peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,041 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-4277 EXP Multiple PHP remote file inclusion vulnerabilities in Tutti Nova 1.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 3.2% 2006-08-21
CVE-2000-0429 EXP A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands. Patch early 7.5 high 3.2% 2000-04-27
CVE-2007-5890 EXP Directory traversal vulnerability in index.php in easyGB 2.1.1 allows remote attackers to include arbitrary files via the DatabaseType parameter. NOT… Patch early 10.0 high 3.2% 2007-11-08
CVE-2013-6875 EXP SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute… Patch early 7.5 high 3.2% 2013-11-26
CVE-2006-4311 EXP PHP remote file inclusion vulnerability in Sonium Enterprise Adressbook 0.2 allows remote attackers to execute arbitrary PHP code via the folder param… Patch early 7.5 high 3.2% 2006-08-23
CVE-2006-0123 EXP Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter in index.p… Patch early 7.5 high 3.2% 2006-01-09
CVE-2006-7185 EXP PHP remote file inclusion vulnerability in includes/user_standard.php in CMSmelborp Beta allows remote attackers to execute arbitrary PHP code via a U… Patch early 9.3 high 3.2% 2007-03-30
CVE-2006-5458 EXP PHP remote file inclusion vulnerability in common.php in Hinton Design phpht Topsites allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 3.2% 2006-10-23
CVE-2017-15645 EXP CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary commands… Patch early 8.8 high 3.2% 2017-10-19
CVE-1999-0899 EXP The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an… Patch early 7.2 high 3.2% 1999-11-04
CVE-2007-4527 EXP Unrestricted file upload vulnerability in phUploader.php in phphq.Net phUploader 1.2 allows remote attackers to upload and execute arbitrary code via… Patch early 7.5 high 3.2% 2007-08-25
CVE-2006-0757 EXP Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid pa… Patch early 7.5 high 3.2% 2006-02-18
CVE-2003-1318 EXP Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a different vuln… Patch early 7.8 high 3.2% 2003-12-31
CVE-2006-1573 EXP PHP remote file inclusion vulnerability in index.php in MediaSlash Gallery allows remote attackers to execute arbitrary PHP code via a URL in the rub… Patch early 7.5 high 3.2% 2006-04-01
CVE-2006-4073 EXP Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbitrary PHP code via a URL in th… Patch early 7.5 high 3.2% 2006-08-11
CVE-2006-4207 EXP Multiple PHP remote file inclusion vulnerabilities in Bob Jewell Discloser 0.0.4 and earlier allow remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 3.2% 2006-08-17
CVE-2006-4282 EXP PHP remote file inclusion vulnerability in MamboLogin.php in the MamboWiki component (com_mambowiki) 0.9.6 and earlier for Mambo and Joomla! allows re… Patch early 7.5 high 3.2% 2006-08-22
CVE-2006-4348 EXP PHP remote file inclusion vulnerability in config.kochsuite.php in the Kochsuite (com_kochsuite) 0.9.4 component for Mambo and Joomla! allows remote a… Patch early 7.5 high 3.2% 2006-08-24
CVE-2006-4063 EXP Multiple PHP remote file inclusion vulnerabilities in Csaba Godor SAPID Blog Beta 2 and earlier allow remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 3.2% 2006-08-10
CVE-2014-1618 EXP Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2… Patch early 7.5 high 3.2% 2014-01-21
CVE-2015-2524 EXP Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation lev… Patch early 7.2 high 3.2% 2015-09-09
CVE-2006-5629 EXP Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the Fo… Patch early 7.5 high 3.2% 2006-10-31
CVE-2005-4427 EXP Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to… Patch early 7.5 high 3.2% 2005-12-20
CVE-2004-1650 EXP D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the IP address of the camera via a… Patch early 7.5 high 3.2% 2004-08-31
CVE-2005-4226 EXP Multiple "potential" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute arbitrary SQL commands via (1)… Patch early 7.5 high 3.2% 2005-12-14
CVE-2007-0568 EXP PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execute arbitrary PHP code via a UR… Patch early 7.5 high 3.2% 2007-01-30
CVE-2007-0581 EXP PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbitrary PHP code via a URL in th… Patch early 7.5 high 3.2% 2007-01-30
CVE-2007-1133 EXP PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_fuss para… Patch early 7.5 high 3.2% 2007-02-27
CVE-2007-1162 EXP A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a… Patch early 7.8 high 3.2% 2007-03-02
CVE-2007-1294 EXP A certain ActiveX control in the DivXBrowserPlugin (npdivx32.dll) in DivX Web Player, as distributed with DivX Player 1.3.0, allows remote attackers t… Patch early 7.8 high 3.2% 2007-03-07
← previous page 232 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt