2007 CVE Vulnerabilities
6,580 CVEs published in 2007.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2007-2563 | — | — | 7.2% | May 9, 2007 | Buffer overflow in the AddFile function in VersalSoft HTTP File Upload ActiveX control (UFileUploaderD.dll) allows remot... |
| CVE-2007-2562 | — | — | 1.0% | May 9, 2007 | Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 3.00.90 allows remote attackers to inject arbit... |
| CVE-2007-2561 | — | — | 1.0% | May 9, 2007 | SQL injection vulnerability in index.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via th... |
| CVE-2007-2560 | — | — | 2.7% | May 9, 2007 | Directory traversal vulnerability in theme/acgv.php in ACGVannu 1.3 and earlier allows remote attackers to read arbitrar... |
| CVE-2007-2559 | — | — | 1.7% | May 9, 2007 | Multiple PHP remote file inclusion vulnerabilities in american cart 3.5 allow remote attackers to execute arbitrary PHP ... |
| CVE-2007-2553 | — | — | 0.9% | May 9, 2007 | Unspecified vulnerability in dop in HP Tru64 UNIX 5.1B-4, 5.1B-3, and 5.1A PK6 allows local users to gain privileges via... |
| CVE-2007-2555 | — | — | 1.0% | May 9, 2007 | Unspecified vulnerability in Default.aspx in Podium CMS allows remote attackers to have an unknown impact, possibly sess... |
| CVE-2007-0605 | — | — | 2.0% | May 9, 2007 | Cross-site scripting (XSS) vulnerability in picture.php in Advanced Guestbook 2.4.2 allows remote attackers to inject ar... |
| CVE-2007-0608 | — | — | 1.8% | May 9, 2007 | Advanced Guestbook 2.4.2 allows remote attackers to obtain sensitive information via an invalid (1) GB_TBL parameter to ... |
| CVE-2007-0609 | — | — | 7.5% | May 9, 2007 | Directory traversal vulnerability in Advanced Guestbook 2.4.2 allows remote attackers to bypass .htaccess settings, and ... |
| CVE-2007-2554 | — | — | 1.4% | May 9, 2007 | Associated Press (AP) Newspower 4.0.1 and earlier uses a default blank password for the MySQL root account, which allows... |
| CVE-2007-2552 | — | — | 1.5% | May 9, 2007 | The RecentChanges feature in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to obtain the names, and poss... |
| CVE-2007-2546 | — | — | 1.5% | May 9, 2007 | Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web se... |
| CVE-2007-2548 | — | — | 1.0% | May 9, 2007 | Unspecified vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 has unknown impact and an l remote a... |
| CVE-2007-2549 | — | — | 1.2% | May 9, 2007 | SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to execute... |
| CVE-2007-2547 | — | — | 1.6% | May 9, 2007 | Cross-site scripting (XSS) vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attacke... |
| CVE-2007-2551 | — | — | 1.2% | May 9, 2007 | Cross-site scripting (XSS) vulnerability in usersettings.php in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote atta... |
| CVE-2007-2550 | — | — | 2.2% | May 9, 2007 | Multiple CRLF injection vulnerabilities in Devellion CubeCart 3.0.15 allow remote attackers to inject arbitrary HTTP hea... |
| CVE-2007-2535 | — | — | 2.7% | May 9, 2007 | WinAce allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure ... |
| CVE-2007-1673 | — | — | 3.2% | May 9, 2007 | unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of s... |
| CVE-2007-2545 | — | — | 68.8% | May 9, 2007 | Multiple PHP remote file inclusion vulnerabilities in Persism CMS 0.9.2 and earlier allow remote attackers to execute ar... |
| CVE-2007-2544 | — | — | 3.2% | May 9, 2007 | PHP remote file inclusion vulnerability in templates/default/tpl_message.php in PHP TopTree BBS 2.0.1a and earlier allow... |
| CVE-2007-2543 | — | — | 1.2% | May 9, 2007 | SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbi... |
| CVE-2007-2536 | — | — | 8.5% | May 9, 2007 | PicoZip allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure... |
| CVE-2007-2537 | — | — | 1.1% | May 9, 2007 | Multiple SQL injection vulnerabilities in mainfile.php in NPDS 5.10 and earlier allow remote authenticated users to exec... |
Check if your code is affected by 2007 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now