peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,108 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-5413 EXP Multiple PHP remote file inclusion vulnerabilities in SuperMod 3.0.0 for YABB (YaBBSM) allow remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 3.2% 2006-10-20
CVE-2006-5555 EXP PHP remote file inclusion vulnerability in constantes.inc.php in EPNadmin 0.7 and 0.7.1 allows remote attackers to execute arbitrary PHP code via the… Patch early 7.5 high 3.2% 2006-10-26
CVE-2006-5670 EXP PHP remote file inclusion vulnerability in forgot_pass.php in Free Image Hosting 1.0 and earlier allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 3.2% 2006-11-03
CVE-2001-0365 EXP Eudora before 5.1 allows a remote attacker to execute arbitrary code, when the 'Use Microsoft Viewer' and 'allow executables in HTML content' options… Patch early 7.5 high 3.2% 2001-06-27
CVE-2008-1245 EXP cgi-bin/setup_virtualserver.exe on the Belkin F5D7230-4 router with firmware 9.01.10 allows remote attackers to cause a denial of service (control cen… Patch early 7.8 high 3.2% 2008-03-10
CVE-2008-6122 EXP The web management interface in Netgear WGR614v9 allows remote attackers to cause a denial of service (crash) via a request that contains a question m… Patch early 7.8 high 3.2% 2009-02-11
CVE-2007-2416 EXP SQL injection vulnerability in home.php in E-Annu allows remote attackers to execute arbitrary SQL commands via the a parameter. Patch early 7.5 high 3.2% 2007-05-01
CVE-2006-3158 EXP index.php in Eduha Meeting does not properly restrict file extensions before permitting a file upload, which allows remote attackers to bypass securit… Patch early 7.5 high 3.2% 2006-06-22
CVE-2006-5841 EXP Multiple PHP remote file inclusion vulnerabilities in dodosmail.php in DodosMail 2.0.1 and earlier, and possibly 2.1, allow remote attackers to execut… Patch early 7.5 high 3.2% 2006-11-10
CVE-2006-5948 EXP PHP remote file inclusion vulnerability in pntUnit/Inspect.php in phpPeanuts 1.1 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 3.2% 2006-11-17
CVE-2006-6516 EXP Multiple PHP remote file inclusion vulnerabilities in KDPics 1.16 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1… Patch early 7.5 high 3.2% 2006-12-14
CVE-2006-5249 EXP PHP remote file inclusion vulnerability in tagmin/delTagUser.php in TagIt! Tagboard 2.1.B Build 2 (tagit2b) allows remote attackers to execute arbitra… Patch early 7.5 high 3.2% 2006-10-12
CVE-2021-29460 EXP Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful content like `<script>` tags.… Patch early 7.6 high 3.2% 2021-04-27
CVE-2006-4122 EXP Simple one-file guestbook 1.0 and earlier allows remote attackers to bypass authentication and delete guestbook entries via a modified id parameter to… Patch early 7.5 high 3.2% 2006-08-14
CVE-2007-2019 EXP PHP remote file inclusion vulnerability in init.gallery.php in phpGalleryScript 1.0 allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 3.2% 2007-04-12
CVE-2007-4925 EXP The ewirePC_Decrypt function in ewirepcfunctions.php in eWire Payment Client (ePC) 1.60 and 1.70 allows remote attackers to execute arbitrary commands… Patch early 7.5 high 3.2% 2007-09-18
CVE-2007-1165 EXP Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the dbs_base_p… Patch early 7.5 high 3.2% 2007-03-02
CVE-2003-0560 EXP SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter. Patch early 10.0 high 3.2% 2003-08-18
CVE-2006-4733 EXP PHP remote file inclusion vulnerability in sipssys/code/box.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) 0.3.1 and earlier all… Patch early 7.5 high 3.2% 2006-09-13
CVE-2006-5314 EXP PHP remote file inclusion vulnerability in ftag.php in TribunaLibre 3.12 Beta allows remote attackers to execute arbitrary PHP code via a URL in the m… Patch early 7.5 high 3.2% 2006-10-17
CVE-2006-5315 EXP PHP remote file inclusion vulnerability in main.php in registroTL allows remote attackers to execute arbitrary PHP code via an ftp:// URL in the page… Patch early 7.5 high 3.2% 2006-10-17
CVE-2006-5317 EXP PHP remote file inclusion vulnerability in index.php in eboli allows remote attackers to execute arbitrary PHP code via a URL in the contentSpecial pa… Patch early 7.5 high 3.2% 2006-10-17
CVE-2006-5521 EXP PHP remote file inclusion vulnerability in DNS/RR.php in Net_DNS 0.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in t… Patch early 7.5 high 3.2% 2006-10-26
CVE-2002-1898 EXP Terminal 1.3 in Apple Mac OS X 10.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a telnet:// link, which is execu… Patch early 7.2 high 3.2% 2002-12-31
CVE-2006-4061 EXP PHP remote file inclusion vulnerability in index.php in Thomas Pequet phpPrintAnalyzer 1.1, when register_globals is enabled, allows remote attackers… Patch early 7.5 high 3.2% 2006-08-10
CVE-2009-1781 EXP Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inject arbitrary PHP code into ph… Patch early 7.5 high 3.2% 2009-05-22
CVE-2007-1015 EXP SQL injection vulnerability in HaberDetay.asp in Aktueldownload Haber script allows remote attackers to execute arbitrary SQL commands via the id para… Patch early 10.0 high 3.2% 2007-02-21
CVE-2008-2884 EXP PHP remote file inclusion vulnerability in display.php in RSS-aggregator allows remote attackers to execute arbitrary PHP code via a URL in the path p… Patch early 9.3 high 3.2% 2008-06-27
CVE-2023-29849 EXP Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice, menuID, staffID, or itemqty… Patch early 8.8 high 3.2% 2023-04-24
CVE-2006-1771 EXP Directory traversal vulnerability in misc in pbcs.dll in SAXoTECH SAXoPRESS, aka Saxotech Online (formerly Publicus) allows remote attackers to read a… Patch early 7.5 high 3.2% 2006-04-13
← previous page 234 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt