peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,922 CVEs 1,739 on KEV 17,301 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

150,703 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-4720 EXP PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary PHP code via a URL in the pat… Patch early 7.5 high 3.6% 2006-09-12
CVE-2006-1090 EXP register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations. Patch early 7.8 high 3.6% 2006-03-09
CVE-2007-2779 EXP PHP remote file inclusion vulnerability in template_csv.php in Libstats 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 3.6% 2007-05-21
CVE-2007-4808 EXP Multiple SQL injection vulnerabilities in TLM CMS 3.2 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php in… Patch early 7.5 high 3.6% 2007-09-11
CVE-2009-0646 EXP Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login and (2)… Patch early 7.5 high 3.6% 2009-02-18
CVE-2016-0143 EXP The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2… Patch early 7.8 high 3.6% 2016-04-12
CVE-2007-2427 EXP SQL injection vulnerability in index.php in the pnFlashGames 1.5 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the… Patch early 7.5 high 3.6% 2007-05-02
CVE-2007-2678 EXP Buffer overflow in the isChecked function in toolbar.dll in Netsprint Toolbar 1.1 might allow remote attackers to execute arbitrary code via unspecifi… Patch early 7.5 high 3.6% 2007-05-15
CVE-2006-5076 EXP Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End 0.4.5 allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 3.6% 2006-09-29
CVE-2005-1161 EXP Multiple SQL injection vulnerabilities in OneWorldStore allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) ow… Patch early 7.5 high 3.6% 2005-05-02
CVE-2017-14266 EXP tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related issue to CVE-2016-6160. Patch early 7.8 high 3.6% 2017-09-12
CVE-2006-7134 EXP Unrestricted file upload vulnerability in main_user.php in Upload Tool for PHP 1.0 allows remote attackers to upload and execute arbitrary files with… Patch early 10.0 high 3.6% 2007-03-06
CVE-2009-0968 EXP SQL injection vulnerability in fmoblog.php in the fMoblog plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the i… Patch early 7.5 high 3.6% 2009-03-19
CVE-2012-3435 EXP SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and earlier, and 2.x before 2.0.2rc1, allows remote attackers to exec… Patch early 7.5 high 3.6% 2012-08-15
CVE-2007-0576 EXP PHP remote file inclusion vulnerability in xt_counter.php in Xt-Stats 2.3.x up to 2.4.0.b3 allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 3.6% 2007-01-30
CVE-2006-5093 EXP PHP remote file inclusion vulnerability in index.php in Tagmin Control Center in TagIt! Tagboard 2.1.B Build 2 allows remote attackers to execute arbi… Patch early 7.5 high 3.6% 2006-09-29
CVE-2006-4607 EXP admin/index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to bypass authentication controls by setting the ID_ADMIN and SUPER_ADMIN… Patch early 7.5 high 3.6% 2006-09-07
CVE-2015-0004 EXP The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win… Patch early 7.2 high 3.6% 2015-01-13
CVE-2006-4026 EXP PHP remote file inclusion vulnerability in SAPID CMS 123 rc3 allows remote attackers to execute arbitrary PHP code via a URL in the (1) root_path para… Patch early 7.5 high 3.6% 2006-08-09
CVE-2006-1799 EXP censtore.cgi in Censtore 7.3.002 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter. Patch early 7.5 high 3.6% 2006-04-18
CVE-2008-6824 EXP The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin account, which makes it easier for… Patch early 10.0 high 3.6% 2009-06-04
CVE-2006-6581 EXP PHP remote file inclusion vulnerability in tests/debug_test.php in Vernet Loic PHP_Debug 1.1.0 allows remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 3.6% 2006-12-15
CVE-2012-0699 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the a… Patch early 8.8 high 3.6% 2018-01-11
CVE-2006-1032 EXP Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other progr… Patch early 7.5 high 3.6% 2006-03-07
CVE-2006-2982 EXP Multiple PHP remote file inclusion vulnerabilities in Enterprise Timesheet and Payroll Systems (EPS) 1.1 and earlier allow remote attackers to execute… Patch early 7.5 high 3.6% 2006-06-13
CVE-2006-3922 EXP PHP remote file inclusion vulnerability in mod_membre/inscription.php in PortailPHP 1.7 allows remote attackers to execute arbitrary PHP code via a UR… Patch early 7.5 high 3.6% 2006-07-28
CVE-2006-6041 EXP Multiple PHP remote file inclusion vulnerabilities in Laurent Van den Reysen WORK system e-commerce 3.0.2, and other versions before 3.0.4, allow remo… Patch early 7.5 high 3.6% 2006-11-22
CVE-2006-2666 EXP PHP remote file inclusion vulnerability in includes/mailaccess/pop3.php in V-Webmail 1.5 through 1.6.4 allows remote attackers to execute arbitrary PH… Patch early 7.5 high 3.6% 2006-05-30
CVE-2006-3028 EXP PHP remote file inclusion vulnerability in stat_modules/users_age/module.php in Minerva 2.0.8a Build 237 and earlier allows remote attackers to execut… Patch early 7.5 high 3.6% 2006-06-15
CVE-2013-3365 EXP TRENDnet TEW-812DRU router allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) wan network prefix to i… Patch early 8.5 high 3.6% 2014-02-04
← previous page 241 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt