peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,370 CVEs 1,739 on KEV 17,299 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-1966 EXP Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary SQL commands via… Patch early 7.5 high 1.3% 2004-12-31
CVE-2011-4559 EXP SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the o… Patch early 7.5 high 1.3% 2011-11-28
CVE-2000-0680 EXP The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committer… Patch early 7.2 high 1.3% 2000-10-20
CVE-2007-4628 EXP SQL injection vulnerability in shownews.php in phpns 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. Patch early 7.5 high 1.3% 2007-08-31
CVE-2001-0553 EXP SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access… Patch early 7.2 high 1.3% 2001-08-14
CVE-2006-5836 EXP The fpathconf syscall function in bsd/kern/kern_descrip.c in the Darwin kernel (XNU) 8.8.1 in Apple Mac OS X allows local users to cause a denial of s… Patch early 7.2 high 1.3% 2006-11-10
CVE-2005-0935 EXP Multiple SQL injection vulnerabilities in ESMI PayPal Storefront allow remote attackers to execute arbitrary SQL commands via the (1) idpages paramete… Patch early 7.5 high 1.3% 2005-05-02
CVE-2005-4035 EXP Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL comm… Patch early 7.5 high 1.3% 2005-12-06
CVE-2006-0358 EXP Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbitrary SQL commands via the… Patch early 7.5 high 1.3% 2006-01-22
CVE-2003-0947 EXP Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environment variable. Patch early 7.2 high 1.3% 2003-12-15
CVE-2016-2288 EXP Cogent DataHub before 7.3.10 allows local users to gain privileges by leveraging the user or guest role to modify a file. Patch early 7.8 high 1.3% 2016-03-29
CVE-2006-3271 EXP Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1) country and (2) sort_by parame… Patch early 7.5 high 1.3% 2006-06-28
CVE-2026-21244 EXP Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. Patch early 7.3 high 1.3% 2026-02-10
CVE-2026-21248 EXP Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. Patch early 7.3 high 1.3% 2026-02-10
CVE-2005-2002 EXP SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating… Patch early 7.5 high 1.3% 2005-06-15
CVE-2005-3924 EXP SQL injection vulnerability in themes/kategorie/index.php in Randshop allows remote attackers to execute arbitrary SQL commands via the (1) kategoriei… Patch early 7.5 high 1.3% 2005-11-30
CVE-2006-0154 EXP SQL injection vulnerability in showthread.php in 427BB 2.2 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the ForumID paramet… Patch early 7.5 high 1.3% 2006-01-10
CVE-2006-0349 EXP SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to blog.php. Patch early 7.5 high 1.3% 2006-01-21
CVE-2006-1109 EXP SQL injection vulnerability in index.asp in Total Ecommerce 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE:… Patch early 7.5 high 1.3% 2006-03-09
CVE-2006-2793 EXP SQL injection vulnerability in Anket.asp in ASPSitem 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter. Patch early 7.5 high 1.3% 2006-06-03
CVE-2006-3394 EXP SQL injection vulnerability in the files mod in index.php in BXCP 0.3.0.4 allows remote attackers to execute arbitrary SQL commands via the where para… Patch early 7.5 high 1.3% 2006-07-06
CVE-2012-1017 EXP Multiple SQL injection vulnerabilities in base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbit… Patch early 7.5 high 1.3% 2012-02-08
CVE-1999-0038 EXP Buffer overflow in xlock program allows local users to execute commands as root. Patch early 8.4 high 1.3% 1997-04-26
CVE-2007-1963 EXP SQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and earlier allows remote attacker… Patch early 7.5 high 1.3% 2007-04-11
CVE-2006-0235 EXP SQL injection vulnerability in WhiteAlbum 2.5 allows remote attackers to execute arbitrary SQL commands via the dir parameter to pictures.php. Patch early 7.5 high 1.3% 2006-01-18
CVE-2006-0372 EXP Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 1.3% 2006-01-22
CVE-2006-1271 EXP SQL injection vulnerability in index.php in OxyNews allows remote attackers to execute arbitrary SQL commands via the oxynews_comment_id parameter. Patch early 7.5 high 1.3% 2006-03-19
CVE-2006-1557 EXP Multiple SQL injection vulnerabilities in X-Changer 0.2 allow remote attackers to execute arbitrary SQL commands via the (1) from and (2) into paramet… Patch early 7.5 high 1.3% 2006-03-31
CVE-2007-1292 EXP SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote authenticated… Patch early 7.5 high 1.3% 2007-03-07
CVE-2005-3369 EXP Multiple SQL injection vulnerabilities in the Info-DB module (info_db.php) in Woltlab Burning Board 2.7 and earlier allow remote attackers to execute… Patch early 7.5 high 1.3% 2005-10-30
← previous page 314 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt