peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,069 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-5141 EXP PHP remote file inclusion vulnerability in script.php in Kevin A. Gordon Open Geo Targeting (aka geotarget) allows remote attackers to execute arbitra… Patch early 7.5 high 2.1% 2006-10-03
CVE-2006-5436 EXP PHP remote file inclusion vulnerability in index.php in FreeFAQ 1.0.e allows remote attackers to execute arbitrary PHP code via a URL in the faqpath p… Patch early 7.5 high 2.1% 2006-10-20
CVE-2006-5899 EXP PHP remote file inclusion vulnerability in install.php3 in @cid stats 2.3 allows remote attackers to execute arbitrary PHP code via a URL in the reper… Patch early 7.5 high 2.1% 2006-11-15
CVE-2006-6140 EXP PHP remote file inclusion vulnerability in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to execute arbitrary PHP code via a URL in the slnt… Patch early 7.5 high 2.1% 2006-11-28
CVE-2007-4605 EXP PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute arbitrary P… Patch early 7.5 high 2.1% 2007-08-31
CVE-2007-4606 EXP PHP remote file inclusion vulnerability in convert/mvcw_conver.php in the Virtual War (VWar) module for PHPNuke-Clan (PNC) 4.2.0 and earlier allows re… Patch early 7.5 high 2.1% 2007-08-31
CVE-2018-5976 EXP Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modifying the admin password. Patch early 8.8 high 2.1% 2018-01-24
CVE-2007-5644 EXP Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortroles.php, which allows remote at… Patch early 7.5 high 2.1% 2007-10-23
CVE-2007-3814 EXP Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the idurlo field in the dele… Patch early 7.5 high 2.1% 2007-07-17
CVE-2006-2541 EXP SQL injection vulnerability in settings.asp in Zixforum 1.12 allows remote attackers to execute arbitrary SQL commands via the layid parameter to (1)… Patch early 7.5 high 2.1% 2006-05-23
CVE-2015-1576 EXP Multiple SQL injection vulnerabilities in u5CMS before 3.9.4 allow remote attackers to execute arbitrary SQL commands via the name parameter to (1) co… Patch early 7.5 high 2.1% 2015-02-11
CVE-2006-3832 EXP SQL injection vulnerability in index.php in Gerrit van Aaken Loudblog 0.5 and earlier allows remote attackers to execute arbitrary SQL commands via th… Patch early 7.5 high 2.1% 2006-07-25
CVE-2015-0919 EXP Multiple SQL injection vulnerabilities in the administrative backend in Sefrengo before 1.6.1 allow remote administrators to execute arbitrary SQL com… Patch early 7.5 high 2.1% 2015-01-08
CVE-2002-1614 EXP Buffer overflow in HP Tru64 UNIX allows local users to execute arbitrary code via a long argument to /usr/bin/at. Patch early 7.2 high 2.1% 2002-09-09
CVE-2007-1171 EXP SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 allows remote attackers to execu… Patch early 7.5 high 2.1% 2007-03-02
CVE-2006-1667 EXP SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows… Patch early 7.5 high 2.1% 2006-04-07
CVE-2007-4062 EXP The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via un… Patch early 7.8 high 2.1% 2007-07-30
CVE-2008-3481 EXP themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct requ… Patch early 7.5 high 2.1% 2008-08-05
CVE-2007-3354 EXP Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition allow remote attackers to execute arbitrary SQL commands via the s_user_id pa… Patch early 7.5 high 2.1% 2007-06-22
CVE-2018-8811 EXP Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allows remote attackers to hijack t… Patch early 8.8 high 2.1% 2018-03-20
CVE-2018-6224 EXP A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to submit aut… Patch early 8.8 high 2.1% 2018-03-15
CVE-2007-2065 EXP PHP remote file inclusion vulnerability in db/PollDB.php in Robert Ladstaetter ActionPoll 1.1.1 allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 2.1% 2007-04-18
CVE-2010-1106 EXP PHP remote file inclusion vulnerability in cgi/index.php in AdvertisementManager 3.1.0 allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 2.1% 2010-03-25
CVE-2009-4104 EXP SQL injection vulnerability in Lyften Designs LyftenBloggie (com_lyftenbloggie) component 1.0.4 for Joomla! allows remote attackers to execute arbitra… Patch early 7.5 high 2.1% 2009-11-29
CVE-2014-5082 EXP Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackers to execut… Patch early 7.5 high 2.1% 2014-08-06
CVE-2014-9237 EXP SQL injection vulnerability in Proticaret E-Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via a tem:Code element in a SOAP re… Patch early 7.5 high 2.1% 2014-12-03
CVE-2006-3364 EXP SQL injection vulnerability in index.php in the NP_SEO plugin in BLOG:CMS before 4.1.0 allows remote attackers to execute arbitrary SQL commands via t… Patch early 7.5 high 2.1% 2006-07-06
CVE-2008-7091 EXP Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to v… Patch early 7.5 high 2.1% 2009-08-26
CVE-2009-0456 EXP PHP remote file inclusion vulnerability in examples/example_clientside_javascript.php in patForms, as used in Sourdough 0.3.5, allows remote attackers… Patch early 7.5 high 2.1% 2009-02-10
CVE-2009-0495 EXP PHP remote file inclusion vulnerability in include/define.php in REALTOR 747 4.11 allows remote attackers to execute arbitrary PHP code via a URL in t… Patch early 7.5 high 2.1% 2009-02-10
← previous page 292 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt