peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,941 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-0140 EXP Domain Name Relay Daemon (dnrd) 2.10 and earlier allows remote malicious DNS sites to cause a denial of service and possibly execute arbitrary code vi… Patch early 7.5 high 3.5% 2002-03-25
CVE-2006-2253 EXP PHP remote file inclusion vulnerability in visible_count_inc.php in Statit 4 (060207) allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 3.5% 2006-05-09
CVE-2006-4050 EXP PHP remote file inclusion vulnerability in auto_check_renewals.php in phpAutoMembersArea (phpAMA) 3.2.4 and earlier allows remote attackers to execute… Patch early 7.5 high 3.5% 2006-08-10
CVE-2006-4278 EXP PHP remote file inclusion vulnerability in includes/layout/plain.footer.php in SportsPHool 1.0 allows remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 3.5% 2006-08-21
CVE-2014-5308 EXP Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) name paramete… Patch early 9.0 high 3.5% 2014-10-08
CVE-2023-24892 EXP Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability Patch early 8.2 high 3.5% 2023-03-14
CVE-2003-0609 EXP Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD… Patch early 7.2 high 3.5% 2003-08-27
CVE-2007-4909 EXP Interpretation conflict in WinSCP before 4.0.4 allows remote attackers to perform arbitrary file transfers with a remote server via file-transfer comm… Patch early 9.3 high 3.5% 2007-09-17
CVE-2019-19726 EXP OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be defeated by setting a very sm… Patch early 7.8 high 3.5% 2019-12-12
CVE-2003-0391 EXP Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cause a denial of service (crash)… Patch early 7.5 high 3.5% 2003-07-02
CVE-2021-30147 EXP DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php. Patch early 8.8 high 3.5% 2021-04-07
CVE-2017-14838 EXP TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange. Patch early 8.8 high 3.5% 2017-09-28
CVE-2017-14839 EXP TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover. Patch early 8.8 high 3.5% 2017-09-28
CVE-2017-14840 EXP TeamWork TicketPlus allows Arbitrary File Upload in updateProfile. Patch early 8.8 high 3.5% 2017-09-28
CVE-2005-1054 EXP PHP remote file inclusion vulnerability in news.php in ModernBill 4.3.0 and earlier allows remote attackers to execute arbitrary PHP code by modifying… Patch early 7.5 high 3.5% 2005-05-02
CVE-2007-2157 EXP Directory traversal vulnerability in upload/force_download.php in Zomplog 3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in th… Patch early 7.8 high 3.5% 2007-04-19
CVE-2013-3527 EXP Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the parameter na… Patch early 7.5 high 3.5% 2013-05-10
CVE-2006-1543 EXP Multiple SQL injection vulnerabilities in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to execute arbitrary SQL commands via the (1… Patch early 7.5 high 3.5% 2006-03-30
CVE-2010-2892 EXP gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbit… Patch early 8.5 high 3.5% 2010-11-15
CVE-2020-15255 EXP In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treate… Patch early 8.7 high 3.5% 2020-10-16
CVE-2008-4329 EXP PHP remote file inclusion vulnerability in cms/system/openengine.php in openEngine 2.0 beta4 and earlier allows remote attackers to execute arbitrary… Patch early 10.0 high 3.5% 2008-09-30
CVE-2008-6651 EXP Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbitrary PHP code into oxyhistory.… Patch early 10.0 high 3.5% 2009-04-07
CVE-2008-0513 EXP Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote attackers to read arbitrary files via a .. (d… Patch early 7.8 high 3.5% 2008-01-31
CVE-2004-2071 EXP Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authentication in the web interface via a… Patch early 7.5 high 3.5% 2004-12-31
CVE-2005-0854 EXP betaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload files via a direct request to… Patch early 7.5 high 3.5% 2005-05-02
CVE-2006-5281 EXP PHP remote file inclusion vulnerability in naboard_pnr.php in n@board 3.1.9e and earlier allows remote attackers to execute arbitrary PHP code via a U… Patch early 7.5 high 3.5% 2006-10-13
CVE-2007-1600 EXP PHP remote file inclusion vulnerability in module.php in Digital Eye Gallery 1.1 Beta (aka 0.1.1b) allows remote attackers to execute arbitrary PHP co… Patch early 9.3 high 3.5% 2007-03-22
CVE-2007-4007 EXP PHP remote file inclusion vulnerability in index.php in Article Directory (Article Site Directory) allows remote attackers to execute arbitrary PHP co… Patch early 9.3 high 3.5% 2007-07-26
CVE-2004-2161 EXP SQL injection vulnerability in file_overview.php in TUTOS 1.1 allows remote attackers to execute arbitrary SQL commands via the link_id parameter. Patch early 7.5 high 3.5% 2004-12-31
CVE-2007-2843 EXP Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demons… Patch early 10.0 high 3.5% 2007-05-24
← previous page 221 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt