peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,240 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

150,786 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-0975 EXP PHP remote file inclusion vulnerability in external.php in PHPCityPortal allows remote attackers to execute arbitrary PHP code via a URL in the url pa… Patch early 7.5 high 3% 2010-03-16
CVE-2010-1114 EXP Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to execute arbitrary PHP code via a U… Patch early 7.5 high 3% 2010-03-25
CVE-2008-5920 EXP The create_anchors function in utils.inc in WebSVN 1.x allows remote attackers to execute arbitrary PHP code via a crafted username that is processed… Patch early 7.5 high 3% 2009-01-21
CVE-2008-1635 EXP Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remote attackers to include and ex… Patch early 7.5 high 3% 2008-04-02
CVE-2007-2324 EXP Directory traversal vulnerability in file.php in JulmaCMS 1.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter… Patch early 7.8 high 3% 2007-04-27
CVE-2005-3005 EXP Helpdesk Software Hesk allows remote attackers to bypass authentication for (1) admin.php and (2) admin_main.php by modifying the PHPSESSID session ID… Patch early 7.5 high 3% 2005-09-21
CVE-2008-4427 EXP changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows rem… Patch early 7.5 high 3% 2008-10-03
CVE-2018-8134 EXP An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulner… Patch early 7.0 high 3% 2018-05-09
CVE-2010-4234 EXP The web server on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to c… Patch early 7.8 high 3% 2010-11-17
CVE-2017-6411 EXP Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any pa… Patch early 8.8 high 3% 2017-03-06
CVE-2007-5050 EXP Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot d… Patch early 7.5 high 3% 2007-09-24
CVE-2007-5069 EXP Directory traversal vulnerability in data/compatible.php in the Nuke Mobile Entertainment 1 addon for PHP-Nuke allows remote attackers to include and… Patch early 7.5 high 3% 2007-09-24
CVE-2007-2326 EXP Multiple PHP remote file inclusion vulnerabilities in HYIP Manager Pro allow remote attackers to execute arbitrary PHP code via a URL in the plugin_fi… Patch early 7.5 high 3% 2007-04-27
CVE-2004-1693 EXP PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifying the mo… Patch early 7.5 high 3% 2004-09-18
CVE-2004-1820 EXP PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitra… Patch early 7.5 high 3% 2004-03-15
CVE-2007-5845 EXP Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include and execute arbitrary local file… Patch early 7.5 high 3% 2007-11-06
CVE-2009-4753 EXP Multiple buffer overflows in the FTP server on the Addonics NAS Adapter NASU2FW41 with loader 1.17 allow remote attackers to cause a denial of service… Patch early 7.1 high 3% 2010-03-29
CVE-2019-6249 EXP An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_inf… Patch early 8.8 high 3% 2019-01-13
CVE-2024-39304 EXP ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due… Patch early 8.8 high 3% 2024-07-26
CVE-2013-0135 EXP Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1)… Patch early 7.5 high 3% 2013-04-09
CVE-2005-1005 EXP ProfitCode PayProCart 3.0 allows remote attackers to bypass authentication and gain administrative privileges to the admin control panel, as demonstra… Patch early 7.5 high 3% 2005-05-02
CVE-2019-6710 EXP Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF. Patch early 8.8 high 3% 2019-03-07
CVE-2006-2794 EXP Hesabim.asp in ASPSitem 2.0 and earlier allows remote attackers to read private messages of other users via a modified id parameter. Patch early 7.8 high 3% 2006-06-03
CVE-2015-4630 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x bef… Patch early 8.0 high 3% 2018-10-18
CVE-2007-0389 EXP Directory traversal vulnerability in ArsDigita Community System (ACS) 3.4.10 and earlier, and ArsDigita Community Education Solution (ACES) 1.1, allow… Patch early 7.8 high 3% 2007-01-19
CVE-2007-5820 EXP Directory traversal vulnerability in index.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers to include and execute arbitrary local files… Patch early 9.3 high 3% 2007-11-05
CVE-2008-4425 EXP Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to delete arbitrary fil… Patch early 8.8 high 3% 2008-10-03
CVE-2005-4657 EXP Ocean12 Calendar Manager Pro 1.01 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to /admin/vie… Patch early 7.5 high 3% 2005-12-31
CVE-2006-2295 EXP Directory traversal vulnerability in Dynamic Galerie 1.0 allows remote attackers to access arbitrary files via an absolute path in the pfad parameter… Patch early 7.5 high 3% 2006-05-10
CVE-2008-1992 EXP Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3) default_mail_jmail.asp, which… Patch early 7.5 high 3% 2008-04-27
← previous page 263 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt