peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,370 CVEs 1,739 on KEV 17,299 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

150,842 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-3639 EXP PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to access or include arbitrary files… Patch early 7.5 high 2.8% 2005-11-16
CVE-2023-33137 EXP Microsoft Excel Remote Code Execution Vulnerability Patch early 7.8 high 2.7% 2023-06-14
CVE-1999-0149 EXP The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack. Patch early 7.5 high 2.7% 1997-04-19
CVE-2000-0412 EXP The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files… Patch early 7.5 high 2.7% 1999-05-01
CVE-2006-5787 EXP admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to bypass authentication and modify user passwords via a direct request, poss… Patch early 7.5 high 2.7% 2006-11-07
CVE-2017-5264 EXP Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web appl… Patch early 8.8 high 2.7% 2017-12-14
CVE-2006-6569 EXP form.php in GenesisTrader 1.0 allows remote attackers to read source code for arbitrary files and obtain sensitive information via the (1) do and (2)… Patch early 7.8 high 2.7% 2006-12-15
CVE-2019-14346 EXP Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password. Patch early 8.8 high 2.7% 2019-08-06
CVE-2008-2293 EXP admin.php in Multi-Page Comment System (MPCS) 1.0 and 1.1 allows remote attackers to bypass authentication and gain privileges by setting the CommentS… Patch early 7.5 high 2.7% 2008-05-18
CVE-2009-0078 EXP The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 200… Patch early 7.2 high 2.7% 2009-04-15
CVE-2008-5937 EXP AyeView 2.20 allows user-assisted attackers to cause a denial of service (memory consumption or application crash) via a bitmap (aka .bmp) file with l… Patch early 7.8 high 2.7% 2009-01-22
CVE-2008-0490 EXP SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to execute arbitrary SQL command… Patch early 7.5 high 2.7% 2008-01-30
CVE-2008-0507 EXP SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the i… Patch early 7.5 high 2.7% 2008-01-31
CVE-2007-6237 EXP cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows… Patch early 9.0 high 2.7% 2007-12-04
CVE-2009-1647 EXP Heap-based buffer overflow in popcorn.exe in Ultrafunk Popcorn 1.87 allows remote POP3 servers to cause a denial of service (application crash) via a… Patch early 9.3 high 2.7% 2009-05-15
CVE-2005-2229 EXP Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access… Patch early 7.5 high 2.7% 2005-07-12
CVE-2005-0887 EXP Eval injection vulnerability in Double Choco Latte before 0.9.4.3 allows remote attackers to execute arbitrary PHP code via the menuAction variable in… Patch early 7.5 high 2.7% 2005-03-24
CVE-2006-0075 EXP Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (ma… Patch early 7.5 high 2.7% 2006-01-04
CVE-2008-1646 EXP SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands v… Patch early 7.5 high 2.7% 2008-04-02
CVE-2009-2122 EXP SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote attackers to execute arbitrary SQL… Patch early 7.5 high 2.7% 2009-06-19
CVE-2009-3913 EXP SQL injection vulnerability in summary.php in Xerox Fiery Webtools allows remote attackers to execute arbitrary SQL commands via the select parameter. Patch early 7.5 high 2.7% 2009-11-09
CVE-2008-6292 EXP Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) username_cookie to "admin," (2) right… Patch early 7.5 high 2.7% 2009-02-26
CVE-2008-6293 EXP admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie… Patch early 7.5 high 2.7% 2009-02-26
CVE-2008-6294 EXP admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie c… Patch early 7.5 high 2.7% 2009-02-26
CVE-2004-1722 EXP SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule p… Patch early 7.5 high 2.7% 2004-08-17
CVE-2007-1130 EXP PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 2.7% 2007-02-27
CVE-2007-1131 EXP PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fus… Patch early 7.5 high 2.7% 2007-02-27
CVE-2007-1219 EXP PHP remote file inclusion vulnerability in actions/del.php in Admin Phorum 3.3.1a allows remote attackers to execute arbitrary PHP code via a URL in t… Patch early 7.5 high 2.7% 2007-03-02
CVE-2006-5764 EXP PHP remote file inclusion vulnerability in contact.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 2.7% 2006-11-06
CVE-2007-0307 EXP PHP remote file inclusion vulnerability in include/common.php in Poplar Gedcom Viewer 2.0 and earlier allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 2.7% 2007-01-18
← previous page 274 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt