peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,696 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2013-3524 EXP SQL injection vulnerability in popupnewsitem/ in the Pop Up News module 2.0 and possibly earlier for phpVMS allows remote attackers to execute arbitra… Patch early 7.5 high 2.6% 2013-05-10
CVE-2006-4871 EXP SQL injection vulnerability in search_run.asp in Keyvan1 (aka Keyvan Janghorbani) EShoppingPro 1.0 allows remote attackers to execute arbitrary SQL co… Patch early 7.5 high 2.6% 2006-09-19
CVE-2006-4872 EXP SQL injection vulnerability in search.asp in Keyvan1 (aka Keyvan Janghorbani) ECardPro 2.0 allows remote attackers to execute arbitrary SQL commands v… Patch early 7.5 high 2.6% 2006-09-19
CVE-2006-4715 EXP SQL injection vulnerability in pdf_version.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier allows remote attackers to… Patch early 7.5 high 2.6% 2006-09-12
CVE-2006-5910 EXP Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 20061110 allow remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 2.6% 2006-11-15
CVE-2006-5786 EXP Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary files via… Patch early 7.5 high 2.6% 2006-11-07
CVE-2007-0049 EXP Geckovich TaskTracker Pro 1.5 and earlier allows remote attackers to add administrative or other accounts via an Add action with a modified GroupID in… Patch early 7.5 high 2.6% 2007-01-04
CVE-2008-5943 EXP Multiple directory traversal vulnerabilities in NavBoard 16 (2.6.0) allow remote attackers to include and execute arbitrary local files via a .. (dot… Patch early 7.5 high 2.6% 2009-01-22
CVE-2005-4228 EXP Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since,… Patch early 7.5 high 2.6% 2005-12-14
CVE-2004-1943 EXP PHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 2.6% 2004-04-19
CVE-2006-3309 EXP SQL injection vulnerability in SPT--ForumTopics.php in Scout Portal Toolkit (SPT) 1.4.0 and earlier allows remote attackers to execute arbitrary SQL c… Patch early 7.5 high 2.6% 2006-06-29
CVE-2006-4987 EXP Multiple PHP remote file inclusion vulnerabilities in Patrick Michaelis Wili-CMS allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 2.6% 2006-09-26
CVE-2006-5103 EXP PHP remote file inclusion vulnerability in admin/index2.php in bbsNew 2.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the "ri… Patch early 7.5 high 2.6% 2006-10-03
CVE-2006-5193 EXP PHP remote file inclusion vulnerability in index.php in Josh Schmidt WikyBlog 1.2.3 and earlier allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 2.6% 2006-10-10
CVE-2013-2594 EXP SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote attackers to execute arbitrary S… Patch early 7.5 high 2.6% 2014-01-21
CVE-2013-5694 EXP SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arbitrary SQL commands via the se… Patch early 7.5 high 2.6% 2013-11-05
CVE-2008-2347 EXP MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting the userID parameter to "admin… Patch early 7.5 high 2.6% 2008-05-20
CVE-2008-4081 EXP admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by setting a bsm cookie. Patch early 7.5 high 2.6% 2008-09-15
CVE-2008-4714 EXP Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to… Patch early 7.5 high 2.6% 2008-10-23
CVE-2008-5040 EXP Graphiks MyForum 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the (1) myforum_login and (2) myforum_… Patch early 7.5 high 2.6% 2008-11-12
CVE-2008-5065 EXP TlGuestBook 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlGuestBook_login cookie to admin. Patch early 7.5 high 2.6% 2008-11-13
CVE-2008-6009 EXP SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1. Patch early 7.5 high 2.6% 2009-01-30
CVE-2008-6162 EXP Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1 and the usNick… Patch early 7.5 high 2.6% 2009-02-20
CVE-2008-6411 EXP Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the login cookie to 1. Patch early 7.5 high 2.6% 2009-03-06
CVE-2008-6523 EXP auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the oiauth cookie. NOTE… Patch early 7.5 high 2.6% 2009-03-25
CVE-2008-6667 EXP A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser… Patch early 7.5 high 2.6% 2009-04-08
CVE-2008-6738 EXP MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_access cookie to 1. Patch early 7.5 high 2.6% 2009-04-21
CVE-2008-6804 EXP Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOKI… Patch early 7.5 high 2.6% 2009-05-11
CVE-2008-7019 EXP Esqlanelapse 2.6.1 and 2.6.2 allows remote attackers to bypass authentication and gain privileges via modified (1) enombre and (2) euri cookies. Patch early 7.5 high 2.6% 2009-08-21
CVE-2008-7028 EXP RPG.Board 0.8 Beta2 and earlier allows remote attackers to bypass authentication and gain privileges by setting the keep4u cookie to a certain value. Patch early 7.5 high 2.6% 2009-08-21
← previous page 262 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt