peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,145 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-6349 EXP Multiple SQL injection vulnerabilities in PWP Technologies The Classified Ad System allow remote attackers to execute arbitrary SQL commands via (1) t… Patch early 7.5 high 2.1% 2006-12-07
CVE-2007-6362 EXP SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and Joomla! allows remote attacke… Patch early 7.5 high 2.1% 2007-12-15
CVE-2006-5228 EXP Multiple SQL injection vulnerabilities in the Google Gadget login.php (gadget/login.php) in Rob Hensley ackerTodo 4.2 and earlier allow remote attacke… Patch early 7.5 high 2.1% 2006-10-10
CVE-2007-0600 EXP SQL injection vulnerability in news_page.asp in Martyn Kilbryde Newsposter Script (aka makit news/blog poster) 3 and earlier allows remote attackers t… Patch early 7.5 high 2.1% 2007-01-30
CVE-2004-1932 EXP SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and cr… Patch early 7.5 high 2.1% 2004-04-12
CVE-2004-1972 EXP SQL injection vulnerability in modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to execute arbitrary SQL code via the (… Patch early 7.5 high 2.1% 2004-04-26
CVE-2005-2028 EXP SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Age… Patch early 7.5 high 2.1% 2005-06-21
CVE-2011-4673 EXP SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands vi… Patch early 7.5 high 2.1% 2011-12-02
CVE-2006-2797 EXP Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) CalendarDeta… Patch early 7.5 high 2.1% 2006-06-03
CVE-2025-49683 EXP Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally. Patch early 7.8 high 2.1% 2025-07-08
CVE-2008-3206 EXP SQL injection vulnerability in browse.groups.php in Yuhhu Pubs Black Cat allows remote attackers to execute arbitrary SQL commands via the category pa… Patch early 7.5 high 2.1% 2008-07-18
CVE-2005-1615 EXP viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 may allow remote attackers to read sensitive data via the postorder parameter, which is no… Patch early 7.5 high 2.1% 2005-05-16
CVE-2023-33148 EXP Microsoft Office Elevation of Privilege Vulnerability Patch early 7.8 high 2.1% 2023-07-11
CVE-2008-6991 EXP SQL injection vulnerability in public/page.php in Websens CMSbright allows remote attackers to execute arbitrary SQL commands via the id_rub_page para… Patch early 7.5 high 2.1% 2009-08-19
CVE-2008-2627 EXP SQL injection vulnerability in the IDoBlog (com_idoblog) component b24 and earlier and 1.0, a component for Joomla!, allows remote attackers to execut… Patch early 7.5 high 2.1% 2008-06-10
CVE-2008-2629 EXP SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitrary SQL commands via the albumI… Patch early 7.5 high 2.1% 2008-06-10
CVE-2008-2678 EXP Multiple SQL injection vulnerabilities in Telephone Directory 2008, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL… Patch early 7.5 high 2.1% 2008-06-12
CVE-2008-6315 EXP PHP remote file inclusion vulnerability in _conf/core/common-tpl-vars.php in PHPmyGallery 1.0 beta2 allows remote attackers to execute arbitrary PHP c… Patch early 7.5 high 2.1% 2009-02-27
CVE-2008-6318 EXP PHP remote file inclusion vulnerability in _conf/_php-core/common-tpl-vars.php in PHPmyGallery 1.5 beta allows remote attackers to execute arbitrary P… Patch early 7.5 high 2.1% 2009-02-27
CVE-2009-0963 EXP Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the Search… Patch early 7.5 high 2.1% 2009-03-19
CVE-2005-4170 EXP SQL injection vulnerability in eFiction 1.1 allows remote attackers to execute arbitrary SQL commands via the uid parameter to viewuser.php. Patch early 7.5 high 2.1% 2005-12-11
CVE-2007-6663 EXP SQL injection vulnerability in (1) Puarcade.php and (2) PUarcade.html.php in Pragmatic Utopia PU Arcade (com_puarcade) 2.0.3, 2.1.2, and 2.1.3 Beta co… Patch early 7.5 high 2.1% 2008-01-04
CVE-2006-7135 EXP PHP remote file inclusion vulnerability in lib/functions.inc.php in PHP Poll Creator (phpPC) 1.04 allows remote attackers to execute arbitrary PHP cod… Patch early 7.5 high 2.1% 2007-03-07
CVE-2007-0354 EXP SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via… Patch early 7.5 high 2.1% 2007-01-19
CVE-2008-6807 EXP PHP remote file inclusion vulnerability in ListRecords.php in osprey 1.0a4.1 allows remote attackers to execute arbitrary PHP code via a URL in the xm… Patch early 7.5 high 2.1% 2009-05-12
CVE-2008-7000 EXP PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan para… Patch early 7.5 high 2.1% 2009-08-19
CVE-2009-3220 EXP PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PH… Patch early 7.5 high 2.1% 2009-09-16
CVE-2010-4914 EXP PHP remote file inclusion vulnerability in tools/phpmailer/class.phpmailer.php in PHP Classifieds 7.3 allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 2.1% 2011-10-08
CVE-2002-0951 EXP SQL injection vulnerability in Ruslan <Body>Builder allows remote attackers to gain administrative privileges via a "'--" sequence in the username and… Patch early 10.0 high 2.1% 2002-10-04
CVE-2017-8928 EXP mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF. Patch early 8.8 high 2% 2017-05-14
← previous page 295 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt