peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,166 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

150,786 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-1650 EXP D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the IP address of the camera via a… Patch early 7.5 high 3.2% 2004-08-31
CVE-2005-4226 EXP Multiple "potential" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute arbitrary SQL commands via (1)… Patch early 7.5 high 3.2% 2005-12-14
CVE-2005-4427 EXP Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to… Patch early 7.5 high 3.2% 2005-12-20
CVE-2007-0568 EXP PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execute arbitrary PHP code via a UR… Patch early 7.5 high 3.2% 2007-01-30
CVE-2007-0581 EXP PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbitrary PHP code via a URL in th… Patch early 7.5 high 3.2% 2007-01-30
CVE-2007-1133 EXP PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_fuss para… Patch early 7.5 high 3.2% 2007-02-27
CVE-2007-1162 EXP A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a… Patch early 7.8 high 3.2% 2007-03-02
CVE-2007-1294 EXP A certain ActiveX control in the DivXBrowserPlugin (npdivx32.dll) in DivX Web Player, as distributed with DivX Player 1.3.0, allows remote attackers t… Patch early 7.8 high 3.2% 2007-03-07
CVE-2007-5440 EXP Multiple PHP remote file inclusion vulnerabilities in CRS Manager allow remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT… Patch early 7.5 high 3.2% 2007-10-14
CVE-2024-42471 EXP actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to… Patch early 7.3 high 3.2% 2024-09-02
CVE-2021-24174 EXP The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as… Patch early 8.1 high 3.2% 2021-04-05
CVE-2007-4806 EXP PHP remote file inclusion vulnerability in modules/Discipline/CategoryBreakdownTime.php in Focus/SIS 1.0 allows remote attackers to execute arbitrary… Patch early 7.5 high 3.2% 2007-09-11
CVE-2007-4807 EXP Multiple PHP remote file inclusion vulnerabilities in Focus/SIS 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the staticpath p… Patch early 7.5 high 3.2% 2007-09-11
CVE-2000-0798 EXP The truncate function in IRIX 6.x does not properly check for privileges when the file is in the xfs file system, which allows local users to delete t… Patch early 10.0 high 3.2% 2000-10-20
CVE-2025-24076 EXP Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. Patch early 7.3 high 3.2% 2025-03-11
CVE-2008-6937 EXP Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cau… Patch early 10.0 high 3.2% 2009-08-11
CVE-2007-1493 EXP nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, which allows remote attackers to e… Patch early 7.5 high 3.2% 2007-03-16
CVE-2009-1516 EXP Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependent… Patch early 7.5 high 3.2% 2009-05-04
CVE-2021-27885 EXP usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism. Patch early 8.8 high 3.2% 2021-03-02
CVE-2006-1031 EXP config/config_inc.php in iGENUS Webmail 2.02 and earlier allows remote attackers to include arbitrary local files via the SG_HOME parameter. Patch early 7.5 high 3.2% 2006-03-07
CVE-2018-0749 EXP The Microsoft Server Message Block (SMB) Server in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and… Patch early 7.8 high 3.2% 2018-01-04
CVE-2018-17182 EXP An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An… Patch early 7.8 high 3.2% 2018-09-19
CVE-2006-3777 EXP PHP remote file inclusion vulnerability in index.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute arbitrary PHP code via a URL i… Patch early 7.5 high 3.2% 2006-07-24
CVE-2007-6378 EXP Directory traversal vulnerability in upload.dll in BadBlue 2.72b and earlier allows remote attackers to create or overwrite arbitrary files via a .. (… Patch early 7.5 high 3.2% 2007-12-15
CVE-2007-0633 EXP PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attackers to execute arbitrary PHP c… Patch early 7.5 high 3.2% 2007-01-31
CVE-2007-0662 EXP PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 3.2% 2007-02-01
CVE-2007-0701 EXP PHP remote file inclusion vulnerability in inc/common.inc.php in Epistemon 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 3.2% 2007-02-04
CVE-2005-1203 EXP Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands via the (1… Patch early 7.5 high 3.2% 2005-05-02
CVE-2006-4285 EXP PHP remote file inclusion vulnerability in news.php in Fantastic News 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a UR… Patch early 7.5 high 3.2% 2006-08-22
CVE-2015-7381 EXP Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to exec… Patch early 7.5 high 3.2% 2015-09-28
← previous page 255 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt