peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,237 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

150,786 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-2951 EXP Directory traversal vulnerability in security.inc.php in AzDGDatingLite 2.1.3, and possibly earlier versions, allows remote attackers to execute arbit… Patch early 7.5 high 3.1% 2005-09-16
CVE-2008-2836 EXP PHP remote file inclusion vulnerability in send_reminders.php in WebCalendar 1.0.4 allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 3.1% 2008-06-24
CVE-2008-2876 EXP Directory traversal vulnerability in index.php in mUnky 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot)… Patch early 7.5 high 3.1% 2008-06-26
CVE-2005-3058 EXP Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HT… Patch early 7.5 high 3.1% 2005-12-31
CVE-2018-8817 EXP Wampserver before 3.1.3 has CSRF in add_vhost.php. Patch early 8.8 high 3.1% 2018-03-25
CVE-2018-4435 EXP A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5… Patch early 7.8 high 3.1% 2019-04-03
CVE-2017-7446 EXP HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges. Patch early 8.8 high 3.1% 2017-04-05
CVE-2003-1252 EXP register.php in S8Forum 3.0 allows remote attackers to execute arbitrary PHP commands by creating a user whose name ends in a .php extension and enter… Patch early 7.5 high 3.1% 2003-12-31
CVE-2007-1586 EXP ZynOS 3.40 allows remote attackers to cause a denial of service (link restart) by sending a request for the name \M via the SMB Mail Slot Protocol. Patch early 7.8 high 3.1% 2007-03-21
CVE-2018-6947 EXP An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2 and earlier al… Patch early 7.8 high 3.1% 2018-02-28
CVE-2007-2149 EXP Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier stores usernames and unencrypted passwords in (1) classes/vars.php and (2) classes/varstuff.p… Patch early 10.0 high 3.1% 2007-04-19
CVE-2023-24788 EXP NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/sales/customer_delivery.php. Patch early 8.8 high 3.1% 2023-03-23
CVE-2002-0142 EXP CGI handler in John Roy Pi3Web for Windows 2.0 beta 1 and 2 allows remote attackers to cause a denial of service (crash) via a series of requests whos… Patch early 7.5 high 3.1% 2002-03-25
CVE-2005-1959 EXP jammail.pl in jamchen JamMail 1.8 allows remote attackers to execute arbitrary commands via shell metacharacters in the mail parameter. Patch early 7.5 high 3.1% 2005-06-12
CVE-2007-3284 EXP corefoundation.dll in Apple Safari 3.0.1 (552.12.2) for Windows allows remote attackers to cause a denial of service (crash) via certain forms that tr… Patch early 7.8 high 3.1% 2007-06-19
CVE-2020-7991 EXP Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password. Patch early 8.8 high 3.1% 2020-01-26
CVE-2007-3636 EXP Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via unspecifi… Patch early 7.5 high 3.1% 2007-07-10
CVE-2006-0076 EXP PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter… Patch early 7.5 high 3.1% 2006-01-04
CVE-2012-4035 EXP The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the member_id and new_password pa… Patch early 7.5 high 3.1% 2012-08-12
CVE-2007-2857 EXP PHP remote file inclusion vulnerability in sample/xls2mysql in ABC Excel Parser Pro 4.0 allows remote attackers to execute arbitrary PHP code via a UR… Patch early 7.5 high 3.1% 2007-05-24
CVE-2002-0931 EXP Cross-site scripting vulnerabilities in MyHelpDesk 20020509, and possibly other versions, allows remote attackers to execute script as other users via… Patch early 7.5 high 3.1% 2002-10-04
CVE-2003-0121 EXP Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field,… Patch early 7.5 high 3.1% 2003-03-18
CVE-2018-8411 EXP An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windo… Patch early 7.8 high 3.1% 2018-10-10
CVE-2008-6364 EXP SQL injection vulnerability in logon_process.jsp in Ad Server Solutions Banner Exchange Solution Java allows remote attackers to execute arbitrary SQL… Patch early 7.5 high 3.1% 2009-03-02
CVE-2006-0478 EXP CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files, via a direct request to files… Patch early 7.5 high 3.1% 2006-01-31
CVE-2008-1327 EXP Gallarific does not require authentication for (1) users.php and (2) index.php, which allows remote attackers to add and edit tasks via a direct reque… Patch early 7.5 high 3.1% 2008-03-13
CVE-2005-2483 EXP Eval injection vulnerability in Karrigell before 2.1.8 allows remote attackers to execute arbitrary Python code via modified arguments to a Karrigell… Patch early 7.5 high 3.1% 2005-08-07
CVE-2004-1881 EXP SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via t… Patch early 7.5 high 3.1% 2004-12-31
CVE-2007-2726 EXP BitsCast 0.13.0 allows remote attackers to cause a denial of service (application crash) via an RSS 2.0 feed item with certain invalid strings in a pu… Patch early 7.8 high 3.1% 2007-05-16
CVE-2007-1626 EXP PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP code via a UR… Patch early 9.3 high 3.1% 2007-03-23
← previous page 260 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt