peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,032 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

170,246 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-4609 EXP Multiple PHP remote file inclusion vulnerabilities in the Content Management module ("Content manager") for PHProjekt 0.6.1, when register_globals is… Patch early 5.1 medium 3% 2006-09-07
CVE-2006-4638 EXP PHP remote file inclusion vulnerability in article.php in ACGV News 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL… Patch early 5.1 medium 3% 2006-09-08
CVE-2006-4719 EXP Multiple PHP remote file inclusion vulnerabilities in MyABraCaDaWeb 1.0.3, when register_globals is enabled, allow remote attackers to execute arbitra… Patch early 5.1 medium 3% 2006-09-12
CVE-2006-4750 EXP PHP remote file inclusion vulnerability in openi-admin/base/fileloader.php in OPENi-CMS 1.0.1, and possibly earlier, allows remote attackers to execut… Patch early 5.1 medium 3% 2006-09-13
CVE-2006-5070 EXP PHP remote file inclusion vulnerability in fsl2/objects/fs_form_links.php in faceStones Personal 2.0.42 and earlier allows remote attackers to execute… Patch early 5.1 medium 3% 2006-09-28
CVE-2006-5167 EXP Multiple PHP remote file inclusion vulnerabilities in BasiliX 1.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 5.1 medium 3% 2006-10-05
CVE-2006-5207 EXP PHP remote file inclusion vulnerability in images/smileys/smileys_packs.php in phpMyTeam 2.0, when register_globals is enabled, allows remote attacker… Patch early 5.1 medium 3% 2006-10-10
CVE-2006-4631 EXP Direct static code injection vulnerability in admin/save_opt.php in SoftBB 0.1, and possibly earlier, allows remote authenticated users to upload and… Patch early 6.5 medium 3% 2006-09-08
CVE-2006-6330 EXP index.php for TorrentFlux 2.2 allows remote registered users to execute arbitrary commands via shell metacharacters in the kill parameter. Patch early 6.0 medium 3% 2006-12-06
CVE-2008-6112 EXP Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a .. (dot dot) in the id parame… Patch early 5.0 medium 3% 2009-02-11
CVE-2010-4781 EXP index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attackers to obtain sensitive informa… Patch early 5.0 medium 3% 2011-04-07
CVE-2015-6965 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for WordPress allow remote attackers… Patch early 6.8 medium 3% 2015-09-16
CVE-2006-4766 EXP Directory traversal vulnerability in print.php in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allows remote attackers to read arbitrary files via a… Patch early 5.0 medium 3% 2006-09-13
CVE-2007-0055 EXP Directory traversal vulnerability in formbankcgi.exe/AbfrageForm in Formbankserver 1.9 allows remote attackers to read arbitrary files via directory t… Patch early 5.0 medium 3% 2007-01-04
CVE-2005-3520 EXP Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web script or HTML via (1) the targe… Patch early 4.3 medium 3% 2005-11-06
CVE-2017-11785 EXP The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, W… Patch early 5.5 medium 3% 2017-10-13
CVE-2017-8564 EXP Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 1… Patch early 5.5 medium 3% 2017-07-11
CVE-2007-3790 EXP The com_print_typeinfo function in the bz2 extension in PHP 5.2.3 allows context-dependent attackers to cause a denial of service via a long argument. Patch early 5.8 medium 3% 2007-07-15
CVE-2007-3556 EXP Liesbeth base CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an inclu… Patch early 5.0 medium 3% 2007-07-04
CVE-2007-2780 EXP PsychoStats 3.0.6b and earlier allows remote attackers to obtain sensitive information via a request for server.php with a missing or invalid newtheme… Patch early 5.0 medium 3% 2007-05-21
CVE-2017-2508 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" co… Patch early 6.1 medium 3% 2017-05-22
CVE-2001-0286 EXP Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request. Patch early 5.0 medium 3% 2001-05-03
CVE-2003-1232 EXP Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted att… Patch early 5.1 medium 3% 2003-12-31
CVE-2005-1870 EXP PHP remote file inclusion vulnerability in childwindow.inc.php in Popper 1.41-r2 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 5.0 medium 3% 2005-06-09
CVE-2006-4637 EXP Multiple PHP remote file inclusion vulnerabilities in ACGV News 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the PathNews p… Patch early 5.1 medium 3% 2006-09-08
CVE-2007-4127 EXP PHP remote file inclusion vulnerability in check_entry.php in Ralf Image Gallery (RIG), aka Raphael Moll RIG Image Gallery, 1.0 allows remote attacker… Patch early 6.8 medium 3% 2007-08-01
CVE-2018-17996 EXP LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content vi… Patch early 6.5 medium 3% 2019-03-21
CVE-2021-27695 EXP Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via an… Patch early 6.1 medium 3% 2021-03-15
CVE-2007-5149 EXP PHP remote file inclusion vulnerability in NewsCMS/news/newstopic_inc.php in North Country Public Radio Public Media Manager (PMM) 1.3 allows remote a… Patch early 6.8 medium 3% 2007-10-01
CVE-2007-5178 EXP contrib/mx_glance_sdesc.php in the mx_glance 2.3.3 module for mxBB places a critical security check within a comment because of a missing comment deli… Patch early 6.8 medium 3% 2007-10-03
← previous page 183 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt