peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,069 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-4400 EXP SQL injection vulnerability in _rights.php in DynPG CMS 4.2.0 allows remote attackers to execute arbitrary SQL commands via the giveRights_UserId para… Patch early 7.5 high 2.2% 2010-12-06
CVE-2007-5053 EXP Multiple incomplete blacklist vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) t… Patch early 7.5 high 2.2% 2007-09-24
CVE-2016-2494 EXP Off-by-one error in sdcard/sdcard.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows attackers to… Patch early 7.8 high 2.2% 2016-06-13
CVE-2000-0449 EXP Omnis Studio 2.4 uses weak encryption (trivial encoding) for encrypting database fields. Patch early 10.0 high 2.2% 2000-05-01
CVE-2009-4657 EXP The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting t… Patch early 7.5 high 2.2% 2010-03-03
CVE-2017-16939 EXP The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial… Patch early 7.8 high 2.2% 2017-11-24
CVE-2006-0673 EXP Multiple SQL injection vulnerabilities in cms/index.php in Magic Calendar Lite 1.02, with magic_quotes_gpc disabled, allow remote attackers to execute… Patch early 7.5 high 2.2% 2006-02-13
CVE-2009-4779 EXP Multiple PHP remote file inclusion vulnerabilities in NukeHall 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the s… Patch early 7.5 high 2.1% 2010-04-21
CVE-2012-2115 EXP SQL injection vulnerability in interface/login/validateUser.php in OpenEMR 4.1.0 and possibly earlier allows remote attackers to execute arbitrary SQL… Patch early 7.5 high 2.1% 2012-09-09
CVE-2019-2721 EXP Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5… Patch early 8.8 high 2.1% 2019-04-23
CVE-2001-0833 EXP Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka… Patch early 7.2 high 2.1% 2001-12-06
CVE-2006-7091 EXP PHP remote file inclusion vulnerability in config.php in phpht Topsites FREE 1.022b allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 2.1% 2007-03-02
CVE-2006-0637 EXP Buffer overflow in cram.dll in QUALCOMM Eudora WorldMail 3.0 allows remote attackers to execute arbitrary code via an IMAP APPEND command with a long… Patch early 7.5 high 2.1% 2006-02-10
CVE-2014-5104 EXP Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) a_country parameter i… Patch early 7.5 high 2.1% 2014-07-28
CVE-2025-4255 EXP A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component RMD Command Handler. Th… Patch early 7.3 high 2.1% 2025-05-05
CVE-2009-0459 EXP Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote attackers to execute arbitra… Patch early 7.5 high 2.1% 2009-02-10
CVE-1999-0834 EXP Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library. Patch early 10.0 high 2.1% 1999-12-01
CVE-2009-1450 EXP PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP code via a URL in the _page_co… Patch early 7.5 high 2.1% 2009-04-28
CVE-2009-3511 EXP Multiple PHP remote file inclusion vulnerabilities in justVisual 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the fs_jVroot p… Patch early 7.5 high 2.1% 2009-10-01
CVE-2009-4993 EXP PHP remote file inclusion vulnerability in home.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 2.1% 2010-08-25
CVE-2007-3394 EXP Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the (1) artid parameter to mod.ph… Patch early 7.5 high 2.1% 2007-06-26
CVE-2017-6328 EXP The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbreviat… Patch early 8.8 high 2.1% 2017-08-11
CVE-2009-0807 EXP zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php. Patch early 7.5 high 2.1% 2009-03-04
CVE-2007-2145 EXP The imagecomments function in classes.php in MiniGal b13 allows remote attackers to inject arbitrary PHP code into a file in the thumbs/ directory via… Patch early 7.5 high 2.1% 2007-04-19
CVE-2007-4389 EXP Cross-site request forgery (CSRF) vulnerability in /xslt in 2wire 1701HG, 1800HW, and 2071 Gateway routers, with 3.17.5, 3.7.1, and 5.29.51 software,… Patch early 7.8 high 2.1% 2007-08-17
CVE-2005-0931 EXP PHP remote file inclusion vulnerability in The Includer 1.0 and 1.1 allows remote attackers to execute arbitrary PHP code. Patch early 7.5 high 2.1% 2005-03-29
CVE-2007-0686 EXP The Intel 2200BG 802.11 Wireless Mini-PCI driver 9.0.3.9 (w29n51.sys) allows remote attackers to cause a denial of service (system crash) via crafted… Patch early 7.1 high 2.1% 2007-02-03
CVE-2026-67206 EXP Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitra… Patch early 8.8 high 2.1% 2026-07-30
CVE-2006-0462 EXP SQL injection vulnerability in comentarios.php in AndoNET Blog 2004.09.02 allows remote attackers to execute arbitrary SQL commands via the entrada pa… Patch early 7.5 high 2.1% 2006-01-27
CVE-2006-4749 EXP Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpATM) 1.20 allow remote attackers to execute arbitrary PHP code… Patch early 7.5 high 2.1% 2006-09-13
← previous page 291 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt