peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,415 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

170,849 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-6027 EXP PHP remote file inclusion vulnerability in admin.jjgallery.php in the Carousel Flash Image Gallery (com_jjgallery) component for Joomla! allows remote… Patch early 6.8 medium 2.1% 2007-11-20
CVE-2007-6139 EXP PHP remote file inclusion vulnerability in index.php in Mp3 ToolBox 1.0 beta 5 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 6.8 medium 2.1% 2007-11-27
CVE-2007-6464 EXP Multiple PHP remote file inclusion vulnerabilities in Form tools 1.5.0b allow remote attackers to execute arbitrary PHP code via a URL in the g_root_d… Patch early 6.8 medium 2.1% 2007-12-20
CVE-2006-5057 EXP Multiple cross-site scripting (XSS) vulnerabilities in Ktools.net PhotoStore allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 5.1 medium 2.1% 2006-09-28
CVE-2006-5064 EXP Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the… Patch early 5.1 medium 2.1% 2006-09-28
CVE-2006-5066 EXP Multiple cross-site scripting (XSS) vulnerabilities in DanPHPSupport 0.5, and other versions before 1.0, allow remote attackers to inject arbitrary we… Patch early 5.1 medium 2.1% 2006-09-28
CVE-2007-3939 EXP SQL injection vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) CMS 3.4 and earlier allows remote attackers to e… Patch early 6.8 medium 2.1% 2007-07-21
CVE-2013-6275 EXP Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php. Patch early 6.5 medium 2.1% 2019-11-05
CVE-2006-2497 EXP Multiple cross-site scripting (XSS) vulnerabilities in AspBB 0.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) action pa… Patch early 5.8 medium 2.1% 2006-05-20
CVE-2020-8839 EXP Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cgi TF_submask field. Patch early 6.1 medium 2.1% 2020-02-12
CVE-2007-4057 EXP Unrestricted file upload vulnerability in pfs.php in Neocrome Seditio 121 and earlier allows remote authenticated users to upload arbitrary PHP code v… Patch early 6.5 medium 2.1% 2007-07-30
CVE-2007-6399 EXP index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current user account by reading the passw… Patch early 6.5 medium 2.1% 2007-12-17
CVE-2008-6282 EXP SQL injection vulnerability in engine/users/users_edit_pub.inc in CMS Ortus 1.13 and earlier allows remote authenticated users to execute arbitrary SQ… Patch early 6.5 medium 2.1% 2009-02-25
CVE-2006-5722 EXP Multiple PHP remote file inclusion vulnerabilities in Segue CMS 1.5.9 and earlier, when magic_quotes_gpc is enabled, allow remote attackers to execute… Patch early 5.1 medium 2.1% 2006-11-04
CVE-2008-2881 EXP Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sen… Patch early 5.0 medium 2.1% 2008-06-26
CVE-2007-3429 EXP Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload a… Patch early 6.8 medium 2.1% 2007-06-27
CVE-2018-5479 EXP FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its search engine via the search param… Patch early 6.1 medium 2.1% 2018-01-15
CVE-2006-1828 EXP SQL injection vulnerability in php121language.php in PHP121 1.4 allows remote attackers to execute arbitrary SQL commands and execute arbitrary code v… Patch early 5.1 medium 2.1% 2006-04-19
CVE-2003-1436 EXP PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute arbitrary PHP code via the fil… Patch early 6.8 medium 2.1% 2003-12-31
CVE-2005-1051 EXP SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in… Patch early 6.5 medium 2.1% 2005-05-02
CVE-2013-5716 EXP Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV f… Patch early 4.3 medium 2.1% 2013-09-09
CVE-2006-7100 EXP PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Insert User 0.1.2 and earlier allows remote attackers to execute a… Patch early 6.8 medium 2.1% 2007-03-03
CVE-2006-2459 EXP SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL commands via… Patch early 6.4 medium 2.1% 2006-05-19
CVE-2006-2070 EXP Cross-site scripting (XSS) vulnerability in member.php in DevBB 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via t… Patch early 4.3 medium 2.1% 2006-04-27
CVE-2006-2228 EXP Cross-site scripting (XSS) vulnerability in w-Agora (aka Web-Agora) 4.2.0 allows remote attackers to inject arbitrary web script or HTML via a post wi… Patch early 4.3 medium 2.1% 2006-05-05
CVE-2011-4333 EXP Multiple cross-site scripting (XSS) vulnerabilities in LabWiki 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (… Patch early 6.1 medium 2.1% 2017-10-23
CVE-2006-1582 EXP Cross-site scripting (XSS) vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to inject arbitrary web script or HTML via the _path… Patch early 5.8 medium 2.1% 2006-04-02
CVE-2008-6039 EXP Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. Patch early 6.8 medium 2.1% 2009-02-03
CVE-2009-4067 EXP Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 allows physically proximate attac… Patch early 6.8 medium 2.1% 2020-02-11
CVE-2026-44596 EXP Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java… Patch early 6.5 medium 2.1% 2026-07-16
← previous page 240 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt