peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,734 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-1654 EXP Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the logi… Patch early 7.5 high 2.5% 2005-05-18
CVE-2018-14029 EXP CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifying the acc… Patch early 8.8 high 2.5% 2018-07-13
CVE-2013-6058 EXP SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to blog-by-ca… Patch early 7.5 high 2.5% 2013-11-14
CVE-2013-6936 EXP Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers… Patch early 7.5 high 2.5% 2013-12-04
CVE-2006-6760 EXP Multiple PHP remote file inclusion vulnerabilities in template.php in Phpmymanga 0.8.1 and earlier allow remote attackers to execute arbitrary PHP cod… Patch early 7.5 high 2.5% 2006-12-27
CVE-2002-1499 EXP Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber pa… Patch early 7.5 high 2.5% 2003-04-02
CVE-2017-9415 EXP Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target username to hijack the authenti… Patch early 7.5 high 2.5% 2017-07-21
CVE-2008-5581 EXP PHP remote file inclusion vulnerability in mini-pub.php/front-end/img.php in mini-pub 0.3 allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 2.5% 2008-12-15
CVE-2006-5918 EXP Unrestricted file upload vulnerability in RapidKill (aka PHP Rapid Kill) 5.7 Pro, and certain other versions, allows remote attackers to upload and ex… Patch early 7.5 high 2.5% 2006-11-15
CVE-2007-0170 EXP PHP remote file inclusion vulnerability in index.php in AllMyVisitors 0.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the AMV… Patch early 7.5 high 2.5% 2007-01-11
CVE-2009-4927 EXP WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cookie, as demonstrated by setting… Patch early 7.5 high 2.5% 2010-07-12
CVE-2008-5585 EXP Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrary PHP code via a URL in the ph… Patch early 7.5 high 2.5% 2008-12-16
CVE-2008-5922 EXP Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Cant Find A Gaming CMS (CFAGCMS) 1 allow remote attackers to execute… Patch early 7.5 high 2.5% 2009-01-21
CVE-2008-6036 EXP PHP remote file inclusion vulnerability in main.inc.php in BaseBuilder 2.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a U… Patch early 7.5 high 2.5% 2009-02-03
CVE-2010-0755 EXP PHP remote file inclusion vulnerability in include/WBmap.php in WikyBlog 1.7.3 rc2 allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 2.5% 2010-02-27
CVE-2008-4529 EXP Multiple PHP remote file inclusion vulnerabilities in asiCMS alpha 0.208 allow remote attackers to execute arbitrary PHP code via a URL in the _ENV[as… Patch early 7.5 high 2.5% 2008-10-09
CVE-2016-3053 EXP IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. Patch early 7.8 high 2.5% 2017-02-01
CVE-2025-48868 EXP Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horill… Patch early 7.2 high 2.5% 2025-09-24
CVE-2007-2232 EXP The CHECK command in Cosign 2.0.1 and earlier allows remote attackers to bypass authentication requirements via CR (\r) sequences in the cosign cookie… Patch early 7.5 high 2.5% 2007-04-25
CVE-2026-43284 EXP In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attac… Patch early 8.8 high 2.5% 2026-05-08
CVE-2008-6553 EXP microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an administrator, which allows r… Patch early 7.5 high 2.5% 2009-03-30
CVE-2008-6716 EXP homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows remote attackers to have an uns… Patch early 7.5 high 2.5% 2009-04-13
CVE-2008-6717 EXP U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers… Patch early 7.5 high 2.5% 2009-04-13
CVE-2008-6719 EXP U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows re… Patch early 7.5 high 2.5% 2009-04-13
CVE-2006-5423 EXP PHP remote file inclusion vulnerability in admin/admin_module.php in Lou Portail 1.4.1, and possibly earlier, allows remote attackers to execute arbit… Patch early 7.5 high 2.5% 2006-10-20
CVE-2006-6151 EXP PHP remote file inclusion vulnerability in centre.php in Messagerie Locale as of 20061127 allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 2.5% 2006-11-28
CVE-2006-6416 EXP Multiple PHP remote file inclusion vulnerabilities in PhpLeague - Univert PhpLeague 0.81 allow remote attackers to execute arbitrary PHP code via a UR… Patch early 7.5 high 2.5% 2006-12-10
CVE-2018-15844 EXP An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/… Patch early 8.8 high 2.5% 2018-08-25
CVE-2006-4944 EXP PHP remote file inclusion vulnerability in includes/pear/Net/DNS/RR.php in ProgSys 0.151 and earlier allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 2.5% 2006-09-23
CVE-2005-1417 EXP Multiple SQL injection vulnerabilities in MaxWebPortal 2.x, 1.35, and other versions allow remote attackers to execute arbitrary SQL commands via (1)… Patch early 7.5 high 2.5% 2005-05-03
← previous page 269 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt