peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,893 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-2886 EXP PHP remote file inclusion vulnerability in include/plugins/jrBrowser/purchase.php in Jamroom 3.3.0 through 3.3.5, when register_globals is enabled, al… Patch early 9.3 high 3.8% 2008-06-27
CVE-2006-6889 EXP FreeStyle Wiki (fswiki) 3.6.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attack… Patch early 7.5 high 3.8% 2006-12-31
CVE-2003-0561 EXP Multiple buffer overflows in IglooFTP PRO 3.8 allow remote FTP servers to execute arbitrary code via (1) a long FTP banner, or long responses to the c… Patch early 7.5 high 3.8% 2003-08-18
CVE-2008-4421 EXP Directory traversal vulnerability in MetaGauge 1.0.0.17, and probably other versions before 1.0.3.38, allows remote attackers to read arbitrary files… Patch early 7.8 high 3.8% 2008-10-07
CVE-2010-3134 EXP Untrusted search path vulnerability in Google Earth 5.1.3535.3218 allows local users, and possibly remote attackers, to execute arbitrary code and con… Patch early 9.3 high 3.8% 2010-08-26
CVE-2006-6284 EXP Directory traversal vulnerability in admin.php in Vikingboard 0.1.2 allows remote authenticated administrators to include arbitrary files via a .. (do… Patch early 9.0 high 3.8% 2006-12-04
CVE-2016-5425 EXP The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions fo… Patch early 7.8 high 3.8% 2016-10-13
CVE-2004-2018 EXP PHP remote file inclusion vulnerability in index.php in Php-Nuke 6.x through 7.3 allows remote attackers to execute arbitrary PHP code by modifying th… Patch early 7.5 high 3.8% 2004-12-31
CVE-2005-3797 EXP PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 3.8% 2005-11-24
CVE-2007-0495 EXP PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 10.0 high 3.8% 2007-01-25
CVE-2011-0960 EXP Multiple SQL injection vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 3.8% 2011-05-20
CVE-2002-0953 EXP globals.php in PHP Address before 0.2f, with the PHP allow_url_fopen and register_globals variables enabled, allows remote attackers to execute arbitr… Patch early 7.5 high 3.8% 2002-10-04
CVE-2019-0732 EXP A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls t… Patch early 7.8 high 3.8% 2019-04-09
CVE-2012-3485 EXP Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname or (2) executable file pathname… Patch early 7.2 high 3.8% 2012-08-26
CVE-2011-5005 EXP Unrestricted file upload vulnerability in QuiXplorer 2.3 and earlier allows remote attackers to execute arbitrary code by uploading a file with an exe… Patch early 7.5 high 3.8% 2011-12-25
CVE-2006-6816 EXP Multiple SQL injection vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified p… Patch early 7.5 high 3.8% 2006-12-29
CVE-2005-0999 EXP SQL injection vulnerability in the Top module for PHP-Nuke 6.x through 7.6 allows remote attackers to execute arbitrary SQL commands via the querylang… Patch early 7.5 high 3.8% 2005-05-02
CVE-1999-0791 EXP Hybrid Network cable modems do not include an authentication mechanism for administration, allowing remote attackers to compromise the system through… Patch early 10.0 high 3.8% 1999-10-06
CVE-2007-4226 EXP Directory traversal vulnerability in the BlueCat Networks Proteus IPAM appliance 2.0.2.0 (Adonis DNS/DHCP appliance 5.0.2.8) allows remote authenticat… Patch early 7.1 high 3.8% 2007-08-08
CVE-2009-5137 EXP Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a long URL in the [playlist] secti… Patch early 7.5 high 3.8% 2014-01-03
CVE-2006-5100 EXP PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute arbitrary PH… Patch early 7.5 high 3.8% 2006-10-03
CVE-2006-5620 EXP PHP remote file inclusion vulnerability in include/menu_builder.php in MiniBILL 2006-10-10 (1.2.3) and earlier, when register_globals is enabled, allo… Patch early 7.5 high 3.8% 2006-10-31
CVE-2006-5760 EXP Multiple PHP remote file inclusion vulnerabilities in phpDynaSite 3.2.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 3.8% 2006-11-06
CVE-2007-0919 EXP Directory traversal vulnerability in Nickolas Grigoriadis Mini Web server (MiniWebsvr) 0.0.6 allows remote attackers to list the directory immediately… Patch early 7.8 high 3.8% 2007-02-14
CVE-2006-4953 EXP Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary SQL commands via the (1) adr_s… Patch early 7.5 high 3.8% 2006-09-23
CVE-2002-1767 EXP Buffer overflow in tnslsnr of Oracle 8i Database Server 8.1.5 for Linux allows local users to execute arbitrary code as the oracle user via a long com… Patch early 7.2 high 3.8% 2002-12-31
CVE-2010-3944 EXP win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate user-mode input, which allows local… Patch early 7.2 high 3.8% 2010-12-16
CVE-2009-2223 EXP Directory traversal vulnerability in locms/smarty.php in LightOpenCMS 0.1 allows remote attackers to include and execute arbitrary local files via a .… Patch early 9.3 high 3.8% 2009-06-26
CVE-2015-1725 EXP Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win… Patch early 7.2 high 3.8% 2015-06-10
CVE-2009-1780 EXP admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to… Patch early 7.5 high 3.8% 2009-05-22
← previous page 214 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt