peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,891 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

187,689 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-1224 EXP Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChannel parame… Patch early 7.5 high 3.7% 2005-05-02
CVE-2005-1550 EXP easymsgb.pl in Easy Message Board allows remote attackers to execute arbitrary commands via shell metacharacters in the print parameter. Patch early 7.5 high 3.7% 2005-05-14
CVE-2005-1307 EXP The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the produ… Patch early 7.2 high 3.7% 2005-05-17
CVE-2026-49952 EXP Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain u… Patch early 9.1 critical 3.7% 2026-06-15
CVE-2006-1793 EXP Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) clas… Patch early 7.6 high 3.6% 2006-04-17
CVE-2007-0637 EXP Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local file… Patch early 7.5 high 3.6% 2007-01-31
CVE-2007-0702 EXP Multiple PHP remote file inclusion vulnerabilities in phpEventMan 1.0.2 allow remote attackers to execute arbitrary PHP code via a URL in the level pa… Patch early 7.5 high 3.6% 2007-02-04
CVE-2008-4439 EXP PHP remote file inclusion vulnerability in admin/bin/patch.php in MartinWood Datafeed Studio before 1.6.3 allows remote attackers to execute arbitrary… Patch early 10.0 high 3.6% 2008-10-03
CVE-2006-3692 EXP PHP remote file inclusion vulnerability in enduser/listmessenger.php in ListMessenger 0.9.3 allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 3.6% 2006-07-21
CVE-2007-3400 EXP The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.7, allows remote attackers to… Patch early 9.3 high 3.6% 2007-06-26
CVE-2009-0465 EXP The SaveDoc method in the All_In_The_Box.AllBox ActiveX control in ALL_IN_THE_BOX.OCX in Synactis ALL In-The-Box ActiveX 3 allows remote attackers to… Patch early 9.3 high 3.6% 2009-02-10
CVE-2002-2360 EXP The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary fi… Patch early 9.3 high 3.6% 2002-12-31
CVE-2007-0535 EXP Multiple eval injection vulnerabilities in Vote! Pro 4.0, and possibly earlier, allow remote attackers to execute arbitrary code via requests to unspe… Patch early 7.5 high 3.6% 2007-01-26
CVE-2007-2527 EXP Multiple PHP remote file inclusion vulnerabilities in DynamicPAD before 1.03.31 allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 3.6% 2007-05-08
CVE-2019-6214 EXP A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.… Patch early 8.6 high 3.6% 2019-03-05
CVE-2006-2137 EXP PHP remote file inclusion vulnerability in master.php in OpenPHPNuke and 2.3.3 earlier allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 3.6% 2006-05-02
CVE-2006-0944 EXP Archangel Weblog 0.90.02 allows remote attackers to bypass authentication by setting the ba_admin cookie to 1. Patch early 7.5 high 3.6% 2006-03-01
CVE-2007-6082 EXP Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary P… Patch early 9.3 high 3.6% 2007-11-22
CVE-2006-4267 EXP Multiple SQL injection vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) oid paramet… Patch early 7.5 high 3.6% 2006-08-21
CVE-2017-6979 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… Patch early 7.0 high 3.6% 2017-05-22
CVE-2013-5582 EXP Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass a… Patch early 7.8 high 3.6% 2020-02-11
CVE-2003-0842 EXP Stack-based buffer overflow in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode, a… Patch early 7.5 high 3.6% 2003-11-17
CVE-2006-7120 EXP PHP remote file inclusion vulnerability in lib/php/phphtmllib-2.5.4/examples/example6.php for maintain 3.0.0-RC2 allows remote attackers to execute ar… Patch early 10.0 high 3.6% 2007-03-06
CVE-2016-1000123 EXP Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla Patch early 9.8 critical 3.6% 2016-10-06
CVE-2006-3689 EXP PHP remote file inclusion vulnerability in user-func.php in Codeworks Gnomedia SubberZ[Lite] allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 3.6% 2006-07-21
CVE-2005-3157 EXP SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL commands via the msg_send paramete… Patch early 7.5 high 3.6% 2005-10-06
CVE-2006-2636 EXP newsadmin.asp in Katy Whitton NewsCMSLite allows remote attackers to bypass authentication and gain administrative access by setting the loggedIn cook… Patch early 7.5 high 3.6% 2006-05-30
CVE-2017-17619 EXP Laundry Booking Script 1.0 has SQL Injection via the /list city parameter. Patch early 9.8 critical 3.6% 2017-12-13
CVE-2017-17621 EXP Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI. Patch early 9.8 critical 3.6% 2017-12-13
CVE-2017-17622 EXP Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter. Patch early 9.8 critical 3.6% 2017-12-13
← previous page 295 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt