peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,905 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-0742 EXP Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include arbitrary files via a .. (dot… Patch early 7.5 high 2.3% 2008-02-13
CVE-2008-1645 EXP Directory traversal vulnerability in body.php in phpSpamManager (phpSM) 0.53 beta allows remote attackers to read arbitrary local files via a .. (dot… Patch early 7.5 high 2.3% 2008-04-02
CVE-2008-1798 EXP Directory traversal vulnerability in forum/kietu/libs/calendrier.php in Dragoon 0.1 allows remote attackers to include and execute arbitrary local fil… Patch early 7.5 high 2.3% 2008-04-15
CVE-2008-2091 EXP Directory traversal vulnerability in ipn.php in KubeLabs Kubelance 1.6.4 allows remote attackers to include and execute arbitrary local files via the… Patch early 7.5 high 2.3% 2008-05-06
CVE-2008-2695 EXP Directory traversal vulnerability in entry.php in phpInv 0.8.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot)… Patch early 7.5 high 2.3% 2008-06-13
CVE-2008-2699 EXP Multiple directory traversal vulnerabilities in Galatolo WebManager (GWM) 1.0 allow remote attackers to include and execute arbitrary local files via… Patch early 7.5 high 2.3% 2008-06-13
CVE-2008-2818 EXP Directory traversal vulnerability in Easy-Clanpage 3.0 b1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in t… Patch early 7.5 high 2.3% 2008-06-23
CVE-2008-2896 EXP Directory traversal vulnerability in index.php in FireAnt 1.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot)… Patch early 7.5 high 2.3% 2008-06-27
CVE-2008-4330 EXP Directory traversal vulnerability in index.php in LanSuite 3.3.2 allows remote attackers to include and execute arbitrary local files via a .. (dot do… Patch early 7.5 high 2.3% 2008-09-30
CVE-2008-4331 EXP Directory traversal vulnerability in library/pagefunctions.inc.php in phpOCS 0.1 beta3 and earlier allows remote attackers to include and execute arbi… Patch early 7.5 high 2.3% 2008-09-30
CVE-2008-4351 EXP Directory traversal vulnerability in index.php in phpSmartCom 0.2 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in… Patch early 7.5 high 2.3% 2008-09-30
CVE-2007-1438 EXP SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. Patch early 7.5 high 2.3% 2007-03-13
CVE-2010-1537 EXP Multiple directory traversal vulnerabilities in phpCDB 1.0 and earlier allow remote attackers to include and execute arbitrary local files via a .. (d… Patch early 7.5 high 2.3% 2010-04-26
CVE-2008-6167 EXP Directory traversal vulnerability in search.php in miniPortail 2.2 and earlier allows remote attackers to include and execute arbitrary local files vi… Patch early 7.5 high 2.3% 2009-02-19
CVE-2008-6407 EXP Directory traversal vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to include and execute arbitrary local files via… Patch early 7.5 high 2.3% 2009-03-06
CVE-2008-6410 EXP Directory traversal vulnerability in show.php in ol'bookmarks manager 0.7.5 and earlier allows remote attackers to include and execute arbitrary local… Patch early 7.5 high 2.3% 2009-03-06
CVE-2008-5776 EXP Multiple directory traversal vulnerabilities in Aperto Blog 0.1.1 allow remote attackers to include and execute arbitrary local files via directory tr… Patch early 7.5 high 2.3% 2008-12-30
CVE-2008-3250 EXP SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL commands via the filter parame… Patch early 7.5 high 2.3% 2008-07-21
CVE-2025-60751 EXP GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode. Patch early 7.5 high 2.3% 2025-10-21
CVE-1999-0768 EXP Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable. Patch early 7.5 high 2.3% 1999-08-25
CVE-2005-1308 EXP SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script o… Patch early 7.5 high 2.3% 2005-04-15
CVE-2007-4458 EXP PHP remote file inclusion vulnerability in includes/class/class_tpl.php in Firesoft allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 2.3% 2007-08-21
CVE-2008-4911 EXP PHP remote file inclusion vulnerability in read.php in Chattaitaliano Istant-Replay allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 2.3% 2008-11-04
CVE-2008-6491 EXP PHP remote file inclusion vulnerability in connexion.php in PHPGKit 0.9 allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMEN… Patch early 7.5 high 2.3% 2009-03-19
CVE-2009-4094 EXP PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows remote attacke… Patch early 7.5 high 2.3% 2009-11-29
CVE-2003-0394 EXP objects.inc.php4 in BLNews 2.1.3 allows remote attackers to execute arbitrary PHP code via a Server[path] parameter that points to malicious code on a… Patch early 7.5 high 2.3% 2003-07-02
CVE-2010-2681 EXP PHP remote file inclusion vulnerability in the SEF404x (com_sef) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 2.3% 2010-07-12
CVE-2013-6341 EXP SQL injection vulnerability in Dokeos 2.2 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the language parameter to inde… Patch early 7.5 high 2.3% 2013-12-05
CVE-2014-1619 EXP Multiple SQL injection vulnerabilities in Cubic CMS 5.1.1, 5.1.2, and 5.2 allow remote attackers to execute arbitrary SQL commands via the (1) resourc… Patch early 7.5 high 2.3% 2014-01-21
CVE-2019-11569 EXP Veeam ONE Reporter 9.5.0.3201 allows CSRF. Patch early 8.8 high 2.3% 2019-05-06
← previous page 285 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt