peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,373 CVEs 1,739 on KEV 17,299 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

150,843 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-3760 EXP Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote at… Patch early 7.5 high 2.7% 2009-10-22
CVE-2007-2257 EXP PHP remote file inclusion vulnerability in subscp.php in Fully Modded phpBB2 allows remote attackers to execute arbitrary PHP code via a URL in the ph… Patch early 7.5 high 2.7% 2007-04-25
CVE-2017-1000366 EXP glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially r… Patch early 7.8 high 2.7% 2017-06-19
CVE-2006-5078 EXP PHP remote file inclusion vulnerability in view/general.php in Kristian Niemi Polaring 00.04.03 and earlier allows remote attackers to execute arbitra… Patch early 7.5 high 2.7% 2006-09-29
CVE-2006-5079 EXP PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary… Patch early 7.5 high 2.7% 2006-09-29
CVE-2005-1384 EXP Multiple SQL injection vulnerabilities in phpCoin 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to index… Patch early 7.5 high 2.7% 2005-05-03
CVE-2015-8356 EXP Multiple SQL injection vulnerabilities in the mcart.xls module 6.5.2 and earlier for Bitrix allow remote authenticated users to execute arbitrary SQL… Patch early 8.0 high 2.7% 2017-04-14
CVE-2017-9429 EXP SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitrary SQL commands via the id par… Patch early 8.8 high 2.7% 2017-06-13
CVE-2005-3978 EXP Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition… Patch early 7.5 high 2.7% 2005-12-03
CVE-2008-1624 EXP Directory traversal vulnerability in v2demo/page.php in Jshop Server 1.x through 2.x allows remote attackers to include and execute arbitrary local fi… Patch early 7.5 high 2.7% 2008-04-02
CVE-2018-9092 EXP There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password. Patch early 8.8 high 2.7% 2018-03-27
CVE-2006-6381 EXP Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files via a .. (dot dot) in the filena… Patch early 7.5 high 2.7% 2006-12-07
CVE-2008-4625 EXP SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arb… Patch early 7.5 high 2.7% 2008-10-21
CVE-2002-0731 EXP Cross-site scripting vulnerability in demonstration scripts for vqServer allows remote attackers to execute arbitrary script via a link that contains… Patch early 7.5 high 2.7% 2002-08-12
CVE-2002-2143 EXP The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to… Patch early 7.5 high 2.7% 2002-12-31
CVE-2006-1164 EXP Nodez 4.6.1.1 and earlier stores sensitive data in the list.gtdat file under the web document root with insufficient access control, which allows remo… Patch early 7.5 high 2.7% 2006-03-12
CVE-2004-2373 EXP The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allow remote attackers to use a sh… Patch early 7.5 high 2.7% 2004-12-31
CVE-2007-1215 EXP Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local u… Patch early 7.2 high 2.7% 2007-04-04
CVE-2007-0570 EXP PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News Script (AINS) 0.02b allows re… Patch early 7.5 high 2.7% 2007-01-30
CVE-2007-0679 EXP PHP remote file inclusion vulnerability in lang/leslangues.php in Nicolas Grandjean PHPMyRing 4.1.3b and earlier allows remote attackers to execute ar… Patch early 7.5 high 2.7% 2007-02-03
CVE-2007-1025 EXP PHP remote file inclusion vulnerability in inc/functions_inc.php in VS-Link-Partner 2.1 and earlier allows remote attackers to execute arbitrary PHP c… Patch early 7.5 high 2.7% 2007-02-21
CVE-2007-1299 EXP PHP remote file inclusion vulnerability in index.php in Mani Stats Reader 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 2.7% 2007-03-07
CVE-2007-0395 EXP PHP remote file inclusion vulnerability in libraries/grab_globals.lib.php in ComVironment 4.0 allows remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 2.7% 2007-01-19
CVE-2009-1282 EXP SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 2.7% 2009-04-09
CVE-2023-28311 EXP Microsoft Word Remote Code Execution Vulnerability Patch early 7.8 high 2.7% 2023-04-11
CVE-2006-6634 EXP Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote attackers to… Patch early 7.5 high 2.7% 2006-12-18
CVE-1999-1437 EXP ePerl 2.2.12 allows remote attackers to read arbitrary files and possibly execute certain commands by specifying a full pathname of the target file as… Patch early 7.5 high 2.7% 1998-07-07
CVE-2008-4752 EXP TlNews 2.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlNews_login cookie to admin. Patch early 7.5 high 2.7% 2008-10-27
CVE-2007-1148 EXP PHP remote file inclusion vulnerability in install/index.php in LoveCMS 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the ste… Patch early 7.5 high 2.7% 2007-03-02
CVE-2006-3951 EXP PHP remote file inclusion vulnerability in moodle.php in Mam-moodle alpha component (com_moodle) for Mambo allows remote attackers to execute arbitrar… Patch early 7.5 high 2.7% 2006-08-01
← previous page 275 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt