peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,887 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-1813 EXP Multiple SQL injection vulnerabilities in admin/index.php in Submitter Script 2 allow remote attackers to execute arbitrary SQL commands via (1) the u… Patch early 7.5 high 2.3% 2009-05-29
CVE-2009-4099 EXP SQL injection vulnerability in the Google Calendar GCalendar (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlier versions for Joomla! allows… Patch early 7.5 high 2.3% 2009-11-29
CVE-2009-1278 EXP Static code injection vulnerability in forms/ajax/configure.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to inject arbitrary PHP code… Patch early 7.5 high 2.3% 2009-04-09
CVE-2010-0122 EXP Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the (1) userna… Patch early 7.5 high 2.3% 2010-03-15
CVE-2006-7102 EXP Multiple PHP remote file inclusion vulnerabilities in phpBurningPortal quiz-modul 1.0.1, and possibly earlier, allow remote attackers to execute arbit… Patch early 7.5 high 2.3% 2007-03-03
CVE-2006-7106 EXP PHP remote file inclusion vulnerability in config.inc.php3 in Power Phlogger 2.0.9 and earlier allows remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 2.3% 2007-03-03
CVE-2007-2899 EXP Direct static code injection vulnerability in admin_config.php in NavBoard 2.6.0 allows remote attackers to inject arbitrary PHP code into data/config… Patch early 7.5 high 2.3% 2007-05-30
CVE-2007-3586 EXP Multiple direct static code injection vulnerabilities in MyCMS 0.9.8 and earlier allow remote attackers to inject arbitrary PHP code into (1) a _score… Patch early 7.5 high 2.3% 2007-07-05
CVE-2010-1479 EXP SQL injection vulnerability in the RokModule (com_rokmodule) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via t… Patch early 7.5 high 2.3% 2010-04-19
CVE-2018-6563 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack th… Patch early 8.8 high 2.3% 2018-06-20
CVE-2006-2034 EXP SQL injection vulnerability in function/showprofile.php in FlexBB 0.5.5 allows remote attackers to execute arbitrary SQL commands, and view all userna… Patch early 7.5 high 2.3% 2006-04-26
CVE-2002-2249 EXP PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands via the neurl parameter to (1)… Patch early 7.5 high 2.3% 2002-12-31
CVE-2005-3332 EXP PHP remote file include vulnerability in admin/define.inc.php in Belchior Foundry vCard 2.9 allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 2.3% 2005-10-27
CVE-2006-1099 EXP PHP remote file include vulnerability in logIT 1.3 and 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter. NOTE:… Patch early 7.5 high 2.3% 2006-03-09
CVE-2007-2168 EXP Static code injection vulnerability in process.php in AimStats 3.2 and earlier allows remote attackers to inject PHP code into config.php via the data… Patch early 7.5 high 2.3% 2007-04-22
CVE-2018-6023 EXP Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi activating, etc. Patch early 8.8 high 2.3% 2018-05-11
CVE-2007-6664 EXP SQL injection vulnerability in index.php in WebPortal CMS 0.6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the m parame… Patch early 7.5 high 2.3% 2008-01-04
CVE-2008-2074 EXP Multiple PHP remote file inclusion vulnerabilities Harris Yusuf Arifin Harris Wap Chat 1.0, when register_globals is enabled, allow remote attackers t… Patch early 7.5 high 2.3% 2008-05-05
CVE-2008-2883 EXP PHP remote file inclusion vulnerability in include/plugins/jrBrowser/payment.php in Jamroom 3.3.0 through 3.3.5 allows remote attackers to execute arb… Patch early 7.5 high 2.3% 2008-06-26
CVE-2006-4916 EXP SQL injection vulnerability in uye_profil.asp in Tekman Portal (TR) 1.0 allows remote attackers to execute arbitrary SQL commands via the uye_id param… Patch early 7.5 high 2.3% 2006-09-21
CVE-2008-6287 EXP Multiple PHP remote file inclusion vulnerabilities in Broadcast Machine 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the base… Patch early 7.5 high 2.3% 2009-02-25
CVE-2008-6377 EXP PHP remote file inclusion vulnerability in include/global.php in Multi SEO phpBB 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 2.3% 2009-03-02
CVE-2008-7042 EXP PHP remote file inclusion vulnerability in url.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to execute arbitrary PH… Patch early 7.5 high 2.3% 2009-08-24
CVE-2010-0367 EXP Multiple PHP remote file inclusion vulnerabilities in BitScripts Bits Video Script 2.05 Gold Beta, and possibly 2.04, allow remote attackers to execut… Patch early 7.5 high 2.3% 2010-01-21
CVE-2008-2690 EXP Multiple PHP remote file inclusion vulnerabilities in BrowserCRM 5.002.00, when register_globals is enabled, allow remote attackers to execute arbitra… Patch early 9.3 high 2.3% 2008-06-13
CVE-2005-4049 EXP Multiple SQL injection vulnerabilities in Blog System 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the cat parameter in index.… Patch early 7.5 high 2.3% 2005-12-07
CVE-2008-7087 EXP PHP remote file inclusion vulnerability in search_wA.php in OpenPro 1.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the LIBPA… Patch early 7.5 high 2.3% 2009-08-26
CVE-2009-4693 EXP Multiple PHP remote file inclusion vulnerabilities in GraFX MiniCWB 2.3.0 allow remote attackers to execute arbitrary PHP code via a URL in the LANG p… Patch early 7.5 high 2.3% 2010-03-10
CVE-2009-4431 EXP PHP remote file inclusion vulnerability in cal_popup.php in the Anything Digital Development JCal Pro (aka com_jcalpro or JCP) component 1.5.3.6 for J… Patch early 7.5 high 2.3% 2009-12-28
CVE-2009-4789 EXP Multiple PHP remote file inclusion vulnerabilities in the MojoBlog component RC 0.15 for Joomla! allow remote attackers to execute arbitrary PHP code… Patch early 7.5 high 2.3% 2010-04-21
← previous page 282 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt