peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,322 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

187,888 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-1821 EXP PHP remote file inclusion vulnerability in pdl_header.inc.php in PowerDownload 3.0.2 and 3.0.3 allows remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 2.9% 2005-06-01
CVE-2007-3587 EXP MyCMS 0.9.8 and earlier allows remote attackers to gain privileges via the admin cookie parameter, as demonstrated by a post to admin/settings.php tha… Patch early 7.5 high 2.9% 2007-07-05
CVE-2007-6508 EXP Directory traversal vulnerability in view.php in xeCMS 1.0 allows remote attackers to read arbitrary files via a ..%2F (dot dot slash) in the list par… Patch early 7.5 high 2.9% 2007-12-21
CVE-2009-2773 EXP PHP remote file inclusion vulnerability in home.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary PHP code via a URL in the p… Patch early 7.5 high 2.9% 2009-08-14
CVE-2007-1772 EXP The FTP service in HP JetDirect print servers allows remote attackers to cause a denial of service (engine crash) via a RETR command with a long pathn… Patch early 7.1 high 2.9% 2007-03-30
CVE-2008-7110 EXP Directory traversal vulnerability in the Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to upload files to a… Patch early 7.8 high 2.9% 2009-08-28
CVE-2006-5586 EXP The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in… Patch early 7.2 high 2.9% 2007-04-04
CVE-2006-5777 EXP Creasito E-Commerce Content Manager 1.3.08 allows remote attackers to bypass authentication and perform privileged functions via a non-empty finame pa… Patch early 7.5 high 2.9% 2006-11-07
CVE-2008-0719 EXP SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remote… Patch early 7.5 high 2.9% 2008-02-12
CVE-2002-0553 EXP Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the sc… Patch early 7.5 high 2.9% 2002-07-03
CVE-2002-0787 EXP Cross-site scripting vulnerabilities in iCon administrative web server for Critical Path inJoin Directory Server 4.0 allow remote attackers to execute… Patch early 7.5 high 2.9% 2002-08-12
CVE-2002-0949 EXP Telindus 1100 series ADSL router allows remote attackers to gain privileges to the device via a certain packet to UDP port 9833, which generates a rep… Patch early 7.5 high 2.9% 2002-10-04
CVE-2008-6195 EXP Directory traversal vulnerability in the PXE TFTP Service (PXEMTFTP.exe) in LANDesk Management Suite (LDMS) 8.80.1.1 and earlier allows remote attacke… Patch early 7.8 high 2.9% 2009-02-20
CVE-2007-6269 EXP Multiple SQL injection vulnerabilities in xlaabsolutenm.aspx in Absolute News Manager.NET 5.1 allow remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 2.9% 2007-12-07
CVE-2007-2370 EXP SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL comm… Patch early 7.5 high 2.9% 2007-04-30
CVE-2007-1801 EXP Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arbitrary local files via a .. (d… Patch early 7.5 high 2.9% 2007-04-02
CVE-2024-0399 EXP The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, l… Patch early 8.1 high 2.9% 2024-04-15
CVE-2019-1364 EXP An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k… Patch early 7.8 high 2.9% 2019-10-10
CVE-2006-3042 EXP Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) go_inf… Patch early 7.5 high 2.9% 2006-06-15
CVE-2006-0214 EXP Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupl… Patch early 7.5 high 2.9% 2006-01-15
CVE-2006-6526 EXP PHP remote file inclusion vulnerability in index.php in Gizzar 03162002 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 2.9% 2006-12-14
CVE-2006-6546 EXP PHP remote file inclusion vulnerability in inc/shows.inc.php in cutenews aj-fork (CN:AJ) 167f and earlier allows remote attackers to execute arbitrary… Patch early 7.5 high 2.9% 2006-12-14
CVE-2006-6553 EXP PHP remote file inclusion vulnerability in includes/newssuite_constants.php in the NewsSuite 1.03 module for mxBB allows remote attackers to execute a… Patch early 7.5 high 2.9% 2006-12-14
CVE-2006-6691 EXP Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 2.9% 2006-12-21
CVE-2006-6850 EXP PHP remote file inclusion vulnerability in include.php in the Roster Module (character_roster) in Shadowed Portal 5.7 allows remote attackers to execu… Patch early 7.5 high 2.9% 2006-12-31
CVE-2009-1050 EXP Bloginator 1A allows remote attackers to bypass authentication and gain administrative access by setting the identifyYourself cookie. Patch early 7.5 high 2.9% 2009-03-24
CVE-2010-3205 EXP PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the i… Patch early 7.5 high 2.9% 2010-09-03
CVE-2023-28293 EXP Windows Kernel Elevation of Privilege Vulnerability Patch early 7.8 high 2.9% 2023-04-11
CVE-2017-0411 EXP An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context… Patch early 7.8 high 2.9% 2017-02-08
CVE-2005-1200 EXP PHP remote file inclusion vulnerability in main_index.php in AZ Bulletin Board (AZbb) 1.0.07a through 1.0.07c allows remote attackers to execute arbit… Patch early 7.5 high 2.9% 2005-05-02
← previous page 326 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt