peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,922 CVEs 1,739 on KEV 17,301 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-3058 EXP Multiple SQL injection vulnerabilities in Octeth Oempro 3.5.5.1, and possibly other versions before 4, allow remote attackers to execute arbitrary SQL… Patch early 7.5 high 2.3% 2008-12-03
CVE-2006-7167 EXP Unspecified vulnerability in ProRat Server 1.9 Fix2 allows remote attackers to bypass the authentication mechanism for remote login via unspecified ve… Patch early 7.5 high 2.3% 2007-03-20
CVE-2018-15686 EXP A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be… Patch early 7.8 high 2.3% 2018-10-26
CVE-2006-4372 EXP PHP remote file inclusion vulnerability in admin.lurm_constructor.php in the Lurm Constructor component (com_lurm_constructor) 0.6b and earlier for Ma… Patch early 7.5 high 2.3% 2006-08-26
CVE-2006-7172 EXP Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers to execute arbitrary code via… Patch early 7.5 high 2.3% 2007-03-20
CVE-2007-6221 EXP TuMusika Evolution 1.7R5 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo func… Patch early 7.8 high 2.3% 2007-12-04
CVE-2026-43500 EXP In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-… Patch early 7.8 high 2.3% 2026-05-11
CVE-2006-0961 EXP SQL injection vulnerability in yazdir.asp in Cilem Hiber 1.1 allows remote attackers to execute arbitrary SQL commands via the haber_id parameter. NO… Patch early 7.5 high 2.3% 2006-03-02
CVE-2012-2629 EXP Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities in Axous 1.1.1 and earlier allow remote attackers to hijack… Patch early 8.8 high 2.3% 2020-02-20
CVE-2006-4114 EXP SQL injection vulnerability in view_com.php in Nicolas Grandjean PHPMyRing 4.2.0 and earlier allows remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 2.3% 2006-08-14
CVE-2002-2287 EXP PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to execute arbi… Patch early 7.5 high 2.3% 2002-12-31
CVE-2024-12905 EXP An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal").… Patch early 7.5 high 2.3% 2025-03-27
CVE-2019-13961 EXP A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php. Patch early 8.8 high 2.3% 2019-07-18
CVE-2017-1000370 EXP The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed with 1GB of arguments or environm… Patch early 7.8 high 2.3% 2017-06-19
CVE-2010-1467 EXP Multiple PHP remote file inclusion vulnerabilities in openUrgence Vaccin 1.03 allow remote attackers to execute arbitrary PHP code via a URL in the pa… Patch early 7.5 high 2.3% 2010-04-16
CVE-2007-6557 EXP Multiple SQL injection vulnerabilities in MeGaCheatZ 1.1 allow remote attackers to execute arbitrary SQL commands via the ItemID parameter to (1) comm… Patch early 7.5 high 2.3% 2007-12-28
CVE-2008-0391 EXP inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arbitrary user account via a modi… Patch early 7.5 high 2.3% 2008-01-23
CVE-2008-5310 EXP SQL injection vulnerability in image.php in NetArt Media Car Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter… Patch early 7.5 high 2.3% 2008-12-02
CVE-2008-6739 EXP Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain administ… Patch early 7.5 high 2.3% 2009-04-21
CVE-2009-4670 EXP admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via the user para… Patch early 7.5 high 2.3% 2010-03-05
CVE-2009-4801 EXP EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP scripts. Patch early 7.5 high 2.3% 2010-04-23
CVE-2008-1893 EXP PHP remote file inclusion vulnerability in index.php in W2B Online Banking allows remote attackers to execute arbitrary PHP code via a URL in the ilan… Patch early 7.5 high 2.3% 2008-04-18
CVE-2002-2319 EXP Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2)… Patch early 7.5 high 2.3% 2002-12-31
CVE-2005-1237 EXP SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands via the newsid parameter. Patch early 7.5 high 2.2% 2005-05-02
CVE-2008-0745 EXP Directory traversal vulnerability in aides/index.php in DomPHP 0.82 allows remote attackers to include and execute arbitrary local files via a .. (dot… Patch early 7.5 high 2.2% 2008-02-13
CVE-2008-3313 EXP Multiple PHP remote file inclusion vulnerabilities in CreaCMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) cfg[docume… Patch early 7.5 high 2.2% 2008-07-25
CVE-2009-1510 EXP Multiple directory traversal vulnerabilities in KoschtIT Image Gallery 1.82 allow remote attackers to include and execute arbitrary local files via di… Patch early 7.5 high 2.2% 2009-05-01
CVE-2018-13032 EXP ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogin_act URI. Patch early 8.8 high 2.2% 2018-07-01
CVE-2018-19138 EXP WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI. Patch early 8.8 high 2.2% 2018-11-09
CVE-2017-7571 EXP public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges. Patch early 8.0 high 2.2% 2017-04-06
← previous page 287 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt