peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,932 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

150,708 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-2183 EXP Multiple SQL injection vulnerabilities in the administrative backend in ZeusCart 4 allow remote administrators to execute arbitrary SQL commands via t… Patch early 7.5 high 3.5% 2015-03-10
CVE-2015-2512 EXP The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Serv… Patch early 7.2 high 3.5% 2015-09-09
CVE-2008-0246 EXP admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain… Patch early 10.0 high 3.5% 2008-01-12
CVE-2007-4956 EXP Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to login.ph… Patch early 7.5 high 3.5% 2007-09-18
CVE-2006-5930 EXP Multiple PHP remote file inclusion vulnerabilities in Aigaion Web based bibliography management system 1.2.1 and earlier allow remote attackers to exe… Patch early 7.5 high 3.5% 2006-11-16
CVE-2008-1989 EXP PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows remo… Patch early 10.0 high 3.5% 2008-04-27
CVE-1999-1007 EXP Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file. Patch early 7.6 high 3.5% 1999-12-13
CVE-2002-0140 EXP Domain Name Relay Daemon (dnrd) 2.10 and earlier allows remote malicious DNS sites to cause a denial of service and possibly execute arbitrary code vi… Patch early 7.5 high 3.5% 2002-03-25
CVE-2006-2253 EXP PHP remote file inclusion vulnerability in visible_count_inc.php in Statit 4 (060207) allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 3.5% 2006-05-09
CVE-2006-4050 EXP PHP remote file inclusion vulnerability in auto_check_renewals.php in phpAutoMembersArea (phpAMA) 3.2.4 and earlier allows remote attackers to execute… Patch early 7.5 high 3.5% 2006-08-10
CVE-2006-4278 EXP PHP remote file inclusion vulnerability in includes/layout/plain.footer.php in SportsPHool 1.0 allows remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 3.5% 2006-08-21
CVE-2014-5308 EXP Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) name paramete… Patch early 9.0 high 3.5% 2014-10-08
CVE-2017-5473 EXP Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demo… Patch early 8.8 high 3.5% 2017-01-14
CVE-2023-24892 EXP Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability Patch early 8.2 high 3.5% 2023-03-14
CVE-2003-0609 EXP Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD… Patch early 7.2 high 3.5% 2003-08-27
CVE-2007-4909 EXP Interpretation conflict in WinSCP before 4.0.4 allows remote attackers to perform arbitrary file transfers with a remote server via file-transfer comm… Patch early 9.3 high 3.5% 2007-09-17
CVE-2019-19726 EXP OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be defeated by setting a very sm… Patch early 7.8 high 3.5% 2019-12-12
CVE-2003-0391 EXP Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cause a denial of service (crash)… Patch early 7.5 high 3.5% 2003-07-02
CVE-2021-30147 EXP DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php. Patch early 8.8 high 3.5% 2021-04-07
CVE-2017-14838 EXP TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange. Patch early 8.8 high 3.5% 2017-09-28
CVE-2017-14839 EXP TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover. Patch early 8.8 high 3.5% 2017-09-28
CVE-2017-14840 EXP TeamWork TicketPlus allows Arbitrary File Upload in updateProfile. Patch early 8.8 high 3.5% 2017-09-28
CVE-2005-1054 EXP PHP remote file inclusion vulnerability in news.php in ModernBill 4.3.0 and earlier allows remote attackers to execute arbitrary PHP code by modifying… Patch early 7.5 high 3.5% 2005-05-02
CVE-2007-2157 EXP Directory traversal vulnerability in upload/force_download.php in Zomplog 3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in th… Patch early 7.8 high 3.5% 2007-04-19
CVE-2013-3527 EXP Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the parameter na… Patch early 7.5 high 3.5% 2013-05-10
CVE-2006-1543 EXP Multiple SQL injection vulnerabilities in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to execute arbitrary SQL commands via the (1… Patch early 7.5 high 3.5% 2006-03-30
CVE-2010-2892 EXP gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbit… Patch early 8.5 high 3.5% 2010-11-15
CVE-2020-15255 EXP In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treate… Patch early 8.7 high 3.5% 2020-10-16
CVE-2008-4329 EXP PHP remote file inclusion vulnerability in cms/system/openengine.php in openEngine 2.0 beta4 and earlier allows remote attackers to execute arbitrary… Patch early 10.0 high 3.5% 2008-09-30
CVE-2008-6651 EXP Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbitrary PHP code into oxyhistory.… Patch early 10.0 high 3.5% 2009-04-07
← previous page 243 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt