peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,011 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-8852 EXP SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file received from an untrusted re… Patch early 7.8 high 3.3% 2017-05-10
CVE-2006-4368 EXP PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows remote attackers to execute arbit… Patch early 7.5 high 3.3% 2006-08-26
CVE-2025-10666 EXP A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The… Patch early 8.8 high 3.3% 2025-09-18
CVE-2015-1721 EXP The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows… Patch early 7.2 high 3.3% 2015-06-10
CVE-2018-8550 EXP An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows 7, W… Patch early 7.8 high 3.3% 2018-11-14
CVE-2006-6910 EXP formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a denial of service (daemon cra… Patch early 7.8 high 3.3% 2006-12-31
CVE-2006-3736 EXP PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to ex… Patch early 7.5 high 3.3% 2006-07-21
CVE-2007-4524 EXP PHP remote file inclusion vulnerability in adisplay.php in PhPress 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the lang p… Patch early 7.5 high 3.3% 2007-08-25
CVE-2007-1078 EXP PHP remote file inclusion vulnerability in index.php in FlashGameScript 1.5.4 allows remote attackers to execute arbitrary PHP code via a URL in the f… Patch early 7.5 high 3.3% 2007-02-22
CVE-2006-4966 EXP PHP remote file inclusion vulnerability in inc/ifunctions.php in chumpsoft phpQuestionnaire (phpQ) 3.12 allows remote attackers to execute arbitrary P… Patch early 7.5 high 3.3% 2006-09-25
CVE-2006-5259 EXP PHP remote file inclusion vulnerability in param_editor.php in Compteur 2 allows remote attackers to execute arbitrary PHP code via a URL in the folde… Patch early 7.5 high 3.3% 2006-10-12
CVE-2006-5309 EXP PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and earlier module for phpBB allows… Patch early 7.5 high 3.3% 2006-10-17
CVE-2006-5318 EXP PHP remote file inclusion vulnerability in index.php in Nayco JASmine (aka Jasmine-Web) allows remote attackers to execute arbitrary PHP code via an F… Patch early 7.5 high 3.3% 2006-10-17
CVE-2006-5385 EXP PHP remote file inclusion vulnerability in admin/admin_spam.php in the SpamOborona 1.0b and earlier phpBB module allows remote attackers to execute ar… Patch early 7.5 high 3.3% 2006-10-18
CVE-2006-5387 EXP PHP remote file inclusion vulnerability in mods/iai/includes/constants.php in the PlusXL 20_272 and earlier phpBB module allows remote attackers to ex… Patch early 7.5 high 3.3% 2006-10-18
CVE-2006-5415 EXP PHP remote file inclusion vulnerability in includes/functions_newshr.php in the News Defilante Horizontale 4.1.1 and earlier module for phpBB allows r… Patch early 7.5 high 3.3% 2006-10-20
CVE-2006-5497 EXP PHP remote file inclusion vulnerability in themes/program/themesettings.inc.php in Segue CMS 1.5.8 and earlier, when register_globals is enabled, allo… Patch early 7.5 high 3.3% 2006-10-25
CVE-2006-5795 EXP Multiple PHP remote file inclusion vulnerabilities in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allow remote attackers to execute a… Patch early 7.5 high 3.3% 2006-11-08
CVE-2004-1402 EXP SQL injection vulnerability in iWebNegar allows remote attackers to execute arbitrary SQL commands via (1) the string parameter for index.php, (2) com… Patch early 10.0 high 3.3% 2004-12-31
CVE-2006-3776 EXP PHP remote file inclusion vulnerability in order/index.php in IDevSpot (1) PhpHostBot 1.0 and (2) AutoHost 3.0 allows remote attackers to execute arbi… Patch early 7.5 high 3.3% 2006-07-24
CVE-2005-3860 EXP PHP remote file inclusion vulnerability in athena.php in Oliver May Athena PHP Website Administration 0.1a allows remote attackers to execute arbitrar… Patch early 7.5 high 3.3% 2005-11-29
CVE-2003-0974 EXP Applied Watch Command Center allows remote attackers to conduct unauthorized activities without authentication, such as (1) add new users to a console… Patch early 7.5 high 3.3% 2003-12-15
CVE-2007-0171 EXP PHP remote file inclusion vulnerability in index.php in AllMyLinks 0.5.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL i… Patch early 7.5 high 3.3% 2007-01-11
CVE-2006-6078 EXP PHP remote file inclusion vulnerability in common.inc.php in a-ConMan 3.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 3.3% 2006-11-24
CVE-2007-1839 EXP Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the p… Patch early 7.5 high 3.3% 2007-04-03
CVE-2007-2530 EXP Multiple PHP remote file inclusion vulnerabilities in Tropicalm Crowell Resource 4.5.2 allow remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 3.3% 2007-05-09
CVE-2007-2531 EXP PHP remote file inclusion vulnerability in berylium-classes.php in Berylium2 2003-08-18 allows remote attackers to execute arbitrary PHP code via a UR… Patch early 7.5 high 3.3% 2007-05-09
CVE-2007-2596 EXP PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 3.3% 2007-05-11
CVE-2007-2620 EXP PHP remote file inclusion vulnerability in inc/config.inc.php in Jakub Steiner (aka jimmac) original 0.11 allows remote attackers to execute arbitrary… Patch early 7.5 high 3.3% 2007-05-11
CVE-2007-2706 EXP PHP remote file inclusion vulnerability in maint/ftpmedia.php in Media Gallery 1.4.8a and earlier for Geeklog allows remote attackers to execute arbit… Patch early 7.5 high 3.3% 2007-05-16
← previous page 229 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt