peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,932 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-0358 EXP Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe… Patch early 7.8 high 2.2% 2018-04-13
CVE-2025-47165 EXP Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Patch early 7.8 high 2.2% 2025-06-10
CVE-2008-1904 EXP Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session, which allows remote attacker… Patch early 7.5 high 2.2% 2008-04-22
CVE-2006-0870 EXP SQL injection vulnerability in pages.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the i… Patch early 7.5 high 2.2% 2006-02-23
CVE-2007-1566 EXP SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote attackers to execute arbitrary SQL commands via the NewsID parameter. NO… Patch early 7.5 high 2.2% 2007-03-21
CVE-2007-1838 EXP SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 2.2% 2007-04-03
CVE-2005-4169 EXP Multiple SQL injection vulnerabilities in eFiction 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) let parameter in a viewlis… Patch early 7.5 high 2.2% 2005-12-11
CVE-2014-3934 EXP SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL commands via the topics[] para… Patch early 7.5 high 2.2% 2014-06-02
CVE-2006-0491 EXP SQL injection vulnerability in SZUserMgnt.class.php in SZUserMgnt 1.4 allows remote attackers to execute arbitrary SQL commands via the username param… Patch early 7.5 high 2.2% 2006-02-01
CVE-2007-1705 EXP SQL injection vulnerability in default.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands via the catid parameter. Patch early 7.5 high 2.2% 2007-03-27
CVE-2007-1846 EXP SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands vi… Patch early 7.5 high 2.2% 2007-04-03
CVE-2007-1979 EXP SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 2.2% 2007-04-12
CVE-2008-7178 EXP Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename… Patch early 7.5 high 2.2% 2009-09-08
CVE-2006-4085 EXP PHP remote file inclusion vulnerability in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allows remote attackers to execute arbitra… Patch early 7.5 high 2.2% 2006-08-11
CVE-2006-4217 EXP PHP remote file inclusion vulnerability in modules/usersonline/users.php in WEBInsta CMS 0.3.1 allows remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 2.2% 2006-08-17
CVE-2005-3423 EXP Multiple SQL injection vulnerabilities in Subdreamer 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the loginusername paramete… Patch early 7.5 high 2.2% 2005-11-01
CVE-2015-8255 EXP AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi. Patch early 8.8 high 2.2% 2017-04-10
CVE-2006-5089 EXP PHP remote file inclusion vulnerability in mybic_server.php in Jim Plush My-BIC 0.6.5 allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 2.2% 2006-09-29
CVE-2006-5739 EXP PHP remote file inclusion vulnerability in cpadmin/cpa_index.php in Leicestershire communityPortals 1.0_2005-10-18_12-31-18 allows remote attackers to… Patch early 7.5 high 2.2% 2006-11-06
CVE-2006-6763 EXP Multiple PHP remote file inclusion vulnerabilities in the Keep It Simple Guest Book (KISGB) allow remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 2.2% 2006-12-27
CVE-2005-3305 EXP Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL commands via the (1) forum_id or (2) thread_i… Patch early 7.5 high 2.2% 2005-10-26
CVE-2007-4046 EXP SQL injection vulnerability in index.php in the Pony Gallery (com_ponygallery) 1.5 and earlier component for Joomla! allows remote attackers to execut… Patch early 7.5 high 2.2% 2007-07-27
CVE-2010-1498 EXP Multiple SQL injection vulnerabilities in dl_stats before 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) dow… Patch early 7.5 high 2.2% 2010-04-23
CVE-2006-5707 EXP SQL injection vulnerability in index.php in PHPEasyData Pro 1.4.1 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the cat para… Patch early 7.5 high 2.2% 2006-11-04
CVE-2007-2889 EXP SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the sc… Patch early 7.5 high 2.2% 2007-05-30
CVE-2005-1287 EXP Multiple SQL injection vulnerabilities in BK Forum 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to member.asp… Patch early 7.5 high 2.2% 2005-04-23
CVE-2005-4140 EXP SQL injection vulnerability in admin/login/index.php in Website Baker 2.6.0 allows remote attackers to execute arbitrary SQL commands via the username… Patch early 7.5 high 2.2% 2005-12-09
CVE-2012-4281 EXP Multiple SQL injection vulnerabilities in Travelon Express 6.2.2 allow remote attackers to execute arbitrary SQL commands via the hid parameter to (1)… Patch early 7.5 high 2.2% 2012-08-13
CVE-2005-1612 EXP SQL injection vulnerability in read.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to execute arbitrary SQL commands via the TID pa… Patch early 7.5 high 2.2% 2005-05-16
CVE-2006-5251 EXP PHP remote file inclusion vulnerability in index.php in Deep CMS 2.0a allows remote attackers to execute arbitrary PHP code via a URL in the ConfigDir… Patch early 7.5 high 2.2% 2006-10-12
← previous page 290 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt