peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,729 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-5135 EXP Multiple PHP remote file inclusion vulnerabilities in A-Blog 2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) open_box, (2)… Patch early 7.5 high 2.5% 2006-10-03
CVE-2006-5189 EXP PHP remote file inclusion vulnerability in funzioni/lib/show_hlp.php in klinza professional cms 5.0.1 and earlier allows remote attackers to execute a… Patch early 7.5 high 2.5% 2006-10-10
CVE-2006-5254 EXP PHP remote file inclusion vulnerability in registration_detailed.inc.php in Mark Van Bellen Detailed User Registration (com_registration_detailed), ak… Patch early 7.5 high 2.5% 2006-10-12
CVE-2006-5257 EXP PHP remote file inclusion vulnerability in modules/forum/include/config.php in Ciamos Content Management System (CMS) 0.9.6b and earlier allows remote… Patch early 7.5 high 2.5% 2006-10-12
CVE-2006-5623 EXP PHP remote file inclusion vulnerability in ip.inc.php in Electronic Engineering Tool (EE Tool) 0.4-1 and earlier allows remote attackers to execute ar… Patch early 7.5 high 2.5% 2006-10-31
CVE-2006-5672 EXP PHP remote file inclusion vulnerability in web/init_mysource.php in MySource CMS 2.16.2 and earlier allows remote attackers to execute arbitrary PHP c… Patch early 7.5 high 2.5% 2006-11-03
CVE-2006-3262 EXP SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary SQL command… Patch early 7.5 high 2.5% 2006-06-27
CVE-2010-1922 EXP Multiple PHP remote file inclusion vulnerabilities in 29o3 CMS 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the LibDir parame… Patch early 7.5 high 2.5% 2010-05-12
CVE-2010-2341 EXP PHP remote file inclusion vulnerability in system/application/views/public/commentform.php in EZPX Photoblog 1.2 beta allows remote attackers to execu… Patch early 7.5 high 2.5% 2010-06-18
CVE-2007-5465 EXP Directory traversal vulnerability in doop CMS 1.3.7 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot… Patch early 7.5 high 2.5% 2007-10-15
CVE-2007-0518 EXP Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote a… Patch early 7.5 high 2.5% 2007-01-26
CVE-2007-0361 EXP PHP remote file inclusion vulnerability in mep/frame.php in PHPMyphorum 1.5a allows remote attackers to execute arbitrary PHP code via a URL in the ch… Patch early 7.5 high 2.5% 2007-01-19
CVE-2007-0558 EXP PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 2.5% 2007-01-30
CVE-2007-0559 EXP PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the sql_language… Patch early 7.5 high 2.5% 2007-01-30
CVE-2007-0572 EXP PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Golem Gaming Portal 0.5.1 Alpha 2 and earlier allows remote attackers to… Patch early 7.5 high 2.5% 2007-01-30
CVE-2007-0810 EXP PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to execute arbitrary PHP code via a U… Patch early 7.5 high 2.5% 2007-02-07
CVE-2008-2687 EXP Directory traversal vulnerability in inc/config.php in ProManager 0.73 allows remote attackers to include and execute arbitrary local files via a .. (… Patch early 7.5 high 2.5% 2008-06-13
CVE-2008-2966 EXP Directory traversal vulnerability in viewprofile.php in JaxUltraBB 2.0 and earlier allows remote attackers to read arbitrary local files via a .. (dot… Patch early 7.5 high 2.5% 2008-07-02
CVE-2008-3036 EXP Directory traversal vulnerability in index.php in CMS little 0.0.1 allows remote attackers to include and execute arbitrary local files, and probably… Patch early 7.5 high 2.5% 2008-07-07
CVE-2008-4702 EXP Multiple directory traversal vulnerabilities in PhpWebGallery 1.3.4 allow remote attackers to include and execute arbitrary local files via a .. (dot… Patch early 7.5 high 2.5% 2008-10-22
CVE-2009-4626 EXP Directory traversal vulnerability in menu.php in phpNagios 1.2.0 allows remote attackers to include and execute arbitrary local files via directory tr… Patch early 7.5 high 2.5% 2010-01-18
CVE-2016-6079 EXP IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IB… Patch early 7.8 high 2.5% 2017-02-15
CVE-2006-4857 EXP SQL injection vulnerability in default.asp (aka the login page) in ClickTech ClickBlog 2.0 allows remote attackers to execute arbitrary SQL commands v… Patch early 7.5 high 2.5% 2006-09-19
CVE-2025-27751 EXP Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Patch early 7.8 high 2.5% 2025-04-08
CVE-2017-15730 EXP In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php. Patch early 8.8 high 2.5% 2017-10-22
CVE-2017-17615 EXP Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter. Patch early 8.8 high 2.5% 2017-12-13
CVE-2006-3775 EXP SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrary… Patch early 7.5 high 2.5% 2006-07-24
CVE-2011-4832 EXP Directory traversal vulnerability in CaupoShop Pro 2.x, CaupoShop Classic 3.01, and CaupoShop Pro 3.70 and earlier allows remote attackers to read arb… Patch early 7.5 high 2.5% 2011-12-15
CVE-2000-0116 EXP Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the "Strip Script Tags" restriction by including an extra < i… Patch early 7.5 high 2.5% 2000-01-29
CVE-2003-0377 EXP SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote attackers to… Patch early 7.5 high 2.5% 2003-06-16
← previous page 268 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt