peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,734 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-3702 EXP Multiple absolute path traversal vulnerabilities in PHP-Calendar 1.1 allow remote attackers to include and execute arbitrary local files via a full pa… Patch early 7.5 high 2.4% 2009-12-22
CVE-2005-0343 EXP SQL injection vulnerability in PerlDesk 1.x allows remote attackers to inject arbitrary SQL commands via the view parameter. Patch early 7.5 high 2.4% 2005-05-02
CVE-2005-0786 EXP SQL injection vulnerability in gb_new.inc in SimpGB allows remote attackers to execute arbitrary SQL commands via the quote parameter to guestbook.php… Patch early 7.5 high 2.4% 2005-03-14
CVE-2005-1833 EXP Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 allow remote attackers to execute arbitrary SQL commands via the (1) eid par… Patch early 7.5 high 2.4% 2005-05-31
CVE-2001-0402 EXP IPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access restrictions… Patch early 7.5 high 2.4% 2001-06-18
CVE-2004-1406 EXP SQL injection vulnerability in ikonboard.cgi in Ikonboard 3.1.0 through 3.1.3 allows remote attackers to inject arbitrary SQL commands via the (1) st… Patch early 7.5 high 2.4% 2004-12-31
CVE-2004-1580 EXP SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. Patch early 7.5 high 2.4% 2004-12-31
CVE-2004-2218 EXP SQL injection vulnerability in pmwh.php in PHPMyWebHosting 0.3.4 and earlier allows remote attackers to modify SQL statements via the password paramet… Patch early 7.5 high 2.4% 2004-12-31
CVE-2005-2000 EXP Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter… Patch early 7.5 high 2.4% 2005-06-15
CVE-2006-6212 EXP PHP remote file inclusion vulnerability in centre.php in Site News (site_news) 2.00, and possibly earlier, allows remote attackers to execute arbitrar… Patch early 7.5 high 2.4% 2006-12-01
CVE-2009-2263 EXP Directory traversal vulnerability in index.php in Awesome PHP Mega File Manager 1.0 allows remote attackers to include and execute arbitrary local fil… Patch early 7.5 high 2.4% 2009-06-30
CVE-2007-4439 EXP PHP remote file inclusion vulnerability in popup_window.php in Squirrelcart 1.x.x and earlier allows remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 2.4% 2007-08-21
CVE-2007-6178 EXP Multiple PHP remote file inclusion vulnerabilities in Easy Hosting Control Panel for Ubuntu (EHCP) 0.22.8 and earlier allow remote attackers to execut… Patch early 7.5 high 2.4% 2007-11-30
CVE-2007-1707 EXP PHP remote file inclusion vulnerability in index.php in Net Side Content Management System (Net-Side.net CMS) allows remote attackers to execute arbit… Patch early 7.5 high 2.4% 2007-03-27
CVE-2007-1715 EXP PHP remote file inclusion vulnerability in frontpage.php in Free Image Hosting 2.0 and earlier allows remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 2.4% 2007-03-27
CVE-2007-2044 EXP PHP remote file inclusion vulnerability in mod_weather.php in the Antonis Ventouris Weather module for Mambo and Joomla! allows remote attackers to ex… Patch early 7.5 high 2.4% 2007-04-16
CVE-2007-2143 EXP PHP remote file inclusion vulnerability in index.php in the Be2004-2 template for Joomla! allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 2.4% 2007-04-19
CVE-2007-2158 EXP PHP remote file inclusion vulnerability in index.php in jGallery 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the G_JGALL[in… Patch early 7.5 high 2.4% 2007-04-19
CVE-2006-6255 EXP Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remot… Patch early 7.5 high 2.4% 2006-12-04
CVE-2026-56766 EXP Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, a… Patch early 8.8 high 2.4% 2026-06-25
CVE-2010-4867 EXP Directory traversal vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to include and execute arbitrar… Patch early 7.5 high 2.4% 2011-10-05
CVE-2005-1026 EXP Multiple SQL injection vulnerabilities in SnailSource phpBB 2.0.x mods allow remote attackers to execute arbitrary SQL commands via the (1) file_id pa… Patch early 7.5 high 2.4% 2005-05-02
CVE-2005-2048 EXP Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL commands vi… Patch early 7.5 high 2.4% 2005-06-22
CVE-2019-9625 EXP JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account. Patch early 8.8 high 2.4% 2019-03-07
CVE-2005-2154 EXP PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and poss… Patch early 7.5 high 2.4% 2005-07-06
CVE-2008-5896 EXP CodeAvalanche RateMySite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download t… Patch early 7.5 high 2.4% 2009-01-12
CVE-2012-3839 EXP Multiple SQL injection vulnerabilities in application/core/MY_Model.php in MyClientBase 0.12 allow remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 2.4% 2012-07-03
CVE-2007-1849 EXP Directory traversal vulnerability in 404.php in Drake CMS allows remote attackers to include and execute arbitrary local arbitrary files via a .. (dot… Patch early 7.5 high 2.4% 2007-04-03
CVE-2007-2008 EXP Directory traversal vulnerability in admin.php in pL-PHP beta 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot d… Patch early 7.5 high 2.4% 2007-04-12
CVE-2004-0077 EXP The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value fr… Patch early 7.2 high 2.4% 2004-03-03
← previous page 271 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt