peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,734 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-4137 EXP SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL commands via the program param… Patch early 7.5 high 2.5% 2015-05-29
CVE-2009-1771 EXP index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which allows remote attackers to cr… Patch early 7.5 high 2.5% 2009-05-22
CVE-2008-5201 EXP Directory traversal vulnerability in index.php in OTManager CMS 24a allows remote attackers to include and execute arbitrary local files via a .. (dot… Patch early 7.5 high 2.5% 2008-11-21
CVE-2008-1493 EXP Directory traversal vulnerability in login.php in Cuteflow Bin 1.5.0 allows remote attackers to include and execute arbitrary local files via a .. (do… Patch early 7.5 high 2.5% 2008-03-25
CVE-2008-3564 EXP Multiple directory traversal vulnerabilities in index.php in Dayfox Blog 4 allow remote attackers to include and execute arbitrary local files via a .… Patch early 7.5 high 2.5% 2008-08-10
CVE-2014-3868 EXP Multiple SQL injection vulnerabilities in ZeusCart 4.x. Patch early 8.8 high 2.5% 2020-01-31
CVE-2004-1291 EXP Buffer overflow in qwik-smtpd allows remote attackers to use the server as an SMTP spam relay via a long HELO command, which overwrites the adjacent l… Patch early 7.5 high 2.5% 2005-01-10
CVE-2001-0519 EXP Aladdin eSafe Gateway versions 2.x allows a remote attacker to circumvent HTML SCRIPT filtering via a special arrangement of HTML tags which includes… Patch early 7.5 high 2.5% 2001-08-14
CVE-2021-32403 EXP Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mechanisms for token protection and… Patch early 8.8 high 2.5% 2021-05-17
CVE-2009-0444 EXP Multiple PHP remote file inclusion vulnerabilities in GRBoard 1.8, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote att… Patch early 7.5 high 2.5% 2009-02-10
CVE-2009-1248 EXP Multiple PHP remote file inclusion vulnerabilities in Acute Control Panel 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 2.5% 2009-04-06
CVE-2009-4056 EXP Directory traversal vulnerability in admin/popup.php in Betsy CMS 3.5 allows remote attackers to include and execute arbitrary local files via a .. (d… Patch early 7.5 high 2.5% 2009-11-24
CVE-2009-4929 EXP admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrary password… Patch early 7.5 high 2.5% 2010-07-12
CVE-2012-2961 EXP SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL c… Patch early 7.5 high 2.5% 2012-07-23
CVE-2011-5213 EXP Multiple SQL injection vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login[u… Patch early 7.5 high 2.5% 2012-10-25
CVE-2008-2396 EXP PHP remote file inclusion vulnerability in index.php in Wajox Software microSSys CMS 1.5 and earlier, when register_globals is enabled, allows remote… Patch early 7.5 high 2.5% 2008-05-21
CVE-2008-3721 EXP PHP remote file inclusion vulnerability in user_language.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary PHP code via a U… Patch early 7.5 high 2.5% 2008-08-20
CVE-2008-6223 EXP PHP remote file inclusion vulnerability in visualizza.php in Way Of The Warrior (WOTW) 5.0 and earlier allows remote attackers to execute arbitrary PH… Patch early 7.5 high 2.5% 2009-02-20
CVE-2009-4471 EXP Multiple PHP remote file inclusion vulnerabilities in FreeSchool 1.1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in t… Patch early 7.5 high 2.5% 2009-12-30
CVE-2008-6001 EXP index.php in ADN Forum 1.0b and earlier allows remote attackers to bypass authentication and gain sysop access via a fpusuario cookie composed of an i… Patch early 7.5 high 2.5% 2009-01-28
CVE-2008-6291 EXP Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLETTERLOGIN cookie to "admin". Patch early 7.5 high 2.5% 2009-02-26
CVE-2008-6963 EXP admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privileges via a direct request. Patch early 7.5 high 2.5% 2009-08-13
CVE-2008-2297 EXP The admin.php file in Rantx allows remote attackers to bypass authentication and gain privileges by setting the logininfo cookie to "<?php" or "?>", w… Patch early 7.5 high 2.5% 2008-05-18
CVE-2017-7851 EXP D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a substr… Patch early 8.8 high 2.5% 2017-11-15
CVE-2009-1752 EXP exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which allows remote attackers to gain p… Patch early 7.5 high 2.5% 2009-05-22
CVE-2008-4649 EXP Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. Patch early 7.5 high 2.4% 2008-10-22
CVE-2007-3582 EXP SQL injection vulnerability in index.php in SuperCali PHP Event Calendar 0.4.0 allows remote attackers to execute arbitrary SQL commands via the o par… Patch early 7.5 high 2.4% 2007-07-05
CVE-2007-3292 EXP Unrestricted file upload vulnerability in LiveCMS 3.4 and earlier allows remote attackers to upload and execute arbitrary PHP code by specifying a PHP… Patch early 7.5 high 2.4% 2007-06-20
CVE-2008-2349 EXP Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.p… Patch early 7.5 high 2.4% 2008-05-20
CVE-2008-6613 EXP uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct requ… Patch early 7.5 high 2.4% 2009-04-06
← previous page 270 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt