peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,069 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-0513 EXP Multiple PHP remote file inclusion vulnerabilities in WebFrame 0.76 allow remote attackers to execute arbitrary PHP code via a URL in the classFiles p… Patch early 7.5 high 2.1% 2009-02-11
CVE-2009-1822 EXP Multiple PHP remote file inclusion vulnerabilities in the InterJoomla ArtForms (com_artforms) component 2.1b7 for Joomla! allow remote attackers to ex… Patch early 7.5 high 2.1% 2009-05-29
CVE-2009-2378 EXP PHP remote file inclusion vulnerability in formmailer.admin.inc.php in Jax FormMailer 3.0.0 allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 2.1% 2009-07-08
CVE-2009-2791 EXP PHP remote file inclusion vulnerability in pda_projects.php in WebDynamite ProjectButler 1.5.0 allows remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 2.1% 2009-08-17
CVE-2009-3323 EXP Multiple PHP remote file inclusion vulnerabilities in BAnner ROtation System mini (BAROSmini) 0.32.595 allow remote attackers to execute arbitrary PHP… Patch early 7.5 high 2.1% 2009-09-23
CVE-2009-3331 EXP Multiple PHP remote file inclusion vulnerabilities in DDL CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the wwwRoot parame… Patch early 7.5 high 2.1% 2009-09-23
CVE-2009-3492 EXP Multiple PHP remote file inclusion vulnerabilities in Loggix Project 9.4.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 2.1% 2009-09-30
CVE-2009-3541 EXP PHP remote file inclusion vulnerability in CoupleDB.php in PHPGenealogy 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the Dat… Patch early 7.5 high 2.1% 2009-10-02
CVE-2009-4156 EXP PHP remote file inclusion vulnerability in modules/pms/index.php in Ciamos CMS 0.9.5 and earlier allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 2.1% 2009-12-02
CVE-2009-4614 EXP Multiple PHP remote file inclusion vulnerabilities in Moa Gallery 1.2.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 2.1% 2010-01-18
CVE-2009-4622 EXP PHP remote file inclusion vulnerability in admin/admin_news_bot.php in Drunken:Golem Gaming Portal 0.5.1 alpha 2 allows remote attackers to execute ar… Patch early 7.5 high 2.1% 2010-01-18
CVE-2008-2128 EXP PHP remote file inclusion vulnerability in templates/header.php in CMS Faethon 2.2 Ultimate allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 2.1% 2008-05-09
CVE-2008-2649 EXP Multiple PHP remote file inclusion vulnerabilities in DesktopOnNet 3 Beta allow remote attackers to execute arbitrary PHP code via a URL in the app_pa… Patch early 7.5 high 2.1% 2008-06-10
CVE-2015-6962 EXP SQL injection vulnerability in the web application in Farol allows remote attackers to execute arbitrary SQL commands via the email parameter to tkmon… Patch early 7.5 high 2.1% 2015-09-17
CVE-2023-25438 EXP An issue was discovered in Genomedics MilleGP5 5.9.2, allows remote attackers to execute arbitrary code and gain escalated privileges via modifying sp… Patch early 7.8 high 2.1% 2023-05-04
CVE-2010-5059 EXP SQL injection vulnerability in index.php in CMScout 2.0.8 allows remote attackers to execute arbitrary SQL commands via the album parameter in a photo… Patch early 7.5 high 2.1% 2011-11-23
CVE-2010-5060 EXP SQL injection vulnerability in Nus.php in NUs Newssystem 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter. Patch early 7.5 high 2.1% 2011-11-23
CVE-2010-5053 EXP SQL injection vulnerability in the XOBBIX (com_xobbix) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the p… Patch early 7.5 high 2.1% 2011-11-23
CVE-2005-1629 EXP SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL commands via the verifykey parameter. Patch early 7.5 high 2.1% 2005-05-17
CVE-2014-6045 EXP SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via… Patch early 7.2 high 2.1% 2018-08-28
CVE-2009-2633 EXP PHP remote file inclusion vulnerability in toolbar_ext.php in the VehicleManager (com_vehiclemanager) component 1.0 Basic for Joomla! allows remote at… Patch early 7.5 high 2.1% 2009-07-28
CVE-2009-2634 EXP PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic for Joomla! allows remote att… Patch early 7.5 high 2.1% 2009-07-28
CVE-2009-2635 EXP PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.0 Basic for Joomla! allows rem… Patch early 7.5 high 2.1% 2009-07-28
CVE-2009-3056 EXP PHP remote file inclusion vulnerability in include/engine/content/elements/menu.php in KingCMS 0.6.0 allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 2.1% 2009-09-03
CVE-2009-3174 EXP PHP remote file inclusion vulnerability in fonctions_racine.php in OBOphiX 2.7.0 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 2.1% 2009-09-11
CVE-2009-3324 EXP PHP remote file inclusion vulnerability in include/prodler.class.php in ProdLer 2.0 and earlier allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 2.1% 2009-09-23
CVE-2009-3365 EXP PHP remote file inclusion vulnerability in add-ons/modules/sysmanager/plugins/install.plugin.php in Aurora CMS 1.0.2 allows remote attackers to execut… Patch early 7.5 high 2.1% 2009-09-24
CVE-2009-4666 EXP Multiple PHP remote file inclusion vulnerabilities in Webradev Download Protect 1.0 allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 2.1% 2010-03-05
CVE-1999-1432 EXP Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows… Patch early 7.5 high 2.1% 1998-07-16
CVE-2005-0413 EXP Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) t… Patch early 7.5 high 2.1% 2005-04-27
← previous page 293 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt