peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,696 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-2113 EXP Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to player.p… Patch early 7.5 high 2.6% 2009-06-18
CVE-2018-16156 EXP In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messages receiv… Patch early 7.8 high 2.6% 2019-05-17
CVE-2014-3871 EXP Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds and GeoAuctions) allow remote… Patch early 7.5 high 2.6% 2014-05-27
CVE-2014-5520 EXP SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via the user_id parameter to plugi… Patch early 7.5 high 2.6% 2014-10-26
CVE-2008-0683 EXP SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execu… Patch early 7.5 high 2.6% 2008-02-12
CVE-2008-5738 EXP Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the nodstrumCalendarV2… Patch early 7.5 high 2.6% 2008-12-26
CVE-2009-0108 EXP PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via modified (1) PHPAUCTION_RM_ID,… Patch early 7.5 high 2.6% 2009-01-09
CVE-2005-4244 EXP SQL injection vulnerability in Snipe Gallery 3.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) gallery_id parame… Patch early 7.5 high 2.6% 2005-12-14
CVE-2008-2920 EXP admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create… Patch early 7.5 high 2.6% 2008-06-30
CVE-2008-4528 EXP Directory traversal vulnerability in notes.php in Phlatline's Personal Information Manager (pPIM) 1.01 allows remote attackers to include and execute… Patch early 7.5 high 2.6% 2008-10-09
CVE-2009-4447 EXP Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbook.admin.p… Patch early 7.5 high 2.6% 2009-12-29
CVE-2006-5118 EXP PHP remote file inclusion vulnerability in index.php3 in the PDD package for PHPSelect Web Development Division allows remote attackers to execute arb… Patch early 7.5 high 2.6% 2006-10-03
CVE-2006-5166 EXP PHP remote file inclusion vulnerability in functions.php in PHP Web Scripts Easy Banner Free allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 2.6% 2006-10-05
CVE-2019-16531 EXP LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php. Patch early 8.8 high 2.5% 2019-09-20
CVE-2007-0644 EXP Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted attackers to cause a denial of service (crash) via format string… Patch early 7.1 high 2.5% 2007-02-01
CVE-2008-5221 EXP The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the orig… Patch early 7.5 high 2.5% 2008-11-25
CVE-2006-0074 EXP SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter. NOTE:… Patch early 7.5 high 2.5% 2006-01-04
CVE-2005-1500 EXP Multiple SQL injection vulnerabilities in myBloggie 2.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the keyword parameter in se… Patch early 7.5 high 2.5% 2005-05-11
CVE-2013-0140 EXP SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote atta… Patch early 7.9 high 2.5% 2013-05-01
CVE-2006-3173 EXP Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1)… Patch early 7.5 high 2.5% 2006-06-23
CVE-2006-3343 EXP PHP remote file inclusion vulnerability in recipe/cookbook.php in CrisoftRicette 1.0pre15b allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 2.5% 2006-07-03
CVE-2006-4156 EXP PHP remote file inclusion vulnerability in big.php in pearlabs mafia moblog 6 and earlier allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 2.5% 2006-08-16
CVE-2007-0804 EXP Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject arbitrary PHP code into arbit… Patch early 7.5 high 2.5% 2007-02-07
CVE-2008-6066 EXP Multiple PHP remote file inclusion vulnerabilities in Meet#Web 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the root_path par… Patch early 7.5 high 2.5% 2009-02-05
CVE-2008-6196 EXP Multiple PHP remote file inclusion vulnerabilities in Philippe CROCHAT EasySite 2.0 allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 2.5% 2009-02-20
CVE-2008-6206 EXP Multiple PHP remote file inclusion vulnerabilities in RobotStats 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_RO… Patch early 7.5 high 2.5% 2009-02-20
CVE-2008-6543 EXP Multiple PHP remote file inclusion vulnerabilities in ComScripts TEAM Quick Classifieds 1.0 via the DOCUMENT_ROOT parameter to (1) index.php3, (2) loc… Patch early 7.5 high 2.5% 2009-03-30
CVE-2005-3395 EXP SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter. Patch early 7.5 high 2.5% 2005-11-01
CVE-2008-3354 EXP Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to execute arbitr… Patch early 7.5 high 2.5% 2008-07-28
CVE-2006-6726 EXP PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to execute arbitrary PHP code via a U… Patch early 7.5 high 2.5% 2006-12-26
← previous page 263 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt