peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,891 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-2193 EXP PHP remote file inclusion vulnerability in example.php in Thomas Gossmann ScorpNews 2.0 allows remote attackers to execute arbitrary PHP code via a UR… Patch early 7.5 high 2.3% 2008-05-14
CVE-2008-2270 EXP Multiple PHP remote file inclusion vulnerabilities in PHPWAY Kostenloses Linkmanagementscript allow remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 2.3% 2008-05-16
CVE-2008-2341 EXP PHP remote file inclusion vulnerability in ch_readalso.php in News Manager 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 2.3% 2008-05-19
CVE-2008-2854 EXP Multiple PHP remote file inclusion vulnerabilities in Orlando CMS 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[pr… Patch early 7.5 high 2.3% 2008-06-25
CVE-2008-2986 EXP Multiple PHP remote file inclusion vulnerabilities in phpDMCA 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the ourlinux_roo… Patch early 7.5 high 2.3% 2008-07-02
CVE-2008-2990 EXP PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! allows rem… Patch early 7.5 high 2.3% 2008-07-02
CVE-2008-3022 EXP Multiple PHP remote file inclusion vulnerabilities in sablonlar/gunaysoft/gunaysoft.php in PHPortal 1.2 Beta allow remote attackers to execute arbitra… Patch early 7.5 high 2.3% 2008-07-07
CVE-2008-6006 EXP Multiple PHP remote file inclusion vulnerabilities in Micronation Banking System (minba) 1.5.0 allow remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 2.3% 2009-01-30
CVE-2008-6138 EXP PHP remote file inclusion vulnerability in adminhead.php in WebBiscuits Modules Controller 1.1 and earlier allows remote attackers to execute arbitrar… Patch early 7.5 high 2.3% 2009-02-14
CVE-2008-6402 EXP PHP remote file inclusion vulnerability in hu/modules/reg-new/modstart.php in Sofi WebGui 0.6.3 PRE and earlier allows remote attackers to execute arb… Patch early 7.5 high 2.3% 2009-03-06
CVE-2008-6403 EXP PHP remote file inclusion vulnerability in themes/default/include/html/insert.inc.php in OpenRat 0.8-beta4 and earlier allows remote attackers to exec… Patch early 7.5 high 2.3% 2009-03-06
CVE-2008-6408 EXP PHP remote file inclusion vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 2.3% 2009-03-06
CVE-2008-7067 EXP PHP remote file inclusion vulnerability in admin/plugins/Online_Users/main.php in PageTree CMS 0.0.2 BETA 0001 allows remote attackers to execute arbi… Patch early 7.5 high 2.3% 2009-08-25
CVE-2010-5047 EXP SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL commands via the id parameter. Patch early 7.5 high 2.3% 2011-11-23
CVE-2013-6873 EXP SQL injection vulnerability in Testa Online Test Management System (OTMS) 2.0.0.2 allows remote attackers to execute arbitrary SQL commands via the te… Patch early 7.5 high 2.3% 2013-11-26
CVE-2009-2637 EXP PHP remote file inclusion vulnerability in toolbar_ext.php in the BookLibrary (com_booklibrary) component 1.5.2.4 Basic for Joomla! allows remote atta… Patch early 7.5 high 2.3% 2009-07-28
CVE-2004-2551 EXP Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the sys_comment_id par… Patch early 7.5 high 2.3% 2004-12-31
CVE-2007-0569 EXP SQL injection vulnerability in xNews.php in xNews 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a shownews act… Patch early 7.5 high 2.3% 2007-01-30
CVE-2009-3759 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers… Patch early 8.8 high 2.3% 2009-10-22
CVE-2013-7219 EXP SQL injection vulnerability in vote.php in the 2Glux Sexy Polling (com_sexypolling) component before 1.0.9 for Joomla! allows remote attackers to exec… Patch early 7.5 high 2.3% 2014-01-21
CVE-2007-2258 EXP PHP remote file inclusion vulnerability in includes/init.inc.php in PHPMyBibli allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 2.3% 2007-04-25
CVE-2008-5966 EXP globsy_edit.php in Globsy 1.0 and earlier allows remote attackers to create or overwrite arbitrary files via a filename in the file parameter and file… Patch early 7.5 high 2.3% 2009-01-26
CVE-2008-6882 EXP Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scannin… Patch early 7.5 high 2.3% 2009-07-30
CVE-2008-7027 EXP Libra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user and pass cookies to 1. Patch early 7.5 high 2.3% 2009-08-21
CVE-2008-7172 EXP Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote attackers to gain administrat… Patch early 7.5 high 2.3% 2009-09-08
CVE-2008-7179 EXP OTManager CMS 2.4 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN_Hora, ADMIN_Logado, and ADMI… Patch early 7.5 high 2.3% 2009-09-08
CVE-2008-7181 EXP Butterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter to category-delete.php with th… Patch early 7.5 high 2.3% 2009-09-08
CVE-2010-0976 EXP Acidcat CMS 3.5.x does not prevent access to install.asp after installation finishes, which might allow remote attackers to restart the installation p… Patch early 7.5 high 2.3% 2010-03-16
CVE-2008-1507 EXP PEEL, possibly 3.x and earlier, has (1) a default info@peel.fr account with password admin, and (2) a default contact@peel.fr account with password ci… Patch early 7.5 high 2.3% 2008-03-25
CVE-2008-0545 EXP Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbitrary local files via a .. (do… Patch early 7.5 high 2.3% 2008-02-01
← previous page 284 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt