peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,429 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-0577 EXP PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 2.9% 2007-01-30
CVE-2008-0520 EXP Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary SQ… Patch early 7.5 high 2.9% 2008-01-31
CVE-2008-0682 EXP SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers to execute arbitrary SQL comm… Patch early 7.5 high 2.8% 2008-02-12
CVE-2013-4011 EXP Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privi… Patch early 7.2 high 2.8% 2013-07-18
CVE-2008-6183 EXP Multiple directory traversal vulnerabilities in index.php in My PHP Indexer 1.0 allow remote attackers to read arbitrary files via a .. (dot dot) in t… Patch early 7.8 high 2.8% 2009-02-19
CVE-2005-3819 EXP Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass authentication… Patch early 7.5 high 2.8% 2005-11-26
CVE-2001-1086 EXP XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote at… Patch early 7.5 high 2.8% 2001-07-04
CVE-2002-0117 EXP Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitrary script an… Patch early 7.5 high 2.8% 2002-03-25
CVE-2008-6940 EXP TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to… Patch early 7.5 high 2.8% 2009-08-12
CVE-2008-6957 EXP member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd action… Patch early 7.5 high 2.8% 2009-08-12
CVE-2008-2073 EXP Directory traversal vulnerability in include/global.inc.php in Virtual Design Studio vlbook 1.21 allows remote attackers to include and execute arbitr… Patch early 7.5 high 2.8% 2008-05-05
CVE-2008-2482 EXP Directory traversal vulnerability in install_mod.php in insanevisions OneCMS 2.5 allows remote attackers to include and execute arbitrary local files… Patch early 7.5 high 2.8% 2008-05-28
CVE-2008-3179 EXP Directory traversal vulnerability in website.php in Web 2 Business (W2B) phpDatingClub (aka Dating Club) 3.7 allows remote attackers to include and ex… Patch early 7.5 high 2.8% 2008-07-15
CVE-2008-4346 EXP Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot… Patch early 7.5 high 2.8% 2008-09-30
CVE-2018-0743 EXP Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows an elevation of privilege vul… Patch early 7.0 high 2.8% 2018-01-04
CVE-2017-1000405 EXP The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside the THP implementation. touch… Patch early 7.0 high 2.8% 2017-11-30
CVE-2007-3272 EXP Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the language para… Patch early 7.8 high 2.8% 2007-06-19
CVE-2002-1211 EXP Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE that points to code stored on… Patch early 7.5 high 2.8% 2002-11-12
CVE-2005-4275 EXP Scientific Atlanta DPX2100 Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and d… Patch early 7.8 high 2.8% 2005-12-16
CVE-2005-3503 EXP chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which a… Patch early 7.2 high 2.8% 2005-11-05
CVE-2012-5849 EXP Multiple SQL injection vulnerabilities in ClipBucket 2.6 Revision 738 and earlier allow remote attackers to execute arbitrary SQL commands via the (1)… Patch early 7.5 high 2.8% 2015-05-14
CVE-2007-0359 EXP PHP remote file inclusion vulnerability in frontpage.php in Uberghey CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 2.8% 2007-01-19
CVE-2007-0591 EXP PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attackers to execute arbitrary PHP c… Patch early 7.5 high 2.8% 2007-01-30
CVE-2007-0824 EXP PHP remote file inclusion vulnerability in inhalt.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dateie… Patch early 7.5 high 2.8% 2007-02-07
CVE-2007-0867 EXP PHP remote file inclusion vulnerability in classes/menu.php in Site-Assistant 0990 and earlier allows remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 2.8% 2007-02-09
CVE-2006-4722 EXP PHP remote file inclusion vulnerability in Open Bulletin Board (OpenBB) 1.0.8 and earlier allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 2.8% 2006-09-12
CVE-2006-5232 EXP Multiple PHP remote file inclusion vulnerabilities in iSearch 2.16 allow remote attackers to execute arbitrary PHP code via a URL in the isearch_path… Patch early 7.5 high 2.8% 2006-10-11
CVE-2006-5831 EXP PHP remote file inclusion vulnerability in admin/code/index.php in All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to exe… Patch early 7.5 high 2.8% 2006-11-10
CVE-2006-5621 EXP PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PH… Patch early 7.5 high 2.8% 2006-10-31
CVE-2008-6799 EXP connection.php in FlashChat 5.0.8 allows remote attackers to bypass the role filter mechanism and gain administrative privileges by setting the s para… Patch early 7.5 high 2.8% 2009-05-07
← previous page 246 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt