peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,461 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2001-0051 EXP IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the d… Patch early 7.5 high 2.8% 2001-02-16
CVE-2002-0095 EXP The default configuration of BSCW (Basic Support for Cooperative Work) 3.x and possibly version 4 enables user self registration, which could allow re… Patch early 7.5 high 2.8% 2002-03-25
CVE-2002-1007 EXP Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id parameter in a link… Patch early 7.5 high 2.8% 2002-10-04
CVE-2008-2298 EXP Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1. Patch early 7.5 high 2.8% 2008-05-18
CVE-2015-7569 EXP SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary SQL commands via the "pagedir_o… Patch early 8.8 high 2.8% 2017-04-24
CVE-2019-0805 EXP An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privil… Patch early 7.8 high 2.8% 2019-04-09
CVE-2007-2663 EXP PHP remote file inclusion vulnerability in language/1/splash.lang.php in Beacon 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 2.8% 2007-05-14
CVE-2005-1709 EXP Unknown vulnerability in Blue Coat Reporter before 7.1.2 allows remote unauthenticated attackers to add a license. Patch early 7.5 high 2.8% 2005-05-24
CVE-2007-1708 EXP PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 2.8% 2007-03-27
CVE-2007-1983 EXP PHP remote file inclusion vulnerability in include/default_header.php in Cyboards PHP Lite 1.21 allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 2.8% 2007-04-12
CVE-2007-1999 EXP PHP remote file inclusion vulnerability in index.php in Weatimages 1.7.1 and earlier, when weatimages.ini is missing, allows remote attackers to execu… Patch early 7.5 high 2.8% 2007-04-12
CVE-2007-2154 EXP PHP remote file inclusion vulnerability in services/samples/inclusionService.php in Cabron Connector 1.1.0 allows remote attackers to execute arbitrar… Patch early 7.5 high 2.8% 2007-04-19
CVE-2007-2347 EXP PHP remote file inclusion vulnerability in main/forum/komentar.php in OneClick CMS (aka Sisplet CMS) 05.10 and earlier allows remote attackers to exec… Patch early 7.5 high 2.8% 2007-04-27
CVE-2007-2573 EXP PHP remote file inclusion vulnerability in plugin/HP_DEV/cms2.php in PHPtree 1.3 allows remote attackers to execute arbitrary PHP code via a URL in th… Patch early 7.5 high 2.8% 2007-05-09
CVE-2008-3595 EXP PHP remote file inclusion vulnerability in examples/txtSQLAdmin/startup.php in txtSQL 2.2 Final allows remote attackers to execute arbitrary PHP code… Patch early 9.3 high 2.8% 2008-08-12
CVE-2008-5210 EXP Multiple PHP remote file inclusion vulnerabilities in PhpBlock A8.5 allow remote attackers to execute arbitrary PHP code via a URL in the PATH_TO_CODE… Patch early 9.3 high 2.8% 2008-11-24
CVE-2006-4164 EXP PHP remote file inclusion vulnerability in inc/header.inc.php in phpPrintAnalyzer 1.2 and earlier allows remote attackers to execute arbitrary PHP cod… Patch early 7.5 high 2.8% 2006-08-16
CVE-2005-0720 EXP PHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitrary PHP code by modifying the s… Patch early 7.5 high 2.8% 2005-03-08
CVE-2007-1635 EXP Static code injection vulnerability in admin/settings.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote authenticated users to in… Patch early 9.0 high 2.8% 2007-03-23
CVE-2008-0612 EXP Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary local files via… Patch early 7.5 high 2.8% 2008-02-06
CVE-2003-1143 EXP Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05 allow remote attackers to caus… Patch early 7.5 high 2.8% 2003-10-30
CVE-2002-1070 EXP Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename p… Patch early 7.5 high 2.8% 2002-10-04
CVE-2008-4919 EXP Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remote attackers to overwrite arbi… Patch early 8.8 high 2.8% 2008-11-04
CVE-2018-0748 EXP The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 16… Patch early 7.8 high 2.8% 2018-01-04
CVE-2018-0752 EXP The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Wind… Patch early 7.8 high 2.8% 2018-01-04
CVE-2008-4708 EXP BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admin_session cookie to 1. Patch early 7.5 high 2.8% 2008-10-23
CVE-2008-4721 EXP PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie t… Patch early 7.5 high 2.8% 2008-10-23
CVE-2008-4783 EXP tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login cookie to "admin." Patch early 7.5 high 2.8% 2008-10-29
CVE-2008-4784 EXP aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a cookie to "A" or "O" in (1) edi… Patch early 7.5 high 2.8% 2008-10-29
CVE-2008-5576 EXP admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large val… Patch early 7.5 high 2.8% 2008-12-15
← previous page 249 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt