peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,069 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

150,779 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-0699 EXP PHP remote file inclusion vulnerability in includes/includes.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) before 2.5.1.1… Patch early 7.5 high 3.5% 2007-02-04
CVE-2009-2925 EXP Directory traversal vulnerability in DJcalendar.cgi in DJCalendar allows remote attackers to read arbitrary files via a .. (dot dot) in the TEMPLATE p… Patch early 7.8 high 3.5% 2009-08-21
CVE-2008-4732 EXP SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to execute arbitrar… Patch early 7.5 high 3.5% 2008-10-24
CVE-2006-6368 EXP PHP remote file inclusion vulnerability in login.php.inc in awrate 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the toroot p… Patch early 7.5 high 3.5% 2006-12-07
CVE-2006-5788 EXP PHP remote file inclusion vulnerability in (1) index.php and (2) admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to execute a… Patch early 7.5 high 3.5% 2006-11-07
CVE-2008-6593 EXP SQL injection vulnerability in LightNEasy/lightneasy.php in LightNEasy SQLite 1.2.2 and earlier allows remote attackers to inject arbitrary PHP code i… Patch early 7.5 high 3.5% 2009-04-03
CVE-2015-2365 EXP win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows… Patch early 7.2 high 3.5% 2015-07-14
CVE-2015-2366 EXP win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2,… Patch early 7.2 high 3.5% 2015-07-14
CVE-2002-2325 EXP The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to c… Patch early 7.8 high 3.5% 2002-12-31
CVE-2003-0243 EXP Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) no… Patch early 7.5 high 3.5% 2003-05-27
CVE-2006-5124 EXP Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 3.5% 2006-10-03
CVE-2007-5089 EXP PHP remote file inclusion vulnerability in php-inc/log.inc.php in sk.log 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 3.5% 2007-09-26
CVE-2017-0214 EXP Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 G… Patch early 7.0 high 3.5% 2017-05-12
CVE-2008-4526 EXP Multiple directory traversal vulnerabilities in CCMS 3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the… Patch early 10.0 high 3.5% 2008-10-09
CVE-2013-4948 EXP SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the element_2 parameter. Patch early 7.5 high 3.5% 2013-07-29
CVE-2006-4040 EXP PHP remote file inclusion vulnerability in myevent.php in myWebland myEvent 1.3 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 3.5% 2006-08-09
CVE-2006-4045 EXP PHP remote file inclusion vulnerability in news.php in Torbstoff News 4 allows remote attackers to execute arbitrary PHP code via a URL in the pfad pa… Patch early 7.5 high 3.5% 2006-08-09
CVE-2006-4209 EXP PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 3.5% 2006-08-17
CVE-2006-4296 EXP PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers to include… Patch early 7.5 high 3.5% 2006-08-23
CVE-2006-4629 EXP PHP remote file inclusion vulnerability in affichage/commentaires.php in C-News.fr C-News 1.0.1 and earlier allows remote attackers to execute arbitra… Patch early 7.5 high 3.5% 2006-09-08
CVE-2006-4630 EXP PHP remote file inclusion vulnerability in jscript.php in Sky GUNNING MySpeach 3.0.2 and earlier, when register_globals is enabled, allows remote atta… Patch early 7.5 high 3.5% 2006-09-08
CVE-2005-1487 EXP Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt… Patch early 7.5 high 3.5% 2005-05-11
CVE-2006-2008 EXP PHP remote file inclusion vulnerability in movie_cls.php in Built2Go PHP Movie Review 2B and earlier allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 3.5% 2006-04-25
CVE-2006-3177 EXP PHP remote file inclusion vulnerability in Admin/rtf_parser.php in The Bible Portal Project 2.12 and earlier allows remote attackers to execute arbitr… Patch early 7.5 high 3.5% 2006-06-23
CVE-2006-3300 EXP PHP remote file inclusion vulnerability in sms_config/gateway.php in PhpMySms 2.0 and earlier allows remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 3.5% 2006-06-29
CVE-2006-0887 EXP Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib distribution is available on th… Patch early 7.5 high 3.5% 2006-02-25
CVE-2000-0342 EXP Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers… Patch early 7.5 high 3.5% 2000-04-28
CVE-2000-0592 EXP Buffer overflows in POP3 service in WinProxy 2.0 and 2.0.1 allow remote attackers to execute arbitrary commands via long USER, PASS, LIST, RETR, or DE… Patch early 7.5 high 3.5% 2000-06-27
CVE-2007-2556 EXP SQL injection vulnerability in Nuked-klaN 1.7.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For (X_FORWARDED_FOR) HT… Patch early 7.5 high 3.5% 2007-05-09
CVE-2007-1795 EXP JCcorp URLshrink 1.3.1 allows remote attackers to execute arbitrary PHP code via the email address field in an HTML link. NOTE: the provenance of thi… Patch early 10.0 high 3.4% 2007-04-02
← previous page 245 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt