peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,908 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-2137 EXP PHP remote file inclusion vulnerability in master.php in OpenPHPNuke and 2.3.3 earlier allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 3.6% 2006-05-02
CVE-2006-0944 EXP Archangel Weblog 0.90.02 allows remote attackers to bypass authentication by setting the ba_admin cookie to 1. Patch early 7.5 high 3.6% 2006-03-01
CVE-2007-6082 EXP Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary P… Patch early 9.3 high 3.6% 2007-11-22
CVE-2006-4267 EXP Multiple SQL injection vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) oid paramet… Patch early 7.5 high 3.6% 2006-08-21
CVE-2017-6979 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… Patch early 7.0 high 3.6% 2017-05-22
CVE-2013-5582 EXP Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass a… Patch early 7.8 high 3.6% 2020-02-11
CVE-2003-0842 EXP Stack-based buffer overflow in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode, a… Patch early 7.5 high 3.6% 2003-11-17
CVE-2006-7120 EXP PHP remote file inclusion vulnerability in lib/php/phphtmllib-2.5.4/examples/example6.php for maintain 3.0.0-RC2 allows remote attackers to execute ar… Patch early 10.0 high 3.6% 2007-03-06
CVE-2006-2636 EXP newsadmin.asp in Katy Whitton NewsCMSLite allows remote attackers to bypass authentication and gain administrative access by setting the loggedIn cook… Patch early 7.5 high 3.6% 2006-05-30
CVE-2006-3689 EXP PHP remote file inclusion vulnerability in user-func.php in Codeworks Gnomedia SubberZ[Lite] allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 3.6% 2006-07-21
CVE-2005-3157 EXP SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL commands via the msg_send paramete… Patch early 7.5 high 3.6% 2005-10-06
CVE-2007-2503 EXP Directory traversal vulnerability in turbulence.php in PHP Turbulence 0.0.1 alpha allows remote attackers to include and execute arbitrary local files… Patch early 10.0 high 3.6% 2007-05-04
CVE-2007-2639 EXP Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside the TFTP root via unspecified ve… Patch early 10.0 high 3.6% 2007-05-13
CVE-2006-5402 EXP Multiple PHP remote file inclusion vulnerabilities in PHPmybibli 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in t… Patch early 7.5 high 3.6% 2006-10-18
CVE-2013-7375 EXP SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execute arbitr… Patch early 7.5 high 3.6% 2014-05-05
CVE-2004-0734 EXP Web_Store.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter. Patch early 7.5 high 3.6% 2004-07-27
CVE-2005-1289 EXP index.cgi in E-Cart 2004 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and possibly (2… Patch early 7.5 high 3.6% 2005-05-02
CVE-2016-0891 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM before 3.7 allow remote attackers to hijack the aut… Patch early 8.8 high 3.6% 2016-04-20
CVE-2017-15236 EXP Tiandy IP cameras 5.56.17.120 do not properly restrict a certain proprietary protocol, which allows remote attackers to read settings via a crafted re… Patch early 7.5 high 3.6% 2017-10-11
CVE-2006-4103 EXP PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 3.6% 2006-08-14
CVE-2006-4365 EXP Multiple PHP remote file inclusion vulnerabilities in VistaBB 2.0.33 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 3.6% 2006-08-26
CVE-2006-1090 EXP register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations. Patch early 7.8 high 3.6% 2006-03-09
CVE-2007-2779 EXP PHP remote file inclusion vulnerability in template_csv.php in Libstats 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 3.6% 2007-05-21
CVE-2007-4808 EXP Multiple SQL injection vulnerabilities in TLM CMS 3.2 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php in… Patch early 7.5 high 3.6% 2007-09-11
CVE-2009-0646 EXP Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login and (2)… Patch early 7.5 high 3.6% 2009-02-18
CVE-2016-0143 EXP The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2… Patch early 7.8 high 3.6% 2016-04-12
CVE-2007-2678 EXP Buffer overflow in the isChecked function in toolbar.dll in Netsprint Toolbar 1.1 might allow remote attackers to execute arbitrary code via unspecifi… Patch early 7.5 high 3.6% 2007-05-15
CVE-2007-2427 EXP SQL injection vulnerability in index.php in the pnFlashGames 1.5 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the… Patch early 7.5 high 3.6% 2007-05-02
CVE-2006-5076 EXP Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End 0.4.5 allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 3.6% 2006-09-29
CVE-2005-1161 EXP Multiple SQL injection vulnerabilities in OneWorldStore allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) ow… Patch early 7.5 high 3.6% 2005-05-02
← previous page 218 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt