peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,069 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

150,779 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-6869 EXP Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and reg… Patch early 9.3 high 3.4% 2006-12-31
CVE-2009-4194 EXP Directory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions allows remote authenticated users… Patch early 8.1 high 3.4% 2009-12-03
CVE-2016-0728 EXP The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error cas… Patch early 7.8 high 3.4% 2016-02-08
CVE-2007-6231 EXP Multiple PHP remote file inclusion vulnerabilities in tellmatic 1.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the tm_include… Patch early 7.5 high 3.4% 2007-12-04
CVE-2005-3859 EXP PHP remote file inclusion vulnerability in q-news.php in Q-News 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the id paramete… Patch early 7.5 high 3.4% 2005-11-29
CVE-2007-5926 EXP OpenBase 10.0.5 and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in arguments to the (1) AsciiBack… Patch early 9.0 high 3.4% 2007-11-10
CVE-2005-4168 EXP Multiple SQL injection vulnerabilities in eFiction 1.0, 1.1, and 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the let paramete… Patch early 7.5 high 3.4% 2005-12-11
CVE-2013-6164 EXP SQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execute arbitrary SQL commands via the objectI… Patch early 7.5 high 3.4% 2013-11-14
CVE-2017-6528 EXP An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/spool/.pfile file). Patch early 8.1 high 3.4% 2017-03-09
CVE-2007-6587 EXP SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. Patch early 7.5 high 3.4% 2007-12-28
CVE-2015-1727 EXP Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win… Patch early 7.2 high 3.4% 2015-06-10
CVE-2008-0785 EXP Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote authenticated users to execute arbitrary SQL… Patch early 7.5 high 3.4% 2008-02-14
CVE-2006-1994 EXP PHP remote file inclusion vulnerability in dForum 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DFORUM_PATH p… Patch early 7.5 high 3.4% 2006-04-25
CVE-2006-5849 EXP PHP remote file inclusion vulnerability in inc/irayofuncs.php in IrayoBlog alpha-0.2.4 allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 3.4% 2006-11-10
CVE-2006-4622 EXP PHP remote file inclusion vulnerability in annonce.php in AnnonceV (aka annoncesV) 1.1 allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 3.4% 2006-09-07
CVE-2006-3185 EXP PHP remote file inclusion vulnerability in data/header.php in CMS Faethon 1.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 3.4% 2006-06-23
CVE-2003-1131 EXP PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary P… Patch early 7.5 high 3.4% 2003-12-31
CVE-2005-1881 EXP upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to up… Patch early 7.5 high 3.4% 2005-06-06
CVE-2012-5049 EXP APIFTP Server in Optimalog Optima PLC 1.5.2 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed packet. Patch early 7.8 high 3.4% 2012-09-28
CVE-2008-3509 EXP LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows r… Patch early 7.5 high 3.4% 2008-08-07
CVE-2010-1897 EXP The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server… Patch early 7.2 high 3.4% 2010-08-11
CVE-2003-1407 EXP Buffer overflow in cmd.exe in Windows NT 4.0 may allow local users to execute arbitrary code via a long pathname argument to the cd command. Patch early 7.2 high 3.4% 2003-12-31
CVE-2008-0743 EXP PHP remote file inclusion vulnerability in members_help.php in Joovili 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL… Patch early 10.0 high 3.4% 2008-02-13
CVE-2006-4648 EXP PHP remote file inclusion vulnerability in bp_ncom.php in BinGo News (BP News) 3.01 and earlier allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 3.4% 2006-09-08
CVE-2011-5212 EXP SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via the (1) user name or… Patch early 7.5 high 3.4% 2012-10-22
CVE-2007-2147 EXP admin/options.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier does not check for administrative credentials, which allows remote attac… Patch early 10.0 high 3.4% 2007-04-19
CVE-2015-5452 EXP SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitrary SQL commands via the sid c… Patch early 7.5 high 3.4% 2015-07-08
CVE-2014-5329 EXP GIGAPOD file servers (Appliance model and Software model) provide two web interfaces, 80/tcp and 443/tcp for user operation, and 8001/tcp for administ… Patch early 7.5 high 3.4% 2023-09-08
CVE-2006-3997 EXP PHP remote file inclusion vulnerability in hsList.php in WoWRoster (aka World of Warcraft Roster) 1.5.x and earlier allows remote attackers to execute… Patch early 7.5 high 3.4% 2006-08-05
CVE-2006-2871 EXP PHP remote file inclusion vulnerability in include/common.php in CyBoards PHP Lite 1.25 allows remote attackers to execute arbitrary PHP code via a UR… Patch early 7.5 high 3.4% 2006-06-06
← previous page 246 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt