peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,534 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-9092 EXP There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password. Patch early 8.8 high 2.7% 2018-03-27
CVE-2006-6381 EXP Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files via a .. (dot dot) in the filena… Patch early 7.5 high 2.7% 2006-12-07
CVE-2008-4625 EXP SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arb… Patch early 7.5 high 2.7% 2008-10-21
CVE-2002-0731 EXP Cross-site scripting vulnerability in demonstration scripts for vqServer allows remote attackers to execute arbitrary script via a link that contains… Patch early 7.5 high 2.7% 2002-08-12
CVE-2002-2143 EXP The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to… Patch early 7.5 high 2.7% 2002-12-31
CVE-2004-2373 EXP The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allow remote attackers to use a sh… Patch early 7.5 high 2.7% 2004-12-31
CVE-2006-1164 EXP Nodez 4.6.1.1 and earlier stores sensitive data in the list.gtdat file under the web document root with insufficient access control, which allows remo… Patch early 7.5 high 2.7% 2006-03-12
CVE-2007-1215 EXP Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local u… Patch early 7.2 high 2.7% 2007-04-04
CVE-2007-0395 EXP PHP remote file inclusion vulnerability in libraries/grab_globals.lib.php in ComVironment 4.0 allows remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 2.7% 2007-01-19
CVE-2007-0570 EXP PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News Script (AINS) 0.02b allows re… Patch early 7.5 high 2.7% 2007-01-30
CVE-2007-0679 EXP PHP remote file inclusion vulnerability in lang/leslangues.php in Nicolas Grandjean PHPMyRing 4.1.3b and earlier allows remote attackers to execute ar… Patch early 7.5 high 2.7% 2007-02-03
CVE-2007-1025 EXP PHP remote file inclusion vulnerability in inc/functions_inc.php in VS-Link-Partner 2.1 and earlier allows remote attackers to execute arbitrary PHP c… Patch early 7.5 high 2.7% 2007-02-21
CVE-2007-1299 EXP PHP remote file inclusion vulnerability in index.php in Mani Stats Reader 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 2.7% 2007-03-07
CVE-2009-1282 EXP SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 2.7% 2009-04-09
CVE-2023-28311 EXP Microsoft Word Remote Code Execution Vulnerability Patch early 7.8 high 2.7% 2023-04-11
CVE-2006-6634 EXP Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote attackers to… Patch early 7.5 high 2.7% 2006-12-18
CVE-1999-1437 EXP ePerl 2.2.12 allows remote attackers to read arbitrary files and possibly execute certain commands by specifying a full pathname of the target file as… Patch early 7.5 high 2.7% 1998-07-07
CVE-2008-4752 EXP TlNews 2.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlNews_login cookie to admin. Patch early 7.5 high 2.7% 2008-10-27
CVE-2006-3951 EXP PHP remote file inclusion vulnerability in moodle.php in Mam-moodle alpha component (com_moodle) for Mambo allows remote attackers to execute arbitrar… Patch early 7.5 high 2.7% 2006-08-01
CVE-2007-1148 EXP PHP remote file inclusion vulnerability in install/index.php in LoveCMS 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the ste… Patch early 7.5 high 2.7% 2007-03-02
CVE-2018-5720 EXP An issue was discovered on DODOCOOL DC38 3-in-1 N300 Mini Wireless Range Extend RTN2-AW.GD.R3465.1.20161103 devices. A Cross-site request forgery (CSR… Patch early 8.8 high 2.7% 2018-01-29
CVE-2007-5488 EXP Multiple SQL injection vulnerabilities in cdr_addon_mysql in Asterisk-Addons before 1.2.8, and 1.4.x before 1.4.4, allow remote attackers to execute a… Patch early 7.5 high 2.7% 2007-10-17
CVE-2007-3201 EXP Visual truncation vulnerability in Windows Privacy Tray (WinPT) 1.2.0 allows user-assisted remote attackers to install a key listed under the wrong us… Patch early 7.1 high 2.7% 2007-06-12
CVE-2014-2022 EXP SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated use… Patch early 7.1 high 2.7% 2014-10-15
CVE-2017-8221 EXP Wireless IP Camera (P2P) WIFICAM devices rely on a cleartext UDP tunnel protocol (aka the Cloud feature) for communication between an Android applicat… Patch early 7.5 high 2.7% 2017-04-25
CVE-2008-2346 EXP AlkalinePHP 0.77.35 and earlier allows remote attackers to bypass authentication and gain administrative access by creating an admin account via a dir… Patch early 7.5 high 2.7% 2008-05-20
CVE-2004-2036 EXP SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject a… Patch early 7.5 high 2.7% 2004-05-28
CVE-2005-2323 EXP Multiple SQL injection vulnerabilities in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allow remote attackers to modify SQL… Patch early 7.5 high 2.7% 2005-07-19
CVE-2015-1428 EXP Multiple SQL injection vulnerabilities in Sefrengo before 1.6.2 allow (1) remote attackers to execute arbitrary SQL commands via the sefrengo cookie i… Patch early 7.5 high 2.7% 2015-02-03
CVE-2004-1601 EXP Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files and execute local PHP scripts v… Patch early 7.5 high 2.7% 2004-10-16
← previous page 253 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt