peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,557 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-4839 EXP SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 2.7% 2011-09-14
CVE-2006-6093 EXP Multiple PHP remote file inclusion vulnerabilities in adminprint.php in PicturesPro Photo Cart 3.9 allow remote attackers to execute arbitrary PHP cod… Patch early 7.5 high 2.7% 2006-11-24
CVE-2001-1326 EXP Eudora 5.1 allows remote attackers to execute arbitrary code when the "Use Microsoft Viewer" option is enabled and the "allow executables in HTML cont… Patch early 7.5 high 2.7% 2001-05-29
CVE-2018-8584 EXP An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevat… Patch early 7.8 high 2.7% 2018-11-14
CVE-2021-36520 EXP A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI. Patch early 7.5 high 2.7% 2023-04-16
CVE-2010-0233 EXP Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold… Patch early 7.2 high 2.7% 2010-02-10
CVE-2002-2106 EXP PHP remote file inclusion vulnerability in WikkiTikkiTavi before 0.21 allows remote attackers to execute arbitrary PHP code via the TemplateDir variab… Patch early 7.5 high 2.7% 2002-12-31
CVE-2006-1347 EXP SQL injection vulnerability in loginfunction.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 2.7% 2006-03-22
CVE-2015-0058 EXP Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local u… Patch early 7.2 high 2.7% 2015-02-11
CVE-2017-14842 EXP Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter. Patch early 8.8 high 2.7% 2017-09-28
CVE-2017-14843 EXP Mojoomla School Management System for WordPress allows SQL Injection via the id parameter. Patch early 8.8 high 2.7% 2017-09-28
CVE-2017-14844 EXP Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter. Patch early 8.8 high 2.7% 2017-09-28
CVE-2017-14845 EXP Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter. Patch early 8.8 high 2.7% 2017-09-28
CVE-2017-14846 EXP Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter. Patch early 8.8 high 2.7% 2017-09-28
CVE-2017-14847 EXP Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter. Patch early 8.8 high 2.7% 2017-09-28
CVE-2008-6496 EXP Insecure method vulnerability in the VSPDFEditorX.VSPDFEdit ActiveX control in VSPDFEditorX.ocx 1.0.200.0 in VISAGESOFT eXPert PDF EditorX allows remo… Patch early 8.8 high 2.7% 2009-03-20
CVE-2007-4341 EXP PHP remote file inclusion vulnerability in adm/my_statistics.php in Omnistar Lib2 PHP 0.2 allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 2.7% 2007-08-14
CVE-2009-2080 EXP admin.php in MRCGIGUY The Ticket System 2.0 does not properly restrict access, which allows remote attackers to (1) obtain sensitive configuration inf… Patch early 7.5 high 2.7% 2009-06-16
CVE-2006-3027 EXP Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) CA… Patch early 7.5 high 2.7% 2006-06-15
CVE-2006-1714 EXP CRLF injection vulnerability in index.php in Christoph Roeder phpMyForum 4.0 allows remote attackers to inject HTTP headers via hex-encoded CRLF seque… Patch early 7.5 high 2.7% 2006-04-11
CVE-2006-2521 EXP PHP remote file inclusion vulnerability in cron.php in phpMyDirectory 10.4.4 and earlier allows remote attackers to execute arbitrary PHP code via a U… Patch early 7.5 high 2.7% 2006-05-22
CVE-2007-2304 EXP Multiple directory traversal vulnerabilities in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to include and execute… Patch early 7.5 high 2.7% 2007-04-26
CVE-2006-0947 EXP Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the "31" para… Patch early 7.5 high 2.7% 2006-03-01
CVE-2006-1800 EXP Directory traversal vulnerability in posts.php in SimpleBBS 1.0.6 through 1.1 allows remote attackers to include and execute arbitrary files via ".."… Patch early 7.5 high 2.7% 2006-04-18
CVE-2000-0032 EXP Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database. Patch early 10.0 high 2.7% 1999-12-22
CVE-2022-45030 EXP A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may interact with secure-file-pri… Patch early 8.8 high 2.7% 2023-04-15
CVE-2006-2962 EXP PHP remote file inclusion vulnerability in sql_fcnsOLD.php in Emergenices Personnel Information System (Empris) 20020923 and earlier allows remote att… Patch early 7.5 high 2.7% 2006-06-12
CVE-2006-4102 EXP PHP remote file inclusion vulnerability in tpl.inc.php in Falko Timme and Till Brehm SQLiteWebAdmin 0.1 and earlier allows remote attackers to execute… Patch early 7.5 high 2.7% 2006-08-14
CVE-2006-4213 EXP PHP remote file inclusion vulnerability in config.php in David Kent Norman Thatware 0.4.6 and possibly earlier allows remote attackers to execute arbi… Patch early 7.5 high 2.7% 2006-08-17
CVE-2008-2294 EXP Pet Grooming Management System 2.0 allows remote attackers to gain privileges via a direct request to useradded.php with a modified user name for "adm… Patch early 7.5 high 2.7% 2008-05-18
← previous page 254 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt