peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,415 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-2298 EXP PHP remote file inclusion vulnerability in config.php in Thatware 0.3 through 0.5.3 allows remote attackers to execute arbitrary PHP code via the root… Patch early 6.8 medium 2% 2002-12-31
CVE-2009-0570 EXP Directory traversal vulnerability in send.php in Ninja Designs Mailist 3.0, when register_globals is enabled and magic_quotes_gpc is disabled, allows… Patch early 5.1 medium 2% 2009-02-13
CVE-2008-6650 EXP del.php in miniBloggie 1.0 allows remote attackers to delete arbitrary posts via a direct request with a modified post_id parameter, a different vulne… Patch early 5.0 medium 2% 2009-04-07
CVE-2007-6560 EXP Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1)… Patch early 4.3 medium 2% 2007-12-28
CVE-2014-10034 EXP Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execute arbitrary SQL commands via t… Patch early 6.5 medium 2% 2015-01-13
CVE-2019-7440 EXP JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcma… Patch early 6.5 medium 2% 2019-03-21
CVE-2010-1887 EXP The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server… Patch early 4.4 medium 2% 2010-08-11
CVE-2012-6433 EXP Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hijack the authentication of admin… Patch early 6.8 medium 2% 2013-01-03
CVE-2006-4543 EXP Cross-site scripting (XSS) vulnerability in index.php in HLStats 1.34 allows remote attackers to inject arbitrary web script or HTML via the (1) game… Patch early 6.8 medium 2% 2006-09-06
CVE-2006-6391 EXP Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow… Patch early 6.8 medium 2% 2006-12-08
CVE-2008-5818 EXP Directory traversal vulnerability in index.php in eDreamers eDContainer 2.22, when magic_quotes_gpc is disabled, allows remote attackers to include an… Patch early 6.8 medium 2% 2009-01-02
CVE-2009-1488 EXP Directory traversal vulnerability in admin/load.php in FunGamez RC1 allows remote attackers to include and execute arbitrary local files via a .. (dot… Patch early 6.8 medium 2% 2009-04-29
CVE-2010-1928 EXP Directory traversal vulnerability in scr/soustab.php in openMairie openPlanning 1.00, when register_globals is enabled, allows remote attackers to inc… Patch early 6.8 medium 2% 2010-05-12
CVE-2010-1935 EXP Directory traversal vulnerability in scr/soustab.php in openMairie Openpresse 1.01, when register_globals is enabled, allows remote attackers to inclu… Patch early 6.8 medium 2% 2010-05-12
CVE-2010-1936 EXP Directory traversal vulnerability in scr/soustab.php in openMairie openComInterne 1.01, when register_globals is enabled, allows remote attackers to i… Patch early 6.8 medium 2% 2010-05-12
CVE-2007-0491 EXP PHP remote file inclusion vulnerability in up.php in Sky GUNNING MySpeach 3.0.6 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 6.8 medium 2% 2007-01-25
CVE-2009-1318 EXP Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions before 3.4.0 allows remote at… Patch early 6.5 medium 2% 2009-04-17
CVE-2010-0380 EXP install.php in JCE-Tech PHP Calendars, downloaded 20100121, allows remote attackers to bypass intended access restrictions and modify application sett… Patch early 5.0 medium 2% 2010-01-22
CVE-2006-5626 EXP Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026… Patch early 4.3 medium 2% 2006-10-31
CVE-2006-4157 EXP Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web script or H… Patch early 6.8 medium 2% 2006-08-16
CVE-2006-4593 EXP Cross-site scripting (XSS) vulnerability in index.php in SoftBB 0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the… Patch early 6.8 medium 2% 2006-09-06
CVE-2009-2553 EXP Multiple SQL injection vulnerabilities in comments.php in Super Simple Blog Script 2.5.4, when magic_quotes_gpc is disabled, allow remote attackers to… Patch early 6.8 medium 2% 2009-07-20
CVE-2006-2396 EXP Cross-site scripting (XSS) vulnerability in phpODP 1.5h allows remote attackers to inject arbitrary web script via the browse parameter. Patch early 5.8 medium 2% 2006-05-16
CVE-2019-15081 EXP OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Produ… Patch early 4.8 medium 2% 2019-08-15
CVE-2009-4722 EXP SQL injection vulnerability in the CheckLogin function in includes/functions.php in Limny 1.01, when magic_quotes_gpc is disabled, allows remote attac… Patch early 6.8 medium 2% 2010-03-18
CVE-2011-4095 EXP Jara 1.6 has an XSS vulnerability Patch early 6.1 medium 2% 2020-01-21
CVE-2008-3573 EXP The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_random value) wi… Patch early 5.0 medium 2% 2008-08-10
CVE-2005-4365 EXP Multiple cross-site scripting (XSS) vulnerabilities in FLIP 0.9.0.1029 allow remote attackers to inject arbitrary web script or HTML via the (1) name… Patch early 4.3 medium 2% 2005-12-20
CVE-2003-0486 EXP SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter. Patch early 5.0 medium 1.9% 2003-08-07
CVE-2014-1671 EXP Multiple SQL injection vulnerabilities in Dell KACE K1000 5.4.76847 and possibly earlier allow remote attackers or remote authenticated users to execu… Patch early 6.5 medium 1.9% 2014-01-26
← previous page 245 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt