peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,932 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-3962 EXP PHP remote file inclusion vulnerability in administrator/components/com_bayesiannaivefilter/lang.php in the bayesiannaivefilter component (com_bayesia… Patch early 7.5 high 2.2% 2006-08-01
CVE-2017-16570 EXP KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_0… Patch early 8.8 high 2.2% 2017-11-06
CVE-2003-1086 EXP PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary… Patch early 7.5 high 2.2% 2003-06-17
CVE-2008-0233 EXP Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and… Patch early 7.5 high 2.2% 2008-01-11
CVE-2008-1971 EXP phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) p… Patch early 7.5 high 2.2% 2008-04-27
CVE-2013-5318 EXP SQL injection vulnerability in Ginkgo CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the rang parameter to index.php. Patch early 7.5 high 2.2% 2013-08-20
CVE-2019-18194 EXP TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junction to restore a malicious DLL f… Patch early 7.8 high 2.2% 2020-01-10
CVE-2012-2338 EXP SQL injection vulnerability in includes/picture.class.php in Galette 0.63, 0.63.1, 0.63.2, 0.63.3, and 0.64rc1 allows remote attackers to execute arbi… Patch early 7.5 high 2.2% 2012-05-21
CVE-2007-2773 EXP SQL injection vulnerability in plugins/mp3playlist/mp3playlist.php in Zomplog 3.8 and earlier allows remote attackers to execute arbitrary SQL command… Patch early 7.5 high 2.2% 2007-05-21
CVE-2007-1481 EXP SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_id parameter in a viewentry cmd… Patch early 7.5 high 2.2% 2007-03-16
CVE-2007-1703 EXP SQL injection vulnerability in index.php in the RWCards (com_rwcards) 2.4.3 and earlier component for Joomla! allows remote attackers to execute arbit… Patch early 7.5 high 2.2% 2007-03-27
CVE-2007-1817 EXP SQL injection vulnerability in index.php in the Lykos Reviews (lykos_reviews) 1.00 module for Xoops allows remote attackers to execute arbitrary SQL c… Patch early 7.5 high 2.2% 2007-04-02
CVE-2008-6718 EXP U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to h… Patch early 7.5 high 2.2% 2009-04-13
CVE-2007-1806 EXP SQL injection vulnerability in categos.php in the RM+Soft Gallery (rmgallery) 1.0 module for Xoops allows remote attackers to execute arbitrary SQL co… Patch early 7.5 high 2.2% 2007-04-02
CVE-2007-2183 EXP SQL injection vulnerability in index.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9 allows remote attackers to execute arbitrary SQL comma… Patch early 7.5 high 2.2% 2007-04-24
CVE-2007-4502 EXP SQL injection vulnerability in index.php in the BibTeX component (com_jombib) 1.3 and earlier for Joomla! allows remote attackers to execute arbitrary… Patch early 7.5 high 2.2% 2007-08-23
CVE-2007-4509 EXP SQL injection vulnerability in index.php in the EventList component (com_eventlist) 0.8 and earlier for Joomla! allows remote attackers to execute arb… Patch early 7.5 high 2.2% 2007-08-23
CVE-2012-1672 EXP SQL injection vulnerability in getcity.php in Hotel Booking Portal 0.1 allows remote attackers to execute arbitrary SQL commands via the country param… Patch early 7.5 high 2.2% 2012-04-11
CVE-2012-1673 EXP SQL injection vulnerability in loginscript.php in e-ticketing allows remote attackers to execute arbitrary SQL commands via the password parameter. Patch early 7.5 high 2.2% 2012-04-11
CVE-2009-3949 EXP cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewauthor action, which allows remo… Patch early 7.5 high 2.2% 2009-11-16
CVE-2026-26235 EXP JUNG Smart Visu Server 1.1.1050 contains a denial of service vulnerability that allows unauthenticated attackers to remotely shutdown or reboot the se… Patch early 7.5 high 2.2% 2026-02-12
CVE-2003-0590 EXP Cross-site scripting (XSS) vulnerability in Splatt Forum allows remote attackers to insert arbitrary HTML and web script via the post icon (image_subj… Patch early 7.1 high 2.2% 2003-08-18
CVE-2006-0167 EXP SQL injection vulnerability in MyPhPim 01.05 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter in calendar.php3 a… Patch early 7.5 high 2.2% 2006-01-11
CVE-2007-1107 EXP SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users to execute arbitrary SQL comma… Patch early 7.5 high 2.2% 2007-02-26
CVE-2009-3065 EXP PHP remote file inclusion vulnerability in editor/edit_htmlarea.php in Ve-EDIT 0.1.4 allows remote attackers to execute arbitrary PHP code via a URL i… Patch early 7.5 high 2.2% 2009-09-03
CVE-2015-7714 EXP Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitra… Patch early 7.2 high 2.2% 2017-10-18
CVE-2008-6002 EXP Absolute path traversal vulnerability in sendfile.php in web-cp 0.5.7, when register_globals is enabled, allows remote attackers to read arbitrary fil… Patch early 7.1 high 2.2% 2009-01-28
CVE-2006-5961 EXP Buffer overflow in Mercury Mail Transport System 4.01b for Windows has unknown impact and attack vectors, as originally reported in a GLEG VulnDisco p… Patch early 7.5 high 2.2% 2006-11-17
CVE-2007-0498 EXP PHP remote file inclusion vulnerability in up.php in MySpeach 2.1 beta and possibly earlier allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 2.2% 2007-01-25
CVE-2005-4380 EXP Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode… Patch early 7.5 high 2.2% 2005-12-20
← previous page 289 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt