peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,734 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-2894 EXP Directory traversal vulnerability in the FTP client in NCH Software Classic FTP 1.02 for Windows allows remote FTP servers to create or overwrite arbi… Patch early 9.3 high 2.4% 2008-06-27
CVE-2019-1170 EXP An elevation of privilege vulnerability exists when reparse points are created by sandboxed processes allowing sandbox escape. An attacker who success… Patch early 7.9 high 2.4% 2019-08-14
CVE-2006-6281 EXP PHP remote file inclusion vulnerability in check_status.php in dicshunary 0.1 alpha allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 2.4% 2006-12-04
CVE-2006-6593 EXP PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD for phpBB allows remote attackers to execute arbitrary PHP code via a U… Patch early 7.5 high 2.4% 2006-12-15
CVE-2011-5200 EXP Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1)… Patch early 7.5 high 2.4% 2012-09-23
CVE-2001-0082 EXP Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets. Patch early 7.5 high 2.4% 2001-02-12
CVE-2004-1873 EXP SQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via the catcode parameter. Patch early 7.5 high 2.4% 2004-12-31
CVE-2001-0579 EXP lpadmin in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first argument to the com… Patch early 7.5 high 2.4% 2001-08-22
CVE-2007-4846 EXP SQL injection vulnerability in start.php in Webace-Linkscript (wls) 1.3 Special Edition (SE) allows remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 2.4% 2007-09-12
CVE-2008-3251 EXP Multiple SQL injection vulnerabilities in tplSoccerSite 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the opp parameter to tamp… Patch early 7.5 high 2.4% 2008-07-21
CVE-2008-3498 EXP SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands vi… Patch early 7.5 high 2.4% 2008-08-06
CVE-2008-3563 EXP Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the checked array p… Patch early 7.5 high 2.4% 2008-08-10
CVE-2008-4886 EXP SQL injection vulnerability in index.php in YourFreeWorld Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the c par… Patch early 7.5 high 2.4% 2008-11-04
CVE-2015-6911 EXP SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL commands via the id parameter t… Patch early 7.5 high 2.4% 2015-09-11
CVE-2008-2296 EXP PHP remote file inclusion vulnerability in include/bbs.lib.inc.php in Rgboard 3.0.12 allows remote attackers to execute arbitrary PHP code via a URL i… Patch early 7.5 high 2.4% 2008-05-18
CVE-2008-2977 EXP Multiple PHP remote file inclusion vulnerabilities in Ourvideo CMS 9.5 allow remote attackers to execute arbitrary PHP code via a URL in the include_c… Patch early 7.5 high 2.4% 2008-07-02
CVE-2008-3570 EXP PHP remote file inclusion vulnerability in index.php in Africa Be Gone (ABG) 1.0a allows remote attackers to execute arbitrary PHP code via a URL in t… Patch early 7.5 high 2.4% 2008-08-10
CVE-2008-5577 EXP PHP remote file inclusion vulnerability in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 2.4% 2008-12-15
CVE-2009-4472 EXP Multiple PHP remote file inclusion vulnerabilities in PHPope 1.0.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (… Patch early 7.5 high 2.4% 2009-12-30
CVE-2005-4218 EXP SQL injection vulnerability in forum.php in PHPWebThings 1.4 allows remote attackers to execute arbitrary SQL commands via the msg parameter, a differ… Patch early 7.5 high 2.4% 2005-12-14
CVE-2007-2725 EXP The DB Software Laboratory DeWizardX (DEWizardAX.ocx) ActiveX control allows remote attackers to overwrite arbitrary files via the SaveToFile function… Patch early 7.5 high 2.4% 2007-05-16
CVE-2008-2110 EXP Unrestricted file upload vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to execute arbitrary PHP code by uploading a file wi… Patch early 7.5 high 2.4% 2008-05-07
CVE-2008-5593 EXP Multiple directory traversal vulnerabilities in index.php in Mini CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via a… Patch early 7.5 high 2.4% 2008-12-16
CVE-2009-1504 EXP Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to "l… Patch early 7.5 high 2.4% 2009-05-01
CVE-2009-1678 EXP Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allows remote attackers to create… Patch early 7.5 high 2.4% 2009-05-18
CVE-2009-1854 EXP Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the userid cookie to 1. Patch early 7.5 high 2.4% 2009-06-01
CVE-2014-5284 EXP host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local users to modif… Patch early 7.2 high 2.4% 2014-12-02
CVE-2026-46300 EXP In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() ca… Patch early 7.8 high 2.4% 2026-05-23
CVE-2006-5923 EXP PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and earlier allows remote attacke… Patch early 7.5 high 2.4% 2006-11-15
CVE-2006-6051 EXP PHP remote file inclusion vulnerability in reporter.logic.php in the MosReporter (com_reporter) component for Mambo and Joomla! allows remote attacker… Patch early 7.5 high 2.4% 2006-11-22
← previous page 272 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt