peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,602 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-6592 EXP Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] para… Patch early 7.5 high 2.7% 2006-12-15
CVE-2008-4718 EXP Directory traversal vulnerability in help/mini.php in X7 Chat 2.0.1 A1 and earlier allows remote attackers to include and execute arbitrary local file… Patch early 7.5 high 2.7% 2008-10-23
CVE-2005-2782 EXP PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp:/… Patch early 7.5 high 2.7% 2005-09-02
CVE-2006-5386 EXP PHP remote file inclusion vulnerability in process.php in NuralStorm Webmail 0.98b and earlier, when register_globals is enabled, allows remote attack… Patch early 7.5 high 2.7% 2006-10-18
CVE-2007-2007 EXP admin.php in pL-PHP beta 0.9 allows remote attackers to bypass authentication by setting the is_admin parameter to 1. Patch early 7.5 high 2.7% 2007-04-12
CVE-2008-6228 EXP Pre Multi-Vendor Shopping Malls allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (… Patch early 7.5 high 2.7% 2009-02-20
CVE-2006-6202 EXP PHP remote file inclusion vulnerability in modules/NukeAI/util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot,… Patch early 7.5 high 2.7% 2006-12-01
CVE-2006-6213 EXP index.php in PEGames uses the extract function to overwrite critical variables, which allows remote attackers to conduct PHP remote file inclusion att… Patch early 7.5 high 2.7% 2006-12-01
CVE-2006-1702 EXP PHP remote file inclusion vulnerability in spip_login.php3 in SPIP 1.8.3 allows remote attackers to execute arbitrary PHP code via a URL in the url pa… Patch early 7.5 high 2.7% 2006-04-11
CVE-2009-3158 EXP admin/files.php in simplePHPWeb 0.2 does not require authentication, which allows remote attackers to perform unspecified administrative actions via u… Patch early 7.5 high 2.7% 2009-09-10
CVE-2004-1401 EXP SQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and bypass authentication via the u… Patch early 7.5 high 2.7% 2004-12-31
CVE-2005-0272 EXP ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file with multiple extensions, wh… Patch early 7.5 high 2.7% 2005-05-02
CVE-2007-0178 EXP PHP remote file inclusion vulnerability in info.php in Easy Banner Pro 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the s[ph… Patch early 7.5 high 2.7% 2007-01-11
CVE-2007-0190 EXP PHP remote file inclusion vulnerability in edit_address.php in edit-x ecommerce allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 2.7% 2007-01-12
CVE-2007-2091 EXP PHP remote file inclusion vulnerability in blocks/tsdisplay4xoops_block2.php in tsdisplay4xoops (TSD4XOOPS, aka the TeamSpeak display module) 0.1 allo… Patch early 7.5 high 2.7% 2007-04-18
CVE-2008-6083 EXP Directory traversal vulnerability in header.php in TXTshop beta 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot… Patch early 7.5 high 2.7% 2009-02-06
CVE-2007-6177 EXP PHP remote file inclusion vulnerability in Exchange/include.php in PHP_CON 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 2.7% 2007-11-30
CVE-2007-0091 EXP newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database con… Patch early 7.5 high 2.7% 2007-01-05
CVE-2002-1884 EXP index.php in Py-Membres 3.1 allows remote attackers to log in as an administrator by setting the pymembs parameter to "admin". Patch early 7.5 high 2.7% 2002-12-31
CVE-2005-1820 EXP zboard.php in Zeroboard version 4.1pl2 to 4.1pl5 allows remote attackers to execute arbitrary PHP code via improper quoting when using the preg_replac… Patch early 7.5 high 2.7% 2005-06-01
CVE-2012-5231 EXP miniCMS 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code via a crafted (1) pagename or (2) area variable containing an executable ext… Patch early 7.5 high 2.7% 2012-10-01
CVE-2014-9115 EXP SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x befor… Patch early 7.5 high 2.7% 2014-12-23
CVE-2009-1949 EXP import_wbb1.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to obtain sensitive information via a direct request, which reveals the… Patch early 7.8 high 2.7% 2009-06-05
CVE-2013-7349 EXP Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (1) news_id parameter to news/s… Patch early 7.5 high 2.7% 2014-04-01
CVE-2008-5873 EXP Yerba SACphp 6.3 and earlier allows remote attackers to bypass authentication and gain administrative access via a galleta[sesion] cookie that has a v… Patch early 7.5 high 2.7% 2009-01-08
CVE-2008-4600 EXP configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain administrative access by setti… Patch early 7.5 high 2.7% 2008-10-18
CVE-2005-0569 EXP Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language parameter to regis… Patch early 7.5 high 2.7% 2005-05-02
CVE-2004-2456 EXP SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter i… Patch early 7.5 high 2.7% 2004-12-31
CVE-2006-7021 EXP PHP remote file inclusion vulnerability in manager/tools/link/dbinstall.php in Plume CMS 1.1.3 allows remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 2.7% 2007-02-15
CVE-2018-12912 EXP An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via an admin/index.php/database/ope… Patch early 7.2 high 2.6% 2018-06-27
← previous page 256 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt