peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,164 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

187,823 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-2524 EXP Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation lev… Patch early 7.2 high 3.2% 2015-09-09
CVE-2006-5629 EXP Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the Fo… Patch early 7.5 high 3.2% 2006-10-31
CVE-2004-1650 EXP D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the IP address of the camera via a… Patch early 7.5 high 3.2% 2004-08-31
CVE-2005-4226 EXP Multiple "potential" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute arbitrary SQL commands via (1)… Patch early 7.5 high 3.2% 2005-12-14
CVE-2005-4427 EXP Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to… Patch early 7.5 high 3.2% 2005-12-20
CVE-2007-0568 EXP PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execute arbitrary PHP code via a UR… Patch early 7.5 high 3.2% 2007-01-30
CVE-2007-0581 EXP PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbitrary PHP code via a URL in th… Patch early 7.5 high 3.2% 2007-01-30
CVE-2007-1133 EXP PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_fuss para… Patch early 7.5 high 3.2% 2007-02-27
CVE-2007-1162 EXP A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a… Patch early 7.8 high 3.2% 2007-03-02
CVE-2007-1294 EXP A certain ActiveX control in the DivXBrowserPlugin (npdivx32.dll) in DivX Web Player, as distributed with DivX Player 1.3.0, allows remote attackers t… Patch early 7.8 high 3.2% 2007-03-07
CVE-2007-5440 EXP Multiple PHP remote file inclusion vulnerabilities in CRS Manager allow remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT… Patch early 7.5 high 3.2% 2007-10-14
CVE-2024-42471 EXP actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to… Patch early 7.3 high 3.2% 2024-09-02
CVE-2021-24174 EXP The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as… Patch early 8.1 high 3.2% 2021-04-05
CVE-2007-4806 EXP PHP remote file inclusion vulnerability in modules/Discipline/CategoryBreakdownTime.php in Focus/SIS 1.0 allows remote attackers to execute arbitrary… Patch early 7.5 high 3.2% 2007-09-11
CVE-2007-4807 EXP Multiple PHP remote file inclusion vulnerabilities in Focus/SIS 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the staticpath p… Patch early 7.5 high 3.2% 2007-09-11
CVE-2000-0798 EXP The truncate function in IRIX 6.x does not properly check for privileges when the file is in the xfs file system, which allows local users to delete t… Patch early 10.0 high 3.2% 2000-10-20
CVE-2018-13045 EXP SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands v… Patch early 9.8 critical 3.2% 2019-01-02
CVE-2018-17376 EXP SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter. Patch early 9.8 critical 3.2% 2018-09-28
CVE-2018-17377 EXP SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter. Patch early 9.8 critical 3.2% 2018-09-28
CVE-2018-17382 EXP SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter. Patch early 9.8 critical 3.2% 2018-09-28
CVE-2018-17383 EXP SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter. Patch early 9.8 critical 3.2% 2018-09-28
CVE-2018-17385 EXP SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter. Patch early 9.8 critical 3.2% 2018-09-28
CVE-2018-17391 EXP SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter. Patch early 9.8 critical 3.2% 2018-09-28
CVE-2018-17394 EXP SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter. Patch early 9.8 critical 3.2% 2018-09-28
CVE-2018-17397 EXP SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter. Patch early 9.8 critical 3.2% 2018-09-28
CVE-2018-18763 EXP SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection. Patch early 9.8 critical 3.2% 2018-11-16
CVE-2018-18795 EXP School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter. Patch early 9.8 critical 3.2% 2018-11-16
CVE-2018-18798 EXP Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.ph… Patch early 9.8 critical 3.2% 2019-03-21
CVE-2018-18800 EXP The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=rooms&q=[SQL], or admin/login.… Patch early 9.8 critical 3.2% 2019-05-14
CVE-2018-18801 EXP The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=[SQL]. Patch early 9.8 critical 3.2% 2018-11-16
← previous page 311 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt