peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,746 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

187,619 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-1423 EXP Multiple PHP remote file inclusion vulnerabilities in WORK system e-commerce 3.0.5 and earlier allow remote attackers to execute arbitrary PHP code vi… Patch early 9.3 high 4.1% 2007-03-13
CVE-2008-3156 EXP The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CA… Patch early 9.3 high 4.1% 2008-07-11
CVE-2005-3879 EXP Multiple SQL injection vulnerabilities in Softbiz Resource Repository Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 4.1% 2005-11-29
CVE-2005-0737 EXP Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode. Patch early 7.5 high 4.1% 2005-05-02
CVE-2017-9834 EXP SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the watup… Patch early 9.8 critical 4.1% 2017-09-07
CVE-2019-6205 EXP A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A mal… Patch early 7.8 high 4.1% 2019-03-05
CVE-2014-9613 EXP Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) login param… Patch early 9.8 critical 4.1% 2020-02-19
CVE-2007-1483 EXP Multiple PHP remote file inclusion vulnerabilities in WebCalendar 0.9.45 allow remote attackers to execute arbitrary PHP code via a URL in the include… Patch early 7.5 high 4.1% 2007-03-16
CVE-2006-2731 EXP Multiple SQL injection vulnerabilities in Enigma Haber 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id paramet… Patch early 7.5 high 4.1% 2006-06-01
CVE-2002-2309 EXP php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via… Patch early 7.8 high 4.1% 2002-12-31
CVE-2006-2807 EXP ASPwebSoft Speedy Asp Discussion Forum allows remote attackers to change the password of any account via a modified account id and possibly arbitrary… Patch early 10.0 high 4.1% 2006-06-05
CVE-2018-10188 EXP phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.… Patch early 8.8 high 4.1% 2018-04-19
CVE-2015-7568 EXP SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known us… Patch early 9.8 critical 4.1% 2017-04-24
CVE-2020-13118 EXP An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter communi… Patch early 9.8 critical 4.1% 2020-05-16
CVE-2022-27412 EXP Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request. Patch early 9.8 critical 4.1% 2022-05-09
CVE-2024-25734 EXP An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is enter… Patch early 7.5 high 4.1% 2024-03-27
CVE-2013-1803 EXP Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) orderby param… Patch early 7.5 high 4% 2014-05-05
CVE-2007-0680 EXP PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and earlier allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 4% 2007-02-03
CVE-2008-6834 EXP Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.01 and 3.01a allow remote attackers to include and execute arbitrary local files via… Patch early 10.0 high 4% 2009-06-22
CVE-2008-1275 EXP Multiple unspecified vulnerabilities in the SMTP service in MailEnable Standard Edition 1.x, Professional Edition 3.x and earlier, and Enterprise Edit… Patch early 7.8 high 4% 2008-03-10
CVE-2003-1097 EXP Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option. Patch early 7.2 high 4% 2003-12-31
CVE-2006-0087 EXP SQL injection vulnerability in (1) pages.php and (2) detail.php in Lizard Cart CMS 1.04 allows remote attackers to execute arbitrary SQL commands via… Patch early 7.5 high 4% 2006-01-05
CVE-2009-4676 EXP Stack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute arbitrary code via a long titl… Patch early 9.3 high 4% 2010-03-05
CVE-2013-2784 EXP Triangle Research International (aka Tri) Nano-10 PLC devices with firmware before r81 use an incorrect algorithm for bounds checking of data in Modbu… Patch early 7.8 high 4% 2013-07-10
CVE-2003-0306 EXP Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClass… Patch early 7.2 high 4% 2003-06-09
CVE-2006-6568 EXP Directory traversal vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to include… Patch early 10.0 high 4% 2006-12-15
CVE-2006-7131 EXP PHP remote file inclusion vulnerability in extras/mt.php in Jinzora 2.6 allows remote attackers to execute arbitrary PHP code via the web_root paramet… Patch early 10.0 high 4% 2007-03-06
CVE-2007-2493 EXP PHP remote file inclusion vulnerability in faq.php in the FAQ & RULES 2.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary P… Patch early 10.0 high 4% 2007-05-04
CVE-2005-3682 EXP Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (1) the AuthID parameter in For… Patch early 7.5 high 4% 2005-11-18
CVE-2002-0250 EXP Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized users to bypass… Patch early 7.5 high 4% 2002-05-29
← previous page 285 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt