peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,011 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-2751 EXP Multiple PHP remote file inclusion vulnerabilities in PHPGlossar 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the format_menu… Patch early 7.5 high 3.3% 2007-05-17
CVE-2007-3271 EXP PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attackers to execute arbitrary PHP c… Patch early 7.5 high 3.3% 2007-06-19
CVE-2007-3460 EXP Multiple PHP remote file inclusion vulnerabilities in index.php3 in EVA-Web 1.1 through 2.2 allow remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 3.3% 2007-06-27
CVE-2007-2330 EXP PHP remote file inclusion vulnerability in includes_handler.php in DynaTracker 151 allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 3.3% 2007-04-27
CVE-2001-1460 EXP SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user parameter. Patch early 7.5 high 3.3% 2001-10-13
CVE-2026-25732 EXP NiceGUI is a Python-based UI framework. Prior to 3.7.0, NiceGUI's FileUpload.name property exposes client-supplied filename metadata without sanitizat… Patch early 7.5 high 3.3% 2026-02-06
CVE-2006-6250 EXP Format string vulnerability in Songbird Media Player 0.2 and earlier allows remote attackers to cause a denial of service (crash) via an M3U Playlist… Patch early 7.8 high 3.3% 2006-12-04
CVE-2014-10023 EXP Multiple SQL injection vulnerabilities in TopicsViewer 3.0 Beta 1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1)… Patch early 7.5 high 3.3% 2015-01-13
CVE-2006-4713 EXP PHP remote file inclusion vulnerability in config.php in PSYWERKS PUMA 1.0 RC2 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 3.3% 2006-09-12
CVE-2006-5230 EXP PHP remote file inclusion vulnerability in forum.php in FreeForum 0.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 3.3% 2006-10-11
CVE-2006-5493 EXP PHP remote file inclusion vulnerability in template/purpletech/base_include.php in DigitalHive 2.0 RC2 allows remote attackers to execute arbitrary PH… Patch early 7.5 high 3.3% 2006-10-25
CVE-2004-1813 EXP VocalTec VGW4/8 Gateway 8.0 allows remote attackers to bypass authentication via an HTTP request to home.asp with a trailing slash (/). Patch early 7.5 high 3.3% 2004-12-31
CVE-2004-1329 EXP Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows… Patch early 7.2 high 3.3% 2004-12-20
CVE-2022-25241 EXP In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF). Patch early 8.8 high 3.3% 2022-02-16
CVE-2008-0422 EXP SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via t… Patch early 7.5 high 3.3% 2008-01-23
CVE-2007-3611 EXP admin.php in VRNews 1.1.1, and possibly other 1.x versions, does not require authentication, which allows remote attackers to perform certain administ… Patch early 9.3 high 3.3% 2007-07-06
CVE-2002-1113 EXP summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_path paramet… Patch early 7.5 high 3.3% 2002-10-04
CVE-2024-53582 EXP An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to execute a directory traversal via… Patch early 7.5 high 3.3% 2025-01-31
CVE-1999-0679 EXP Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option. Patch early 7.5 high 3.3% 1999-08-13
CVE-2005-3980 EXP SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attackers to execute arbitrary SQL comm… Patch early 7.5 high 3.3% 2005-12-04
CVE-2006-5148 EXP Multiple PHP remote file inclusion vulnerabilities in Forum82 2.5.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 3.3% 2006-10-05
CVE-2015-2553 EXP The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2,… Patch early 7.2 high 3.3% 2015-10-14
CVE-2012-1199 EXP Multiple PHP remote file inclusion vulnerabilities in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary PHP… Patch early 7.5 high 3.3% 2012-02-18
CVE-2026-22241 EXP The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an arbitrary file upload vulne… Patch early 7.2 high 3.3% 2026-01-08
CVE-2007-0825 EXP FlashFXP 3.4.0 build 1145 allows remote servers to cause a denial of service (CPU consumption) via a response to a PWD command that contains a long st… Patch early 7.8 high 3.3% 2007-02-07
CVE-2005-3518 EXP SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL commands via the old_searches para… Patch early 7.5 high 3.3% 2005-11-06
CVE-2015-6171 EXP The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2,… Patch early 7.2 high 3.3% 2015-12-09
CVE-2006-4672 EXP PHP remote file inclusion vulnerability in profitCode ppalCart 2.5 EE, possibly a component of PayProCart, allows remote attackers to execute arbitrar… Patch early 7.5 high 3.3% 2006-09-11
CVE-2006-2005 EXP Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as… Patch early 7.5 high 3.3% 2006-04-25
CVE-2008-5042 EXP Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks via a direct request to admin… Patch early 7.5 high 3.3% 2008-11-12
← previous page 230 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt