peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,887 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-4821 EXP Multiple SQL injection vulnerabilities in Land Down Under (LDU) v801 and earlier allow remote attackers to execute arbitrary SQL commands via paramete… Patch early 7.5 high 2.3% 2005-12-31
CVE-2007-1961 EXP PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote attackers to execute arbitrary… Patch early 7.5 high 2.3% 2007-04-11
CVE-2007-2302 EXP PHP remote file inclusion vulnerability in autoindex.php in Expow 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_file… Patch early 7.5 high 2.3% 2007-04-26
CVE-2008-0737 EXP SQL injection vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and other 4.x and 3.x versions, allows remote attackers to… Patch early 7.5 high 2.3% 2008-02-13
CVE-2008-3374 EXP SQL injection vulnerability in ajax.php in Gregarius 0.5.4 and earlier allows remote attackers to execute arbitrary SQL commands via the rsargs array… Patch early 7.5 high 2.3% 2008-07-30
CVE-2010-4918 EXP PHP remote file inclusion vulnerability in iJoomla Magazine (com_magazine) component 3.0.1 for Joomla! allows remote attackers to execute arbitrary PH… Patch early 7.5 high 2.3% 2011-10-08
CVE-2010-2148 EXP SQL injection vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pagi… Patch early 7.5 high 2.3% 2010-06-03
CVE-2008-5945 EXP Nukeviet 2.0 Beta allows remote attackers to bypass authentication and gain administrative access by setting the admf cookie to 1. NOTE: the provenan… Patch early 7.5 high 2.3% 2009-01-22
CVE-2009-4796 EXP Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in glFusion 1.1.2 and earlier al… Patch early 7.5 high 2.3% 2010-04-22
CVE-2006-7024 EXP Multiple PHP remote file inclusion vulnerabilities in Harpia CMS 1.0.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in t… Patch early 7.5 high 2.3% 2007-02-15
CVE-2007-5062 EXP account.php in Adam Scheinberg Flip 3.0 and earlier allows remote attackers to create administrative accounts via the un parameter in a register actio… Patch early 7.5 high 2.3% 2007-09-24
CVE-2008-0245 EXP admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain… Patch early 7.5 high 2.3% 2008-01-12
CVE-2008-4735 EXP PHP remote file inclusion vulnerability in header.php in Concord Asset, Software, and Ticket system (CoAST) 0.95 allows remote attackers to execute ar… Patch early 8.5 high 2.3% 2008-10-24
CVE-2007-4820 EXP Absolute path traversal vulnerability in blanko.preview.php in Sisfo Kampus 2006 allows remote attackers to read arbitrary local files, and possibly e… Patch early 7.5 high 2.3% 2007-09-11
CVE-2007-5489 EXP Directory traversal vulnerability in index.php in Artmedic CMS 3.4 and earlier allows remote attackers to include and execute arbitrary local files vi… Patch early 7.5 high 2.3% 2007-10-17
CVE-2008-2284 EXP PHP remote file inclusion vulnerability in fusebox5.php in Fusebox 5.5.1 allows remote attackers to execute arbitrary PHP code via a URL in the FUSEBO… Patch early 7.5 high 2.3% 2008-05-18
CVE-2008-6545 EXP PHP remote file inclusion vulnerability in news/include/createdb.php in Web Server Creator Web Portal 0.1 allows remote attackers to execute arbitrary… Patch early 7.5 high 2.3% 2009-03-30
CVE-2009-0399 EXP Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.php. NOTE: this is only a vuln… Patch early 7.5 high 2.3% 2009-02-03
CVE-2009-0448 EXP Directory traversal vulnerability in admin/modules/aa/preview.php in Syntax Desktop 2.7 allows remote attackers to include and execute arbitrary local… Patch early 7.5 high 2.3% 2009-02-10
CVE-2009-1748 EXP Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrary files via a .. (dot dot) in… Patch early 7.5 high 2.3% 2009-05-22
CVE-2009-1770 EXP Directory traversal vulnerability in includes/database/examples/addressbook.php in Flyspeck CMS 6.8 allows remote attackers to include and execute arb… Patch early 7.5 high 2.3% 2009-05-22
CVE-2009-1486 EXP Directory traversal vulnerability in pmscript.php in Flatchat 3.0 allows remote attackers to include and execute arbitrary local files via a .. (dot d… Patch early 7.5 high 2.3% 2009-04-29
CVE-2009-2792 EXP Directory traversal vulnerability in plugings/pagecontent.php in Really Simple CMS (RSCMS) 0.3a allows remote attackers to include and execute arbitra… Patch early 7.5 high 2.3% 2009-08-17
CVE-2009-3596 EXP JoxTechnology Ajox Poll does not properly restrict access to admin/managepoll.php, which allows remote attackers to bypass authentication and gain adm… Patch early 7.5 high 2.3% 2009-10-08
CVE-2009-3825 EXP Multiple directory traversal vulnerabilities in GenCMS 2006 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in… Patch early 7.5 high 2.3% 2009-10-28
CVE-2008-4334 EXP PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the infouser cookie to 1. Patch early 7.5 high 2.3% 2008-09-30
CVE-2012-5685 EXP SQL injection vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the inEmailAddress parameter in… Patch early 7.5 high 2.3% 2014-08-14
CVE-2014-9215 EXP SQL injection vulnerability in the CheckEmail function in includes/functions.class.php in PBBoard 3.0.1 before 20141128 allows remote attackers to exe… Patch early 7.5 high 2.3% 2014-12-05
CVE-2007-2575 EXP PHP remote file inclusion vulnerability in watermark.php in the vm (aka Jean-Francois Laflamme) watermark 0.4.1 mod for Gallery allows remote attacker… Patch early 7.5 high 2.3% 2007-05-09
CVE-2005-0368 EXP Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) EntryID or (2) searchterm param… Patch early 7.5 high 2.3% 2005-05-02
← previous page 280 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt