peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,999 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-3764 EXP Eval injection vulnerability in globalsoff.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 3.3% 2008-08-21
CVE-2007-0573 EXP PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 3.3% 2007-01-30
CVE-2007-0839 EXP Multiple PHP remote file inclusion vulnerabilities in index/index_album.php in Valarsoft WebMatic 2.6 allow remote attackers to execute arbitrary PHP… Patch early 7.5 high 3.3% 2007-02-08
CVE-2007-0848 EXP PHP remote file inclusion vulnerability in classes/class_mail.inc.php in Maian Recipe 1.0 allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 3.3% 2007-02-08
CVE-2007-1233 EXP PHP remote file inclusion vulnerability in downloadcounter.php in STWC-Counter 3.4.0.0 and earlier allows remote attackers to execute arbitrary PHP co… Patch early 7.5 high 3.3% 2007-03-03
CVE-2008-5967 EXP admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote… Patch early 7.5 high 3.3% 2009-01-26
CVE-2008-6581 EXP login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter. Patch early 7.5 high 3.3% 2009-04-02
CVE-2007-4486 EXP Multiple PHP remote file inclusion vulnerabilities in index.php in Linkliste 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 3.3% 2007-08-22
CVE-2003-0961 EXP Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges. Patch early 7.2 high 3.3% 2003-12-15
CVE-1999-0745 EXP Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler. Patch early 10.0 high 3.3% 1999-08-18
CVE-2007-4368 EXP SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL c… Patch early 7.5 high 3.3% 2007-08-15
CVE-2006-5192 EXP PHP remote file inclusion vulnerability in includes/footer.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 3.3% 2006-10-10
CVE-2014-9303 EXP EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and password via a UR… Patch early 7.8 high 3.3% 2014-12-07
CVE-2007-2262 EXP Multiple PHP remote file inclusion vulnerabilities in html/php/detail.php in Sinato jmuffin allow remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 3.3% 2007-04-25
CVE-2007-5822 EXP Direct static code injection vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to inject arbitrary PHP code into a c… Patch early 7.5 high 3.3% 2007-11-05
CVE-2015-1724 EXP Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 an… Patch early 7.2 high 3.3% 2015-06-10
CVE-2004-0348 EXP SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId para… Patch early 10.0 high 3.3% 2004-11-23
CVE-2014-3139 EXP recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth parameter to a… Patch early 7.5 high 3.3% 2014-05-02
CVE-2002-2176 EXP SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profile… Patch early 10.0 high 3.3% 2002-12-31
CVE-2007-0200 EXP PHP remote file inclusion vulnerability in template.php in Geoffrey Golliher Axiom Photo/News Gallery (axiompng) 0.8.6 allows remote attackers to exec… Patch early 7.5 high 3.3% 2007-01-11
CVE-2007-0757 EXP PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and earlier allows remote attackers t… Patch early 7.5 high 3.3% 2007-02-06
CVE-2007-0762 EXP PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Build 100 allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 3.3% 2007-02-06
CVE-2007-0837 EXP PHP remote file inclusion vulnerability in examples/inc/top.inc.php in AgerMenu 0.03 and earlier allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 3.3% 2007-02-08
CVE-2004-0239 EXP SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo va… Patch early 10.0 high 3.3% 2004-11-23
CVE-2018-8214 EXP An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Brid… Patch early 7.0 high 3.3% 2018-06-14
CVE-2024-51774 EXP qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors. Patch early 8.1 high 3.3% 2024-11-02
CVE-2006-6566 EXP PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module for mxBB 0.91c allows remote a… Patch early 7.5 high 3.3% 2006-12-15
CVE-2024-0566 EXP The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQ… Patch early 7.2 high 3.3% 2024-02-12
CVE-2006-1183 EXP The Ubuntu 5.10 installer does not properly clear passwords from the installer log file (questions.dat), and leaves the log file with world-readable p… Patch early 7.2 high 3.3% 2006-03-13
CVE-2007-2273 EXP PHP remote file inclusion vulnerability in include/loading.php in Alessandro Lulli wavewoo 0.1.1 allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 3.3% 2007-04-25
← previous page 228 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt