peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,984 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-0094 EXP The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2… Patch early 7.8 high 3.4% 2016-03-09
CVE-2008-6367 EXP Unrestricted file upload vulnerability in Photos/create_album.php in Social Groupie allows remote authenticated users to execute arbitrary code by upl… Patch early 8.5 high 3.4% 2009-03-02
CVE-2008-6438 EXP SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbi… Patch early 7.5 high 3.4% 2009-03-06
CVE-2007-4235 EXP Multiple PHP remote file inclusion vulnerabilities in VietPHP allow remote attackers to execute arbitrary PHP code via a URL in (1) the dirpath parame… Patch early 9.3 high 3.4% 2007-08-08
CVE-2018-17776 EXP PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users to gain privileges by replacin… Patch early 7.8 high 3.4% 2018-09-28
CVE-2007-2210 EXP A certain ActiveX control in askPopStp.dll in Netsprint Ask IE Toolbar 1.1 allows remote attackers to cause a denial of service (Internet Explorer cra… Patch early 7.8 high 3.4% 2007-04-24
CVE-2006-5282 EXP Multiple PHP remote file inclusion vulnerabilities in SH-News 3.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the sc… Patch early 7.5 high 3.4% 2006-10-13
CVE-2006-5539 EXP PHP remote file inclusion vulnerability in login/secure.php in UeberProject Management System 1.0 and earlier allows remote attackers to execute arbit… Patch early 7.5 high 3.4% 2006-10-26
CVE-2006-5590 EXP PHP remote file inclusion vulnerability in index.php in ArticleBeach Script 2.0 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 3.4% 2006-10-27
CVE-2006-5613 EXP PHP remote file inclusion in Core/core.inc.php in MP3 Streaming DownSampler (mp3SDS) 3.0, when register_globals is enabled, allows remote attackers to… Patch early 7.5 high 3.4% 2006-10-31
CVE-2006-5665 EXP PHP remote file inclusion vulnerability in admin/modules_data.php in the phpBB module Spider Friendly 1.3.10 and earlier allows remote attackers to ex… Patch early 7.5 high 3.4% 2006-11-03
CVE-2006-5667 EXP Multiple PHP remote file inclusion vulnerabilities in P-Book 1.17 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the pb… Patch early 7.5 high 3.4% 2006-11-03
CVE-2007-2180 EXP Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted WMV file. Patch early 7.1 high 3.4% 2007-04-24
CVE-2013-1627 EXP Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attacke… Patch early 7.8 high 3.4% 2013-03-11
CVE-2015-2507 EXP The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Serv… Patch early 7.2 high 3.4% 2015-09-09
CVE-2006-1000 EXP Multiple SQL injection vulnerabilities in Pentacle In-Out Board 3.0 and earlier allow remote attackers to execute arbitrary SQL commands and bypass au… Patch early 10.0 high 3.4% 2006-03-06
CVE-2007-1812 EXP PHP remote file inclusion vulnerability in utilitaires/gestion_sondage.php in BT-Sondage 112 allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 3.4% 2007-04-02
CVE-2007-2204 EXP Multiple PHP remote file inclusion vulnerabilities in GPL PHP Board (GPB) unstable-2001.11.14-1 allow remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 3.4% 2007-04-24
CVE-2007-3118 EXP Multiple PHP remote file inclusion vulnerabilities in Kravchuk letter (K-letter) 1.0 allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 3.4% 2007-06-07
CVE-2005-0313 EXP Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain p… Patch early 7.5 high 3.4% 2005-01-27
CVE-2016-1607 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Novell Filr before 2.0 Security Update 2 allow remote at… Patch early 7.2 high 3.4% 2016-08-01
CVE-2007-2290 EXP Multiple PHP remote file inclusion vulnerabilities in B2 Weblog and News Publishing Tool 0.6.1 allow remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 3.4% 2007-04-26
CVE-2013-7053 EXP D-Link DIR-100 4.03B07: cli.cgi CSRF Patch early 8.8 high 3.4% 2020-02-04
CVE-2007-2325 EXP PHP remote file inclusion vulnerability in include.php in MyNewsGroups :) allows remote attackers to execute arbitrary PHP code via a URL in the myng_… Patch early 10.0 high 3.4% 2007-04-27
CVE-2008-4178 EXP SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and Downline Goldmine Builder allow… Patch early 7.5 high 3.4% 2008-09-23
CVE-2006-0153 EXP 427BB 2.2 and 2.2.1 verifies authentication credentials based on the username, authenticated, and usertype cookies, which allows remote attackers to b… Patch early 7.5 high 3.4% 2006-01-10
CVE-2006-6552 EXP PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to execute arbitrary… Patch early 7.5 high 3.4% 2006-12-14
CVE-2023-40279 EXP An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to main.… Patch early 7.5 high 3.4% 2024-03-19
CVE-2016-7185 EXP The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R… Patch early 7.8 high 3.4% 2016-10-14
CVE-2016-4311 EXP Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authenti… Patch early 8.8 high 3.4% 2017-02-17
← previous page 225 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt