peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,941 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-12603 EXP Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users… Patch early 8.8 high 3.5% 2018-06-25
CVE-2006-5893 EXP Multiple PHP remote file inclusion vulnerabilities in iWonder Designs Storystream 0.4.0.0 allow remote attackers to execute arbitrary PHP code via a U… Patch early 7.5 high 3.5% 2006-11-14
CVE-2006-5863 EXP PHP remote file inclusion vulnerability in inc/session.php for LetterIt 2 allows remote attackers to execute arbitrary PHP code via a URL in the lang… Patch early 7.5 high 3.5% 2006-11-11
CVE-2006-6154 EXP PHP remote file inclusion vulnerability in addcode.php in HIOX Star Rating System Script (HSRS) 1.0 and earlier allows remote attackers to execute arb… Patch early 7.5 high 3.5% 2006-11-28
CVE-2006-6867 EXP Multiple PHP remote file inclusion vulnerabilities in Vladimir Menshakov buratinable templator (aka bubla) 0.9.1 allow remote attackers to execute arb… Patch early 7.5 high 3.5% 2006-12-31
CVE-2017-7447 EXP HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code. Patch early 8.8 high 3.5% 2017-04-05
CVE-2000-1186 EXP Buffer overflow in phf CGI program allows remote attackers to execute arbitrary commands by specifying a large number of arguments and including a lon… Patch early 7.5 high 3.5% 2001-01-09
CVE-2006-7148 EXP PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to execute arb… Patch early 10.0 high 3.5% 2007-03-07
CVE-2012-4335 EXP Samsung NET-i viewer 1.37.120316 allows remote attackers to cause a denial of service (infinite loop) via a negative size value in a TCP request to (1… Patch early 7.8 high 3.5% 2012-08-14
CVE-2000-0257 EXP Buffer overflow in the NetWare remote web administration utility allows remote attackers to cause a denial of service or execute commands via a long U… Patch early 7.5 high 3.5% 2000-04-19
CVE-2009-3322 EXP The Siemens Gigaset SE361 WLAN router allows remote attackers to cause a denial of service (device reboot) via a flood of crafted TCP packets to port… Patch early 7.8 high 3.5% 2009-09-23
CVE-2014-9240 EXP SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL commands v… Patch early 7.5 high 3.5% 2014-12-03
CVE-2018-18772 EXP CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbi… Patch early 8.8 high 3.5% 2018-11-20
CVE-2018-6941 EXP A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunctio… Patch early 8.8 high 3.5% 2018-02-20
CVE-2015-1722 EXP Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 an… Patch early 7.2 high 3.5% 2015-06-10
CVE-2006-6538 EXP D-LINK DWL-2000AP+ firmware 2.11 allows remote attackers to cause (1) a denial of service (device reset) via a flood of ARP replies on the wired or wi… Patch early 7.8 high 3.5% 2006-12-14
CVE-2007-2507 EXP Directory traversal vulnerability in includes/download.php in Treble Designs 1024 CMS 0.7 allows remote attackers to read arbitrary files via a .. (do… Patch early 7.8 high 3.5% 2007-05-04
CVE-2005-3363 EXP SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to execute arbitrary SQL commands vi… Patch early 7.5 high 3.5% 2005-10-30
CVE-2017-6366 EXP Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijack… Patch early 8.8 high 3.5% 2017-03-15
CVE-1999-0943 EXP Buffer overflow in OpenLink 3.2 allows remote attackers to gain privileges via a long GET request to the web configurator. Patch early 10.0 high 3.5% 1999-10-15
CVE-1999-0973 EXP Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode. Patch early 10.0 high 3.5% 1999-12-07
CVE-2006-5055 EXP PHP remote file inclusion vulnerability in admin/testing/tests/0004_init_urls.php in syntaxCMS 1.1.1 through 1.3 allows remote attackers to execute ar… Patch early 7.5 high 3.5% 2006-09-28
CVE-2007-0699 EXP PHP remote file inclusion vulnerability in includes/includes.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) before 2.5.1.1… Patch early 7.5 high 3.5% 2007-02-04
CVE-2009-2925 EXP Directory traversal vulnerability in DJcalendar.cgi in DJCalendar allows remote attackers to read arbitrary files via a .. (dot dot) in the TEMPLATE p… Patch early 7.8 high 3.5% 2009-08-21
CVE-2008-4732 EXP SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to execute arbitrar… Patch early 7.5 high 3.5% 2008-10-24
CVE-2006-6368 EXP PHP remote file inclusion vulnerability in login.php.inc in awrate 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the toroot p… Patch early 7.5 high 3.5% 2006-12-07
CVE-2006-5788 EXP PHP remote file inclusion vulnerability in (1) index.php and (2) admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to execute a… Patch early 7.5 high 3.5% 2006-11-07
CVE-2008-6593 EXP SQL injection vulnerability in LightNEasy/lightneasy.php in LightNEasy SQLite 1.2.2 and earlier allows remote attackers to inject arbitrary PHP code i… Patch early 7.5 high 3.5% 2009-04-03
CVE-2015-2365 EXP win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows… Patch early 7.2 high 3.5% 2015-07-14
CVE-2015-2366 EXP win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2,… Patch early 7.2 high 3.5% 2015-07-14
← previous page 222 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt