peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,932 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

208,100 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-15978 EXP AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter. Patch early 9.8 critical 2.7% 2017-10-31
CVE-2017-15979 EXP Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter. Patch early 9.8 critical 2.7% 2017-10-31
CVE-2017-15980 EXP US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter. Patch early 9.8 critical 2.7% 2017-10-31
CVE-2017-15983 EXP MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. Patch early 9.8 critical 2.7% 2017-10-31
CVE-2017-15984 EXP Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php. Patch early 9.8 critical 2.7% 2017-10-31
CVE-2017-15985 EXP Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter. Patch early 9.8 critical 2.7% 2017-10-31
CVE-2017-15986 EXP CPA Lead Reward Script allows SQL Injection via the username parameter. Patch early 9.8 critical 2.7% 2017-10-31
CVE-2017-15988 EXP Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525. Patch early 9.8 critical 2.7% 2017-10-31
CVE-2017-15989 EXP Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action. Patch early 9.8 critical 2.7% 2017-10-31
CVE-2017-15991 EXP Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter… Patch early 9.8 critical 2.7% 2017-10-31
CVE-2017-15992 EXP Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php. Patch early 9.8 critical 2.7% 2017-10-31
CVE-2017-15993 EXP Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter. Patch early 9.8 critical 2.7% 2017-10-31
CVE-2026-26335 EXP Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web application and stored in C:\\Pro… Patch early 9.8 critical 2.7% 2026-02-13
CVE-2006-5016 EXP Unrestricted file upload vulnerability in admin/x_image.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, allows remote attackers to uplo… Patch early 5.0 medium 2.7% 2006-09-27
CVE-2007-1516 EXP PHP remote file inclusion vulnerability in functions/update.php in Cicoandcico CcMail 1.0 allows remote attackers to execute arbitrary PHP code via a… Patch early 6.8 medium 2.7% 2007-03-20
CVE-2007-1907 EXP PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attackers to execute arbitrary PHP… Patch early 6.8 medium 2.7% 2007-04-10
CVE-2008-3368 EXP PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to exe… Patch early 6.5 medium 2.7% 2008-07-30
CVE-2009-0673 EXP Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.30 allows remote authenticated… Patch early 6.5 medium 2.7% 2009-02-22
CVE-2014-8674 EXP Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and mb… Patch early 5.4 medium 2.6% 2020-01-06
CVE-2002-2351 EXP Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with names containing a trailing ".… Patch early 6.4 medium 2.6% 2002-12-31
CVE-2014-9236 EXP Cross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allows remote attackers to injec… Patch early 4.3 medium 2.6% 2014-12-03
CVE-2011-1872 EXP Hyper-V in Microsoft Windows Server 2008 Gold, SP2, R2, and R2 SP1 allows guest OS users to cause a denial of service (host OS infinite loop) via malf… Patch early 4.7 medium 2.6% 2011-06-16
CVE-2016-6851 EXP An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX Guard guest reader web applicat… Patch early 6.1 medium 2.6% 2016-12-15
CVE-2013-6128 EXP The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict SaveTo… Patch early 5.8 medium 2.6% 2013-10-25
CVE-2007-3535 EXP Multiple directory traversal vulnerabilities in GL-SH Deaf Forum 6.4.4 and earlier allow remote attackers to include and execute arbitrary local files… Patch early 6.4 medium 2.6% 2007-07-03
CVE-2005-0936 EXP Cross-site scripting vulnerability in products1h.php in ESMI PayPal Storefront allows remote attackers to inject arbitrary web script or HTML via the… Patch early 5.0 medium 2.6% 2005-05-02
CVE-2006-2608 EXP artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute a… Patch early 5.1 medium 2.6% 2006-05-26
CVE-2014-4162 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote attackers to hijack the authentic… Patch early 6.8 medium 2.6% 2014-06-16
CVE-2014-7281 EXP Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hija… Patch early 6.8 medium 2.6% 2014-10-23
CVE-2009-4224 EXP Multiple PHP remote file inclusion vulnerabilities in SweetRice 0.5.4, 0.5.3, and earlier allow remote attackers to execute arbitrary PHP code via a U… Patch early 6.8 medium 2.6% 2009-12-07
← previous page 265 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt