peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,164 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

150,785 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-1402 EXP SQL injection vulnerability in iWebNegar allows remote attackers to execute arbitrary SQL commands via (1) the string parameter for index.php, (2) com… Patch early 10.0 high 3.3% 2004-12-31
CVE-2006-3776 EXP PHP remote file inclusion vulnerability in order/index.php in IDevSpot (1) PhpHostBot 1.0 and (2) AutoHost 3.0 allows remote attackers to execute arbi… Patch early 7.5 high 3.3% 2006-07-24
CVE-2005-3860 EXP PHP remote file inclusion vulnerability in athena.php in Oliver May Athena PHP Website Administration 0.1a allows remote attackers to execute arbitrar… Patch early 7.5 high 3.3% 2005-11-29
CVE-2003-0974 EXP Applied Watch Command Center allows remote attackers to conduct unauthorized activities without authentication, such as (1) add new users to a console… Patch early 7.5 high 3.3% 2003-12-15
CVE-2006-6078 EXP PHP remote file inclusion vulnerability in common.inc.php in a-ConMan 3.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 3.3% 2006-11-24
CVE-2007-1839 EXP Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the p… Patch early 7.5 high 3.3% 2007-04-03
CVE-2007-2530 EXP Multiple PHP remote file inclusion vulnerabilities in Tropicalm Crowell Resource 4.5.2 allow remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 3.3% 2007-05-09
CVE-2007-2531 EXP PHP remote file inclusion vulnerability in berylium-classes.php in Berylium2 2003-08-18 allows remote attackers to execute arbitrary PHP code via a UR… Patch early 7.5 high 3.3% 2007-05-09
CVE-2007-2596 EXP PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 3.3% 2007-05-11
CVE-2007-2620 EXP PHP remote file inclusion vulnerability in inc/config.inc.php in Jakub Steiner (aka jimmac) original 0.11 allows remote attackers to execute arbitrary… Patch early 7.5 high 3.3% 2007-05-11
CVE-2007-2706 EXP PHP remote file inclusion vulnerability in maint/ftpmedia.php in Media Gallery 1.4.8a and earlier for Geeklog allows remote attackers to execute arbit… Patch early 7.5 high 3.3% 2007-05-16
CVE-2007-2751 EXP Multiple PHP remote file inclusion vulnerabilities in PHPGlossar 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the format_menu… Patch early 7.5 high 3.3% 2007-05-17
CVE-2007-3271 EXP PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attackers to execute arbitrary PHP c… Patch early 7.5 high 3.3% 2007-06-19
CVE-2007-3460 EXP Multiple PHP remote file inclusion vulnerabilities in index.php3 in EVA-Web 1.1 through 2.2 allow remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 3.3% 2007-06-27
CVE-2007-2330 EXP PHP remote file inclusion vulnerability in includes_handler.php in DynaTracker 151 allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 3.3% 2007-04-27
CVE-2001-1460 EXP SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user parameter. Patch early 7.5 high 3.3% 2001-10-13
CVE-2026-25732 EXP NiceGUI is a Python-based UI framework. Prior to 3.7.0, NiceGUI's FileUpload.name property exposes client-supplied filename metadata without sanitizat… Patch early 7.5 high 3.3% 2026-02-06
CVE-2006-6250 EXP Format string vulnerability in Songbird Media Player 0.2 and earlier allows remote attackers to cause a denial of service (crash) via an M3U Playlist… Patch early 7.8 high 3.3% 2006-12-04
CVE-2014-10023 EXP Multiple SQL injection vulnerabilities in TopicsViewer 3.0 Beta 1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1)… Patch early 7.5 high 3.3% 2015-01-13
CVE-2006-5230 EXP PHP remote file inclusion vulnerability in forum.php in FreeForum 0.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 3.3% 2006-10-11
CVE-2006-5493 EXP PHP remote file inclusion vulnerability in template/purpletech/base_include.php in DigitalHive 2.0 RC2 allows remote attackers to execute arbitrary PH… Patch early 7.5 high 3.3% 2006-10-25
CVE-2004-1813 EXP VocalTec VGW4/8 Gateway 8.0 allows remote attackers to bypass authentication via an HTTP request to home.asp with a trailing slash (/). Patch early 7.5 high 3.3% 2004-12-31
CVE-2004-1329 EXP Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows… Patch early 7.2 high 3.3% 2004-12-20
CVE-2022-25241 EXP In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF). Patch early 8.8 high 3.3% 2022-02-16
CVE-2008-0422 EXP SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via t… Patch early 7.5 high 3.3% 2008-01-23
CVE-2007-3611 EXP admin.php in VRNews 1.1.1, and possibly other 1.x versions, does not require authentication, which allows remote attackers to perform certain administ… Patch early 9.3 high 3.3% 2007-07-06
CVE-2002-1113 EXP summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_path paramet… Patch early 7.5 high 3.3% 2002-10-04
CVE-2024-53582 EXP An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to execute a directory traversal via… Patch early 7.5 high 3.3% 2025-01-31
CVE-1999-0679 EXP Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option. Patch early 7.5 high 3.3% 1999-08-13
CVE-2006-5148 EXP Multiple PHP remote file inclusion vulnerabilities in Forum82 2.5.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 3.3% 2006-10-05
← previous page 252 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt