peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,169 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

150,786 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-5315 EXP PHP remote file inclusion vulnerability in main.php in registroTL allows remote attackers to execute arbitrary PHP code via an ftp:// URL in the page… Patch early 7.5 high 3.2% 2006-10-17
CVE-2006-5317 EXP PHP remote file inclusion vulnerability in index.php in eboli allows remote attackers to execute arbitrary PHP code via a URL in the contentSpecial pa… Patch early 7.5 high 3.2% 2006-10-17
CVE-2006-5521 EXP PHP remote file inclusion vulnerability in DNS/RR.php in Net_DNS 0.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in t… Patch early 7.5 high 3.2% 2006-10-26
CVE-2002-1898 EXP Terminal 1.3 in Apple Mac OS X 10.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a telnet:// link, which is execu… Patch early 7.2 high 3.2% 2002-12-31
CVE-2006-4061 EXP PHP remote file inclusion vulnerability in index.php in Thomas Pequet phpPrintAnalyzer 1.1, when register_globals is enabled, allows remote attackers… Patch early 7.5 high 3.2% 2006-08-10
CVE-2009-1781 EXP Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inject arbitrary PHP code into ph… Patch early 7.5 high 3.2% 2009-05-22
CVE-2007-1015 EXP SQL injection vulnerability in HaberDetay.asp in Aktueldownload Haber script allows remote attackers to execute arbitrary SQL commands via the id para… Patch early 10.0 high 3.2% 2007-02-21
CVE-2008-2884 EXP PHP remote file inclusion vulnerability in display.php in RSS-aggregator allows remote attackers to execute arbitrary PHP code via a URL in the path p… Patch early 9.3 high 3.2% 2008-06-27
CVE-2023-29849 EXP Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice, menuID, staffID, or itemqty… Patch early 8.8 high 3.2% 2023-04-24
CVE-2006-1771 EXP Directory traversal vulnerability in misc in pbcs.dll in SAXoTECH SAXoPRESS, aka Saxotech Online (formerly Publicus) allows remote attackers to read a… Patch early 7.5 high 3.2% 2006-04-13
CVE-2007-2541 EXP PHP remote file inclusion vulnerability in includes/ajax_listado.php in Versado CMS 1.07 allows remote attackers to execute arbitrary PHP code via a U… Patch early 7.5 high 3.2% 2007-05-09
CVE-2007-2544 EXP PHP remote file inclusion vulnerability in templates/default/tpl_message.php in PHP TopTree BBS 2.0.1a and earlier allows remote attackers to execute… Patch early 7.5 high 3.2% 2007-05-09
CVE-2007-2709 EXP PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 3.2% 2007-05-16
CVE-2006-5919 EXP PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2 allows remote attackers to ex… Patch early 7.5 high 3.2% 2006-11-15
CVE-2008-1982 EXP SQL injection vulnerability in ss_load.php in the Spreadsheet (wpSS) 0.6 and earlier plugin for WordPress allows remote attackers to execute arbitrary… Patch early 7.5 high 3.2% 2008-04-27
CVE-2009-3576 EXP Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table… Patch early 9.3 high 3.2% 2009-11-24
CVE-2008-1492 EXP Multiple directory traversal vulnerabilities in CoronaMatrix phpAddressBook 2.11 allow remote attackers to include and execute arbitrary local files v… Patch early 7.5 high 3.2% 2008-03-25
CVE-1999-0947 EXP AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via shell meta… Patch early 7.5 high 3.2% 1999-11-02
CVE-1999-1436 EXP Ray Chan WWW Authorization Gateway 0.1 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "user" parame… Patch early 7.5 high 3.2% 1998-07-08
CVE-2001-0614 EXP Carello E-Commerce 1.2.1 and earlier allows a remote attacker to gain additional privileges and execute arbitrary commands via a specially constructed… Patch early 7.5 high 3.2% 2001-08-22
CVE-2008-3384 EXP Multiple directory traversal vulnerabilities in help/help.php in Interact Learning Community Environment Interact 2.4.1 allow remote attackers to incl… Patch early 7.5 high 3.2% 2008-07-30
CVE-2006-5494 EXP Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allow remote a… Patch early 7.5 high 3.2% 2006-10-25
CVE-2006-5612 EXP PHP remote file inclusion vulnerability in aide.php3 (aka aide.php) in GestArt beta 1, when register_globals is enabled, allows remote attackers to ex… Patch early 7.5 high 3.2% 2006-10-31
CVE-2002-2306 EXP Sharman Networks KaZaA Media Desktop 1.7.1 allows remote attackers to cause a denial of service (CPU consumption) by sending several large messages. Patch early 7.8 high 3.2% 2002-12-31
CVE-2018-8208 EXP An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Brid… Patch early 7.0 high 3.2% 2018-06-14
CVE-2006-4423 EXP Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[_… Patch early 7.5 high 3.2% 2006-08-29
CVE-2019-14328 EXP The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section. Patch early 8.8 high 3.2% 2019-07-28
CVE-2006-6150 EXP PHP remote file inclusion vulnerability in memory/OWLMemoryProperty.php in OWLLib 1.0 allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 3.2% 2006-11-28
CVE-2008-0546 EXP Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL comman… Patch early 7.5 high 3.2% 2008-02-01
CVE-2006-0164 EXP phgstats.inc.php in phgstats before 0.5.1, if register_globals is enabled, allows remote attackers to include arbitrary files and execute arbitrary PH… Patch early 7.5 high 3.1% 2006-01-11
← previous page 257 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt