peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,879 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-1480 EXP Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD… Patch early 7.5 high 2.4% 2007-03-16
CVE-2009-4683 EXP Directory traversal vulnerability in vote.php in Good/Bad Vote allows remote attackers to include and execute arbitrary local files via directory trav… Patch early 7.5 high 2.4% 2010-03-10
CVE-2009-4957 EXP Directory traversal vulnerability in loadpanel.php in Interspire ActiveKB allows remote attackers to read arbitrary files and possibly have unspecifie… Patch early 7.5 high 2.4% 2010-07-22
CVE-2010-1043 EXP Directory traversal vulnerability in index.php in jaxCMS 1.0 allows remote attackers to include and execute arbitrary local files via directory traver… Patch early 7.5 high 2.4% 2010-03-23
CVE-2018-12739 EXP In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266. Patch early 8.8 high 2.4% 2018-07-05
CVE-2008-5190 EXP SQL injection vulnerability in index.php in eSHOP100 allows remote attackers to execute arbitrary SQL commands via the SUB parameter. Patch early 7.5 high 2.4% 2008-11-21
CVE-2008-5574 EXP SQL injection vulnerability in member.php in Webmaster Marketplace allows remote attackers to execute arbitrary SQL commands via the u parameter. Patch early 7.5 high 2.4% 2008-12-15
CVE-2008-6608 EXP Multiple SQL injection vulnerabilities in DevelopItEasy Events Calendar 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the user_… Patch early 7.5 high 2.4% 2009-04-06
CVE-2007-5579 EXP login.php in Pligg CMS 9.5 uses a guessable confirmation code when resetting a forgotten password, which allows remote attackers with knowledge of a u… Patch early 7.5 high 2.4% 2007-10-18
CVE-2008-3240 EXP SQL injection vulnerability in index.php in AlstraSoft Affiliate Network Pro allows remote attackers to execute arbitrary SQL commands via the pgm par… Patch early 7.5 high 2.4% 2008-07-21
CVE-2008-3266 EXP SQL injection vulnerability in picture_pic_bv.asp in SoftAcid Hotel Reservation System (HRS) Multi allows remote attackers to execute arbitrary SQL co… Patch early 7.5 high 2.4% 2008-07-24
CVE-2008-3416 EXP SQL injection vulnerability in modules/members.php in IceBB before 1.0-rc9.3 allows remote attackers to execute arbitrary SQL commands via the usernam… Patch early 7.5 high 2.4% 2008-07-31
CVE-2008-4613 EXP SQL injection vulnerability in forums.asp in PortalApp 4.0 allows remote attackers to execute arbitrary SQL commands via the sortby parameter. Patch early 7.5 high 2.4% 2008-10-20
CVE-2010-3893 EXP The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP addres… Patch early 7.5 high 2.4% 2010-11-12
CVE-2004-2754 EXP SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary… Patch early 7.5 high 2.4% 2004-12-31
CVE-2008-6163 EXP SQL injection vulnerability in www/delivery/ac.php in OpenX 2.6.1 allows remote attackers to execute arbitrary SQL commands via the bannerid parameter… Patch early 7.5 high 2.4% 2009-02-20
CVE-2018-15845 EXP There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add. Patch early 8.8 high 2.4% 2018-08-25
CVE-2005-1822 EXP Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) print… Patch early 7.5 high 2.4% 2005-06-01
CVE-2009-1226 EXP core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attacker… Patch early 7.5 high 2.3% 2009-04-02
CVE-2009-4096 EXP RADIO istek scripti 2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user… Patch early 7.5 high 2.3% 2009-11-29
CVE-2010-4988 EXP PHP remote file inclusion vulnerability in mod_chatting/themes/default/header.php in Family Connections Who is Chatting 2.2.3 allows remote attackers… Patch early 7.5 high 2.3% 2011-11-01
CVE-2008-3311 EXP PHP remote file inclusion vulnerability in config.php in Adam Scheinberg Flip 3.0 allows remote attackers to execute arbitrary PHP code via a URL in t… Patch early 7.5 high 2.3% 2008-07-25
CVE-2014-100031 EXP Multiple SQL injection vulnerabilities in Ganesha Digital Library (GDL) 4.2 allow remote attackers to execute arbitrary SQL commands via the id parame… Patch early 7.5 high 2.3% 2015-01-13
CVE-2014-10020 EXP SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL commands via the username paramete… Patch early 7.5 high 2.3% 2015-01-13
CVE-2014-10038 EXP SQL injection vulnerability in agenda/indexdate.php in DomPHP 0.83 and earlier allows remote attackers to execute arbitrary SQL commands via the ids p… Patch early 7.5 high 2.3% 2015-01-13
CVE-2014-3962 EXP Multiple SQL injection vulnerabilities in Videos Tube 1.0 allow remote attackers to execute arbitrary SQL commands via the url parameter to (1) videoc… Patch early 7.5 high 2.3% 2014-06-04
CVE-2014-4736 EXP SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the note-id parameter to @actions/co… Patch early 7.5 high 2.3% 2014-07-24
CVE-2014-4960 EXP Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, fo… Patch early 7.5 high 2.3% 2014-07-21
CVE-2014-5097 EXP Multiple SQL injection vulnerabilities in Free Reprintables ArticleFR 3.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via t… Patch early 7.5 high 2.3% 2014-08-22
CVE-2014-7201 EXP Multiple SQL injection vulnerabilities in the search function in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extension 2.14.0… Patch early 7.5 high 2.3% 2014-10-10
← previous page 278 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt