peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,413 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-1887 EXP PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l pa… Patch early 7.5 high 3% 2002-12-31
CVE-2017-7398 EXP D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted actio… Patch early 8.8 high 3% 2017-04-04
CVE-2007-1604 EXP Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute arbitrary PHP code (1) via a for… Patch early 7.5 high 3% 2007-03-22
CVE-2008-4720 EXP Multiple PHP remote file inclusion vulnerabilities in The Gemini Portal 4.7 allow remote attackers to execute arbitrary PHP code via a URL in the lang… Patch early 9.3 high 3% 2008-10-23
CVE-2006-2523 EXP PHP remote file inclusion vulnerability in config.php in phpListPro 2.0.1 and earlier, with magic_quotes_gpc disabled, allows remote attackers to exec… Patch early 7.5 high 3% 2006-05-22
CVE-2006-4498 EXP PHP remote file inclusion vulnerability in sommaire_admin.php in PhpAlbum (mod_phpalbum) 2.15 for PortailPHP allows remote attackers to execute arbitr… Patch early 7.5 high 3% 2006-08-31
CVE-2018-12602 EXP A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily. Patch early 8.8 high 3% 2018-06-25
CVE-2007-0871 EXP Unrestricted file upload vulnerability in eXtremePow eXtreme File Hosting allows remote attackers to upload arbitrary PHP code via a filename with a d… Patch early 7.5 high 3% 2007-02-12
CVE-2023-40278 EXP An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp componen… Patch early 7.5 high 3% 2024-03-19
CVE-2001-0006 EXP The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the p… Patch early 7.1 high 3% 2001-02-12
CVE-2005-1547 EXP Heap-based buffer overflow in the demo version of Bakbone Netvault, and possibly other versions, allows remote attackers to execute arbitrary commands… Patch early 7.5 high 3% 2005-05-14
CVE-2007-3199 EXP Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP code by uploading a file with… Patch early 7.5 high 3% 2007-06-12
CVE-2008-4155 EXP Multiple directory traversal vulnerabilities in EasySite 2.3 allow remote attackers to read arbitrary files or list directories via a .. (dot dot) in… Patch early 7.8 high 3% 2008-09-19
CVE-2008-4361 EXP Directory traversal vulnerability in PowerPortal 2.0.13 allows remote attackers to list and possibly read arbitrary files via a .. (dot dot) in the pa… Patch early 7.8 high 3% 2008-09-30
CVE-2008-1534 EXP Multiple directory traversal vulnerabilities in PowerPHPBoard 1.00b allow remote attackers to include and execute arbitrary local files via a .. (dot… Patch early 7.5 high 3% 2008-03-28
CVE-2002-0833 EXP Buffer overflow in Eudora 5.1.1 and 5.0-J for Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a multi-part… Patch early 7.5 high 3% 2002-08-12
CVE-2006-0805 EXP The CAPTCHA functionality in php-Nuke 6.0 through 7.9 uses fixed challenge/response pairs that only vary once per day based on the User Agent (HTTP_US… Patch early 7.5 high 3% 2006-02-21
CVE-2006-3734 EXP Multiple unspecified vulnerabilities in the Command Line Interface (CLI) for Cisco Security Monitoring, Analysis and Response System (CS-MARS) before… Patch early 7.2 high 3% 2006-07-21
CVE-2019-0570 EXP An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka "Windows Runtime Elevation of Privil… Patch early 7.8 high 3% 2019-01-08
CVE-2009-4082 EXP PHP remote file inclusion vulnerability in forums/Forum_Include/index.php in Outreach Project Tool (OPT) 1.2.7 and earlier allows remote attackers to… Patch early 7.5 high 3% 2009-11-29
CVE-2008-5920 EXP The create_anchors function in utils.inc in WebSVN 1.x allows remote attackers to execute arbitrary PHP code via a crafted username that is processed… Patch early 7.5 high 3% 2009-01-21
CVE-2010-0975 EXP PHP remote file inclusion vulnerability in external.php in PHPCityPortal allows remote attackers to execute arbitrary PHP code via a URL in the url pa… Patch early 7.5 high 3% 2010-03-16
CVE-2010-1114 EXP Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to execute arbitrary PHP code via a U… Patch early 7.5 high 3% 2010-03-25
CVE-2008-1635 EXP Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remote attackers to include and ex… Patch early 7.5 high 3% 2008-04-02
CVE-2007-2324 EXP Directory traversal vulnerability in file.php in JulmaCMS 1.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter… Patch early 7.8 high 3% 2007-04-27
CVE-2008-4427 EXP changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows rem… Patch early 7.5 high 3% 2008-10-03
CVE-2005-3005 EXP Helpdesk Software Hesk allows remote attackers to bypass authentication for (1) admin.php and (2) admin_main.php by modifying the PHPSESSID session ID… Patch early 7.5 high 3% 2005-09-21
CVE-2018-8134 EXP An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulner… Patch early 7.0 high 3% 2018-05-09
CVE-2010-4234 EXP The web server on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to c… Patch early 7.8 high 3% 2010-11-17
CVE-2017-6411 EXP Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any pa… Patch early 8.8 high 3% 2017-03-06
← previous page 240 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt