peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,659 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-2025 EXP admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) G… Patch early 7.5 high 2.6% 2009-06-09
CVE-2006-3374 EXP PHP remote file inclusion vulnerability in index.php in Randshop 1.2 and earlier, including 0.9.3, allows remote attackers to execute arbitrary PHP co… Patch early 7.5 high 2.6% 2006-07-06
CVE-2006-4034 EXP PHP remote file inclusion vulnerability in include/html/config.php in ModernGigabyte ModernBill 1.6 allows remote attackers to execute arbitrary PHP c… Patch early 7.5 high 2.6% 2006-08-09
CVE-2006-4441 EXP Multiple PHP remote file inclusion vulnerabilities in Ay System Solutions CMS 2.6 and earlier allow remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 2.6% 2006-08-29
CVE-2007-2327 EXP PHP remote file inclusion vulnerability in _editor.php in HTMLeditbox 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the setti… Patch early 7.5 high 2.6% 2007-04-27
CVE-2007-2628 EXP PHP remote file inclusion vulnerability in include/logout.php in Justin Koivisto SecurityAdmin for PHP (aka PHPSecurityAdmin, PSA) 4.0.2 allows remote… Patch early 7.5 high 2.6% 2007-05-11
CVE-2012-1200 EXP Multiple PHP remote file inclusion vulnerabilities in Nova CMS allow remote attackers to execute arbitrary PHP code via a URL in the (1) fileType para… Patch early 7.5 high 2.6% 2012-02-18
CVE-2013-4789 EXP SQL injection vulnerability in modules/rss/rss.php in Cotonti before 0.9.14 allows remote attackers to execute arbitrary SQL commands via the "c" para… Patch early 7.5 high 2.6% 2013-08-09
CVE-2005-1882 EXP PHP remote file inclusion vulnerability in last_gallery.php in YaPiG 0.93u and 0.94u allows remote attackers to execute arbitrary PHP code via the YAP… Patch early 7.5 high 2.6% 2005-06-09
CVE-2005-2775 EXP php_api.php in phpWebNotes 2.0.0 uses the extract function to modify key variables such as $t_path_core, which leads to a PHP file inclusion vulnerabi… Patch early 7.5 high 2.6% 2005-09-02
CVE-2006-6856 EXP Direct static code injection vulnerability in WebText CMS 0.4.5.2 and earlier allows remote attackers to inject arbitrary PHP code into a script in wt… Patch early 7.5 high 2.6% 2006-12-31
CVE-2008-0502 EXP PHP remote file inclusion vulnerability in templates/Official/part_userprofile.php in Connectix Boards 0.8.2 and earlier allows remote attackers to ex… Patch early 7.5 high 2.6% 2008-01-31
CVE-2000-0473 EXP Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin… Patch early 7.5 high 2.6% 2000-06-15
CVE-2013-4890 EXP The DMCRUIS/0.1 web server on the Samsung PS50C7700 TV allows remote attackers to cause a denial of service (daemon crash) via a long URI to TCP port… Patch early 7.8 high 2.6% 2013-07-23
CVE-2011-4803 EXP SQL injection vulnerability in wptouch/ajax.php in the WPTouch plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the… Patch early 7.5 high 2.6% 2011-12-14
CVE-2005-2857 EXP Free SMTP Server 2.2 allows remote attackers to use the server as an open mail relay (spam proxy). Patch early 7.5 high 2.6% 2005-09-08
CVE-2007-1243 EXP Audins Audiens 3.3 allows remote attackers to bypass authentication and perform certain privileged actions, possibly an uninstall of the product, by c… Patch early 7.5 high 2.6% 2007-03-03
CVE-2006-0209 EXP SQL injection vulnerability in general_functions.php in TankLogger 2.4 allows remote attackers to execute arbitrary SQL commands via the (1) livestock… Patch early 7.5 high 2.6% 2006-01-14
CVE-2006-3315 EXP PHP remote file inclusion vulnerability in page.php in an unspecified RahnemaCo.com product, possibly eShop, allows remote attackers to execute arbitr… Patch early 7.5 high 2.6% 2006-06-29
CVE-2006-3967 EXP PHP remote file inclusion vulnerability in component/option,com_moskool/Itemid,34/admin.moskool.php in MamboXChange Moskool 1.5 allows remote attacker… Patch early 7.5 high 2.6% 2006-08-01
CVE-2006-3982 EXP PHP remote file inclusion vulnerability in quickie.php in Knusperleicht Quickie, probably 0.2, allows remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 2.6% 2006-08-05
CVE-2006-4007 EXP PHP remote file inclusion vulnerability in index.php in Knusperleicht Guestbook 3.5 allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 2.6% 2006-08-07
CVE-2006-4008 EXP PHP remote file inclusion vulnerability in index.php in Knusperleicht Faq 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the f… Patch early 7.5 high 2.6% 2006-08-07
CVE-2006-4230 EXP Multiple PHP remote file inclusion vulnerabilities in index.php in Lizge V.20 Web Portal allow remote attackers to execute arbitrary PHP code via a UR… Patch early 7.5 high 2.6% 2006-08-18
CVE-2006-4241 EXP PHP remote file inclusion vulnerability in processor/reporter.sql.php in the Reporter Mambo component (com_reporter) allows remote attackers to execut… Patch early 7.5 high 2.6% 2006-08-21
CVE-2006-4357 EXP PHP remote file inclusion vulnerability in clients/index.php in Diesel Smart Traffic allows remote attackers to execute arbitrary PHP code via a URL i… Patch early 7.5 high 2.6% 2006-08-27
CVE-2006-4443 EXP PHP remote file inclusion vulnerability in myajaxphp.php in AlstraSoft Video Share Enterprise allows remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 2.6% 2006-08-29
CVE-2006-4891 EXP SQL injection vulnerability in ArticlesTableview.asp in Techno Dreams Articles & Papers Package 2.0 and earlier allows remote attackers to execute arb… Patch early 7.5 high 2.6% 2006-09-19
CVE-2006-4892 EXP SQL injection vulnerability in faqview.asp in Techno Dreams FAQ Manager Package 1.0 allows remote attackers to execute arbitrary SQL commands via the… Patch early 7.5 high 2.6% 2006-09-19
CVE-2013-7278 EXP SQL injection vulnerability in Naxtech CMS Afroditi 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to default.asp. Patch early 7.5 high 2.6% 2014-01-08
← previous page 259 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt