peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,145 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

150,782 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-1607 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Novell Filr before 2.0 Security Update 2 allow remote at… Patch early 7.2 high 3.4% 2016-08-01
CVE-2007-2290 EXP Multiple PHP remote file inclusion vulnerabilities in B2 Weblog and News Publishing Tool 0.6.1 allow remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 3.4% 2007-04-26
CVE-2013-7053 EXP D-Link DIR-100 4.03B07: cli.cgi CSRF Patch early 8.8 high 3.4% 2020-02-04
CVE-2007-2325 EXP PHP remote file inclusion vulnerability in include.php in MyNewsGroups :) allows remote attackers to execute arbitrary PHP code via a URL in the myng_… Patch early 10.0 high 3.4% 2007-04-27
CVE-2008-4178 EXP SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and Downline Goldmine Builder allow… Patch early 7.5 high 3.4% 2008-09-23
CVE-2006-0153 EXP 427BB 2.2 and 2.2.1 verifies authentication credentials based on the username, authenticated, and usertype cookies, which allows remote attackers to b… Patch early 7.5 high 3.4% 2006-01-10
CVE-2006-6552 EXP PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to execute arbitrary… Patch early 7.5 high 3.4% 2006-12-14
CVE-2023-40279 EXP An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to main.… Patch early 7.5 high 3.4% 2024-03-19
CVE-2016-7185 EXP The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R… Patch early 7.8 high 3.4% 2016-10-14
CVE-2016-4311 EXP Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authenti… Patch early 8.8 high 3.4% 2017-02-17
CVE-2007-4283 EXP PHP remote file inclusion vulnerability in bridge/yabbse.inc.php in Coppermine Photo Gallery (CPG) 1.3.1 allows remote attackers to execute arbitrary… Patch early 7.5 high 3.4% 2007-08-09
CVE-2002-0612 EXP FileSeek.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) head or (2) foot parameters. Patch early 7.5 high 3.4% 2002-06-18
CVE-2003-1286 EXP HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy HTTP request… Patch early 7.5 high 3.4% 2003-12-31
CVE-2025-10666 EXP A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The… Patch early 8.8 high 3.4% 2025-09-18
CVE-2008-5783 EXP admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative access by setting the admin coo… Patch early 7.5 high 3.4% 2008-12-31
CVE-2006-5154 EXP PHP remote file inclusion vulnerability in cp/sig.php in DeluxeBB 1.09 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 3.4% 2006-10-05
CVE-2007-0181 EXP PHP remote file inclusion vulnerability in include/common_function.php in magic photo storage website allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 3.4% 2007-01-11
CVE-2007-0205 EXP Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directo… Patch early 7.5 high 3.4% 2007-01-11
CVE-2012-2109 EXP SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attackers to execute arbitrary SQL c… Patch early 7.5 high 3.4% 2012-09-04
CVE-2015-1726 EXP Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 an… Patch early 7.2 high 3.4% 2015-06-10
CVE-2011-1516 EXP The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all creat… Patch early 7.6 high 3.4% 2011-11-15
CVE-2006-5547 EXP PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.0.0 through 1.0.3 allows remote… Patch early 7.5 high 3.4% 2006-10-26
CVE-2006-5548 EXP PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 2.0.0 through 2.1.3 allows remote… Patch early 7.5 high 3.4% 2006-10-26
CVE-2020-14930 EXP An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verif… Patch early 8.1 high 3.4% 2020-06-19
CVE-2007-0682 EXP PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allows remote attackers to execute… Patch early 7.5 high 3.4% 2007-02-03
CVE-2007-1011 EXP PHP remote file inclusion vulnerability in functions_inc.php in VS-Gastebuch 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 3.4% 2007-02-21
CVE-2006-1662 EXP The frontpage option in Limbo CMS 1.0.4.2 and 1.0.4.1 allows remote attackers to execute arbitrary PHP commands via the Itemid parameter in index.php. Patch early 7.5 high 3.4% 2006-04-07
CVE-2006-6417 EXP PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers to execute a… Patch early 7.5 high 3.4% 2006-12-10
CVE-2019-5797 EXP Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p… Patch early 7.5 high 3.4% 2022-09-29
CVE-2015-4593 EXP eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserService.jsp which allows remote at… Patch early 8.8 high 3.4% 2017-01-10
← previous page 248 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt