peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,729 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-6296 EXP admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "demo." Patch early 7.5 high 2.5% 2009-02-26
CVE-2008-6966 EXP AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass authe… Patch early 7.5 high 2.5% 2009-08-13
CVE-2008-7066 EXP OpenForum 0.66 Beta allows remote attackers to bypass authentication and reset passwords of other users via a direct request with the update parameter… Patch early 7.5 high 2.5% 2009-08-25
CVE-2009-3317 EXP PHP remote file inclusion vulnerability in pages/pageHeader.php in OpenSiteAdmin 0.9.7 BETA allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 2.5% 2009-09-23
CVE-2009-3817 EXP PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary (com_booklibrary) component 1.0 for Joomla! allows remote attackers… Patch early 7.5 high 2.5% 2009-10-28
CVE-2007-0500 EXP PHP remote file inclusion vulnerability in include/includes.php in Bradabra 2.0.5 and earlier allows remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 2.5% 2007-01-25
CVE-2008-4137 EXP PHP remote file inclusion vulnerability in footer.php in PHP-Crawler 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the footer… Patch early 7.5 high 2.5% 2008-09-24
CVE-2007-5108 EXP Unspecified vulnerability in IAC Search & Media ask.com toolbar has unknown impact and remote attack vectors. NOTE: this information is based upon a… Patch early 10.0 high 2.5% 2007-09-26
CVE-2008-0350 EXP admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain adminis… Patch early 7.5 high 2.5% 2008-01-18
CVE-2008-0818 EXP Multiple directory traversal vulnerabilities in freePHPgallery 0.6 allow remote attackers to include and execute arbitrary local files via a .. (dot d… Patch early 7.5 high 2.5% 2008-02-19
CVE-2008-4522 EXP Multiple directory traversal vulnerabilities in JMweb MP3 Music Audio Search and Download Script allow remote attackers to include and execute arbitra… Patch early 7.5 high 2.5% 2008-10-09
CVE-2008-5291 EXP Directory traversal vulnerability in code/track.php in FuzzyLime 3.03 allows remote attackers to include and execute arbitrary local files via directo… Patch early 7.5 high 2.5% 2008-12-01
CVE-2005-4276 EXP Westell Versalink 327W allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs a… Patch early 7.8 high 2.5% 2005-12-16
CVE-2006-5431 EXP PHP remote file inclusion vulnerability in gorum/dbproperty.php in PHPOutsourcing Zorum 3.5 and earlier allows remote attackers to execute arbitrary P… Patch early 7.5 high 2.5% 2006-10-20
CVE-2006-6694 EXP Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 2.5% 2006-12-21
CVE-2006-6722 EXP Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct request to admin.php with the Logi… Patch early 7.5 high 2.5% 2006-12-23
CVE-2006-6788 EXP Multiple PHP remote file inclusion vulnerabilities in LuckyBot 3 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter t… Patch early 7.5 high 2.5% 2006-12-28
CVE-2006-6793 EXP PHP remote file inclusion vulnerability in ataturk.php in Okul Merkezi Portal 1.0 allows remote attackers to execute arbitrary PHP code via a URL in t… Patch early 7.5 high 2.5% 2006-12-28
CVE-2014-1206 EXP SQL injection vulnerability in the password reset page in Open Web Analytics (OWA) before 1.5.5 allows remote attackers to execute arbitrary SQL comma… Patch early 7.5 high 2.5% 2014-01-15
CVE-1999-0744 EXP Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request. Patch early 7.5 high 2.5% 2000-01-04
CVE-2007-2621 EXP SQL injection vulnerability in event_view.php in Thyme Calendar 1.3 allows remote attackers to execute arbitrary SQL commands via the eid parameter. Patch early 7.5 high 2.5% 2007-05-11
CVE-2007-3526 EXP Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the news_id para… Patch early 7.5 high 2.5% 2007-07-03
CVE-2007-3808 EXP SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL commands via the categories[] para… Patch early 7.5 high 2.5% 2007-07-17
CVE-2007-2665 EXP PHP remote file inclusion vulnerability in block.php in PhpFirstPost 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the Includ… Patch early 7.5 high 2.5% 2007-05-14
CVE-2009-2293 EXP Optimum Web Design Tutorial Share 3.5.0 and earlier allows remote attackers to bypass authentication and obtain administrative access by setting the u… Patch early 7.5 high 2.5% 2009-07-01
CVE-2006-4649 EXP PHP remote file inclusion vulnerability in bp_news.php in BinGo News (BP News) 3.01 and earlier allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 2.5% 2006-09-08
CVE-2006-4716 EXP PHP remote file inclusion vulnerability in demarrage.php in Fire Soft Board (FSB) RC3 and earlier allows remote attackers to execute arbitrary PHP cod… Patch early 7.5 high 2.5% 2006-09-12
CVE-2006-4770 EXP PHP remote file inclusion vulnerability in menu.php in MiniPort@l 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in t… Patch early 7.5 high 2.5% 2006-09-13
CVE-2006-5022 EXP PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allows remote attackers to execute… Patch early 7.5 high 2.5% 2006-09-27
CVE-2006-5126 EXP PHP remote file inclusion vulnerability in index.php in John Himmelman (aka DaRk2k1) PowerPortal 1.3a allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 2.5% 2006-10-03
← previous page 267 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt