peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,879 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

187,676 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2026-44262 EXP Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints are publicly accessible and vali… Patch early 9.4 critical 3.9% 2026-05-12
CVE-2002-2113 EXP search.cgi in AGH HTMLsearch 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the template parameter. Patch early 7.5 high 3.9% 2002-12-31
CVE-2001-0985 EXP shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter… Patch early 7.5 high 3.9% 2001-09-08
CVE-2016-1749 EXP IOUSBFamily in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corru… Patch early 7.8 high 3.9% 2016-03-24
CVE-2008-5868 EXP Stack-based buffer overflow in IntelliTamper 2.07 and 2.08 allows user-assisted attackers to execute arbitrary code via a long ProxyLogin value in a c… Patch early 9.3 high 3.9% 2009-01-08
CVE-2017-12763 EXP An unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privileges by gaining access to loca… Patch early 8.8 high 3.9% 2017-08-29
CVE-2008-2638 EXP Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message p… Patch early 10.0 high 3.9% 2008-06-10
CVE-2011-1939 EXP SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction P… Patch early 9.8 critical 3.9% 2019-11-26
CVE-2009-1779 EXP PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 3.9% 2009-05-22
CVE-1999-1112 EXP Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image type in a Phot… Patch early 7.5 high 3.8% 1999-11-09
CVE-2005-4554 EXP Multiple SQL injection vulnerabilities in DEV web management system 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (… Patch early 7.5 high 3.8% 2005-12-28
CVE-2008-2480 EXP PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers to execute arbitrary PHP code v… Patch early 10.0 high 3.8% 2008-05-28
CVE-2006-5068 EXP PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.1 and earlier allows remote at… Patch early 7.5 high 3.8% 2006-09-28
CVE-2006-3690 EXP Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 3.8% 2006-07-21
CVE-2006-2843 EXP PHP remote file inclusion vulnerability in Redaxo 2.7.4 allows remote attackers to execute arbitrary PHP code via a URL in the (1) REX[INCLUDE_PATH] p… Patch early 7.5 high 3.8% 2006-06-06
CVE-2006-2844 EXP Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDE_PAT… Patch early 7.5 high 3.8% 2006-06-06
CVE-2006-2845 EXP PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDE_PAT… Patch early 7.5 high 3.8% 2006-06-06
CVE-2007-6538 EXP SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL… Patch early 7.5 high 3.8% 2007-12-27
CVE-2023-33592 EXP Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/con… Patch early 9.8 critical 3.8% 2023-06-28
CVE-2006-0959 EXP SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote attackers to execute arbitrary… Patch early 7.5 high 3.8% 2006-03-02
CVE-2020-35151 EXP The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection. Patch early 8.8 high 3.8% 2020-12-21
CVE-2006-6360 EXP PHP remote file inclusion vulnerability in activate.php in PHP Upload Center 2.0 allows remote attackers to execute arbitrary PHP code via a URL in th… Patch early 7.5 high 3.8% 2006-12-07
CVE-2012-5897 EXP The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly impleme… Patch early 9.3 high 3.8% 2012-11-17
CVE-2008-4999 EXP Nortel Networks UNIStim IP Phone 0604DAS allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE:… Patch early 7.8 high 3.8% 2008-11-07
CVE-2007-2496 EXP The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1)… Patch early 7.8 high 3.8% 2007-05-04
CVE-2007-0202 EXP SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute ar… Patch early 7.5 high 3.8% 2007-01-11
CVE-2001-0274 EXP kicq IRC client 1.0.0, and possibly later versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. Patch early 7.5 high 3.8% 2001-05-03
CVE-2022-4681 EXP The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action a… Patch early 9.8 critical 3.8% 2023-02-06
CVE-2024-31777 EXP File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoin… Patch early 9.8 critical 3.8% 2024-06-13
CVE-2006-7173 EXP Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP code via a… Patch early 10.0 high 3.8% 2007-03-20
← previous page 289 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt