peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,164 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

187,823 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-5147 EXP PHP remote file inclusion vulnerability in wamp_dir/setup/yesno.phtml in VAMP Webmail 2.0beta1 and earlier allows remote attackers to execute arbitrar… Patch early 7.5 high 3.2% 2006-10-05
CVE-2006-5401 EXP PHP remote file inclusion vulnerability in template/barnraiser_01/p_new_password.tpl.php in AROUNDMe 0.5.2 and earlier allows remote attackers to exec… Patch early 7.5 high 3.2% 2006-10-18
CVE-2006-5522 EXP Multiple PHP remote file inclusion vulnerabilities in Johannes Erdfelt Kawf 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 3.2% 2006-10-26
CVE-2006-5523 EXP PHP remote file inclusion vulnerability in common.php in EZ-Ticket 0.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the ezt_ro… Patch early 7.5 high 3.2% 2006-10-26
CVE-2006-5562 EXP PHP remote file inclusion vulnerability in include/database.php in SourceForge (aka alexandria) 1.0.4 allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 3.2% 2006-10-27
CVE-2006-5766 EXP PHP remote file inclusion vulnerability in volume.php in Article System 0.6 allows remote attackers to execute arbitrary PHP code via a URL in the con… Patch early 7.5 high 3.2% 2006-11-06
CVE-2006-4044 EXP PHP remote file inclusion vulnerability in Beautifier/Core.php in Brad Fears phpCodeCabinet 0.5 and earlier allows remote attackers to execute arbitra… Patch early 7.5 high 3.2% 2006-08-09
CVE-2006-4077 EXP PHP remote file inclusion vulnerability in CheckUpload.php in Vincenzo Valvano Comet WebFileManager (CWFM) 0.9.1, and possibly earlier, allows remote… Patch early 7.5 high 3.2% 2006-08-11
CVE-2006-4277 EXP Multiple PHP remote file inclusion vulnerabilities in Tutti Nova 1.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 3.2% 2006-08-21
CVE-2006-3069 EXP PHP remote file inclusion vulnerability in DoubleSpeak 0.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 3.2% 2006-06-19
CVE-2000-0429 EXP A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands. Patch early 7.5 high 3.2% 2000-04-27
CVE-2007-5890 EXP Directory traversal vulnerability in index.php in easyGB 2.1.1 allows remote attackers to include arbitrary files via the DatabaseType parameter. NOT… Patch early 10.0 high 3.2% 2007-11-08
CVE-2018-12055 EXP Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.php, faq.php, about.php, photo_g… Patch early 9.8 critical 3.2% 2018-06-08
CVE-2013-6875 EXP SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute… Patch early 7.5 high 3.2% 2013-11-26
CVE-2006-4311 EXP PHP remote file inclusion vulnerability in Sonium Enterprise Adressbook 0.2 allows remote attackers to execute arbitrary PHP code via the folder param… Patch early 7.5 high 3.2% 2006-08-23
CVE-2006-0123 EXP Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter in index.p… Patch early 7.5 high 3.2% 2006-01-09
CVE-2006-7185 EXP PHP remote file inclusion vulnerability in includes/user_standard.php in CMSmelborp Beta allows remote attackers to execute arbitrary PHP code via a U… Patch early 9.3 high 3.2% 2007-03-30
CVE-2006-5458 EXP PHP remote file inclusion vulnerability in common.php in Hinton Design phpht Topsites allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 3.2% 2006-10-23
CVE-2017-15645 EXP CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary commands… Patch early 8.8 high 3.2% 2017-10-19
CVE-1999-0899 EXP The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an… Patch early 7.2 high 3.2% 1999-11-04
CVE-2006-0757 EXP Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid pa… Patch early 7.5 high 3.2% 2006-02-18
CVE-2007-4527 EXP Unrestricted file upload vulnerability in phUploader.php in phphq.Net phUploader 1.2 allows remote attackers to upload and execute arbitrary code via… Patch early 7.5 high 3.2% 2007-08-25
CVE-2003-1318 EXP Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a different vuln… Patch early 7.8 high 3.2% 2003-12-31
CVE-2006-1573 EXP PHP remote file inclusion vulnerability in index.php in MediaSlash Gallery allows remote attackers to execute arbitrary PHP code via a URL in the rub… Patch early 7.5 high 3.2% 2006-04-01
CVE-2006-4073 EXP Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbitrary PHP code via a URL in th… Patch early 7.5 high 3.2% 2006-08-11
CVE-2006-4207 EXP Multiple PHP remote file inclusion vulnerabilities in Bob Jewell Discloser 0.0.4 and earlier allow remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 3.2% 2006-08-17
CVE-2006-4282 EXP PHP remote file inclusion vulnerability in MamboLogin.php in the MamboWiki component (com_mambowiki) 0.9.6 and earlier for Mambo and Joomla! allows re… Patch early 7.5 high 3.2% 2006-08-22
CVE-2006-4348 EXP PHP remote file inclusion vulnerability in config.kochsuite.php in the Kochsuite (com_kochsuite) 0.9.4 component for Mambo and Joomla! allows remote a… Patch early 7.5 high 3.2% 2006-08-24
CVE-2006-4063 EXP Multiple PHP remote file inclusion vulnerabilities in Csaba Godor SAPID Blog Beta 2 and earlier allow remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 3.2% 2006-08-10
CVE-2014-1618 EXP Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2… Patch early 7.5 high 3.2% 2014-01-21
← previous page 310 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt