peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,746 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-5786 EXP Multiple PHP remote file inclusion vulnerabilities in GoSamba 1.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the include_path… Patch early 7.5 high 2.4% 2007-11-01
CVE-2007-6229 EXP PHP remote file inclusion vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote attackers to execute arbitrary… Patch early 7.5 high 2.4% 2007-12-04
CVE-2004-1536 EXP SQL injection vulnerability in index.php in the ibProArcade module for Invision Power Board (IPB) 1.x and 2.x allows remote attackers to execute arbit… Patch early 7.5 high 2.4% 2004-12-31
CVE-2004-2062 EXP SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2… Patch early 7.5 high 2.4% 2004-12-31
CVE-2005-3326 EXP SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the awayday paramete… Patch early 7.5 high 2.4% 2005-10-27
CVE-2005-3865 EXP SQL injection vulnerability in index.php in AllWeb search 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the search par… Patch early 7.5 high 2.4% 2005-11-29
CVE-2007-2298 EXP Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 2.4% 2007-04-26
CVE-2007-2572 EXP PHP remote file inclusion vulnerability in modules/noevents/templates/mfa_theme.php in NoAh (aka PHP Content Architect, phparch) 0.9 pre 1.2 and earli… Patch early 7.5 high 2.4% 2007-05-09
CVE-2006-6710 EXP Multiple PHP remote file inclusion vulnerabilities in PgmReloaded 0.8.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 2.4% 2006-12-23
CVE-2015-6519 EXP SQL injection vulnerability in Arab Portal 3 allows remote attackers to execute arbitrary SQL commands via the showemail parameter in a signup action… Patch early 7.5 high 2.4% 2015-08-18
CVE-2002-0991 EXP Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, allows local users to gain root p… Patch early 7.2 high 2.4% 2002-10-04
CVE-2009-4222 EXP phpBazar 2.1.1fix and earlier does not require administrative authentication for admin/admin.php, which allows remote attackers to obtain access to th… Patch early 7.5 high 2.4% 2009-12-07
CVE-2007-4933 EXP Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and earlier allows remote attackers to in… Patch early 7.5 high 2.4% 2007-09-18
CVE-2007-5055 EXP Multiple directory traversal vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to include and execute arbitrary local files via… Patch early 7.5 high 2.4% 2007-09-24
CVE-2007-6396 EXP Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and earlier allows remote attackers to inject arbitrary PHP code via the… Patch early 7.5 high 2.4% 2007-12-17
CVE-2005-0781 EXP SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL comma… Patch early 7.5 high 2.4% 2005-05-02
CVE-2005-1236 EXP Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via the (1) iCh… Patch early 7.5 high 2.4% 2005-05-02
CVE-2005-2049 EXP Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState parameter… Patch early 7.5 high 2.4% 2005-06-22
CVE-2005-2788 EXP Multiple SQL injection vulnerabilities in Land Down Under (LDU) 801 and earlier allow remote attackers to execute arbitrary SQL commands via the c par… Patch early 7.5 high 2.4% 2005-09-02
CVE-2015-1400 EXP SQL injection vulnerability in search.php in NPDS Revolution 13 allows remote attackers to execute arbitrary SQL commands via the query parameter. Patch early 7.5 high 2.4% 2015-02-03
CVE-2012-1225 EXP Multiple SQL injection vulnerabilities in Dolibarr CMS 3.2.0 Alpha and earlier allow remote authenticated users to execute arbitrary SQL commands via… Patch early 7.5 high 2.4% 2012-02-21
CVE-2011-4674 EXP SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions before 1.8.9, allows remote attackers to execute arbit… Patch early 7.5 high 2.4% 2011-12-02
CVE-2007-1432 EXP Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to gain privileges via direct requests with modified arguments in (1) the… Patch early 7.5 high 2.4% 2007-03-13
CVE-2007-2851 EXP A certain ActiveX control in LeadTools Raster Variant Object Library (LTRVR14e.dll) 14.5.0.44 allows remote attackers to overwrite arbitrary files via… Patch early 7.5 high 2.4% 2007-05-24
CVE-2005-0411 EXP Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files v… Patch early 7.5 high 2.4% 2005-02-14
CVE-2000-1244 EXP Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP header is missing the "From" field… Patch early 7.5 high 2.4% 2000-12-31
CVE-2005-2683 EXP Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter to login/… Patch early 7.5 high 2.4% 2005-08-23
CVE-2006-0064 EXP PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 2.4% 2006-01-03
CVE-2006-1094 EXP SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via t… Patch early 7.5 high 2.4% 2006-03-09
CVE-2012-0973 EXP Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter to… Patch early 7.5 high 2.4% 2012-09-25
← previous page 274 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt