Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt file composed of lines that begin with an integer followed by a space and a long string. | EXPLOIT ✓HIGH 9.3EPSS 36.6% | 19 January 2007 |
| CVE-2007-0243 | Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which… | EXPLOIT ✓MEDIUM 6.8EPSS 11.3% | 17 January 2007 |
| CVE-2007-0222 | Directory traversal vulnerability in the EmChartBean server side component for Oracle Application Server 10g allows remote attackers to read arbitrary files via unknown vectors, probably "\.." sequences in the beanId parameter. | MEDIUM 5.0EPSS 10.9% | 17 January 2007 |
| CVE-2007-0256 | VideoLAN VLC 0.8.6a allows remote attackers to cause a denial of service (application crash) via a crafted .wmv file. | EXPLOIT ×2 ✓HIGH 7.8EPSS 11.9% | 16 January 2007 |
| CVE-2006-5172 | Stack-based buffer overflow in the RPC interface in Mediasvr.exe in Computer Associates (CA) Brightstor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Protection Suites r2 allows remote attackers to execute arbitrary code via crafted… | HIGH 10.0EPSS 15.0% | 16 January 2007 |
| CVE-2006-5171 | Stack-based buffer overflow in the RPC interface in Mediasvr.exe in Computer Associates (CA) Brightstor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Protection Suites r2 allows remote attackers to execute arbitrary code via crafted… | HIGH 10.0EPSS 16.5% | 16 January 2007 |
| CVE-2007-0247 | squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFinish and (2) ftpHtmlifyListEntry functions. | EXPLOIT ✓MEDIUM 5.0EPSS 19.7% | 16 January 2007 |
| CVE-2007-0236 | Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (kernel panic) and possibly execute arbitrary code via a crafted AppleTalk request that… | EXPLOIT ✓HIGH 10.0EPSS 21.4% | 16 January 2007 |
| CVE-2007-0233 | wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL… | EXPLOIT ✓HIGH 7.5EPSS 11.6% | 13 January 2007 |
| CVE-2007-0169 | Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data… | EXPLOIT ✓HIGH 7.5EPSS 70.0% | 11 January 2007 |
| CVE-2007-0168 | The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allows remote attackers to execute arbitrary code via certain data in opnum 0xBF in an… | EXPLOIT ✓HIGH 7.5EPSS 19.9% | 11 January 2007 |
| CVE-2007-0167 | Multiple PHP file inclusion vulnerabilities in WGS-PPC (aka PPC Search Engine), as distributed with other aliases, allow remote attackers to execute arbitrary PHP code via a URL in the INC parameter in (1) config_admin.php, (2) config_main.php, (3)… | EXPLOIT ✓HIGH 7.5EPSS 10.3% | 10 January 2007 |
| CVE-2007-0034 | Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka… | HIGH 9.3EPSS 37.1% | 9 January 2007 |
| CVE-2007-0033 | Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file. | HIGH 9.3EPSS 32.4% | 9 January 2007 |
| CVE-2007-0031 | Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of… | EXPLOIT ✓HIGH 9.3EPSS 41.9% | 9 January 2007 |
| CVE-2007-0030 | Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via an Excel file with an out-of-range Column field in certain BIFF8 record types, which references arbitrary… | HIGH 9.3EPSS 32.3% | 9 January 2007 |
| CVE-2007-0029 | Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string, aka "Excel Malformed String Vulnerability." | HIGH 9.3EPSS 30.3% | 9 January 2007 |
| CVE-2007-0028 | Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an… | HIGH 9.3EPSS 33.2% | 9 January 2007 |
| CVE-2007-0024 | Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web… | EXPLOIT ×2 ✓HIGH 9.3EPSS 44.0% | 9 January 2007 |
| CVE-2007-0027 | Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via malformed IMDATA records that trigger memory corruption. | HIGH 9.3EPSS 31.4% | 9 January 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.