peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,999 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-6462 EXP PHP remote file inclusion vulnerability in engine/oldnews.inc.php in CM68 News 12.02.06 allows remote attackers to execute arbitrary PHP code via a UR… Patch early 7.5 high 3.3% 2006-12-11
CVE-1999-1405 EXP snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when sn… Patch early 10.0 high 3.3% 1999-02-17
CVE-2015-4592 EXP eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allows remote authenticated users t… Patch early 8.8 high 3.3% 2017-01-10
CVE-2018-0877 EXP The Desktop Bridge Virtual File System (VFS) in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevat… Patch early 7.8 high 3.3% 2018-03-14
CVE-2007-4804 EXP Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) hal.php,… Patch early 7.5 high 3.3% 2007-09-11
CVE-2008-5659 EXP The gnu.java.security.util.PRNG class in GNU Classpath 0.97.2 and earlier uses a predictable seed based on the system time, which makes it easier for… Patch early 7.5 high 3.3% 2008-12-17
CVE-2006-0940 EXP Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 3.3% 2006-03-01
CVE-2006-5849 EXP PHP remote file inclusion vulnerability in inc/irayofuncs.php in IrayoBlog alpha-0.2.4 allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 3.3% 2006-11-10
CVE-2007-1647 EXP Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allo… Patch early 7.8 high 3.3% 2007-03-24
CVE-2007-0181 EXP PHP remote file inclusion vulnerability in include/common_function.php in magic photo storage website allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 3.3% 2007-01-11
CVE-2007-0205 EXP Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directo… Patch early 7.5 high 3.3% 2007-01-11
CVE-2007-0232 EXP PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 3.3% 2007-01-13
CVE-2007-0360 EXP PHP remote file inclusion vulnerability in lang/index.php in Oreon 1.2.3 RC4 and earlier allows remote attackers to execute arbitrary PHP code via a U… Patch early 7.5 high 3.3% 2007-01-19
CVE-2007-0571 EXP PHP remote file inclusion vulnerability in include/lib/lib_head.php in phpMyReports 3.0.11 and earlier allows remote attackers to execute arbitrary PH… Patch early 7.5 high 3.3% 2007-01-30
CVE-2007-0761 EXP PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 3.3% 2007-02-06
CVE-2007-0797 EXP PHP remote file inclusion vulnerability in theme/settings.php in bluevirus-design SMA-DB 0.3.9 and earlier allows remote attackers to execute arbitrar… Patch early 7.5 high 3.3% 2007-02-06
CVE-2007-0809 EXP PHP remote file inclusion vulnerability in includes/class_template.php in Categories hierarchy (aka CH or mod-CH) 2.1.2 in ptirhiikmods allows remote… Patch early 7.5 high 3.3% 2007-02-07
CVE-2018-14057 EXP Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token… Patch early 8.8 high 3.3% 2018-08-17
CVE-2017-0165 EXP An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1, Windows RT 8.1, and Windows… Patch early 7.8 high 3.3% 2017-04-12
CVE-2007-2521 EXP PHP remote file inclusion vulnerability in common.php in E-GADS! before 2.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the l… Patch early 7.5 high 3.3% 2007-05-08
CVE-2015-2528 EXP Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation lev… Patch early 7.2 high 3.3% 2015-09-09
CVE-2008-4614 EXP PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to create and delete forums, topic… Patch early 7.5 high 3.3% 2008-10-20
CVE-2006-4373 EXP PHP remote file inclusion vulnerability in modules/visitors2/include/config.inc.php in pSlash 0.70 allows remote attackers to execute arbitrary PHP co… Patch early 7.5 high 3.3% 2006-08-26
CVE-2015-1723 EXP Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 an… Patch early 7.2 high 3.3% 2015-06-10
CVE-2017-7314 EXP An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating a new role, a list of databas… Patch early 7.5 high 3.3% 2017-06-07
CVE-2016-7454 EXP CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST allows an att… Patch early 8.0 high 3.3% 2016-12-17
CVE-2012-2740 EXP SQL injection vulnerability in public_html/lists/admin in phpList before 2.10.18 allows remote attackers to execute arbitrary SQL commands via the sor… Patch early 7.5 high 3.3% 2012-09-06
CVE-2025-54769 EXP An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing.… Patch early 8.8 high 3.3% 2025-07-29
CVE-2007-0972 EXP Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload arbitrary files by modifying th… Patch early 7.5 high 3.3% 2007-02-16
CVE-2008-3363 EXP Directory traversal vulnerability in user_portal.php in the Dokeos E-Learning System 1.8.5 on Windows allows remote attackers to include and execute a… Patch early 7.5 high 3.3% 2008-07-30
← previous page 227 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt