peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,355 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

187,891 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-2073 EXP Directory traversal vulnerability in include/global.inc.php in Virtual Design Studio vlbook 1.21 allows remote attackers to include and execute arbitr… Patch early 7.5 high 2.8% 2008-05-05
CVE-2018-0743 EXP Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows an elevation of privilege vul… Patch early 7.0 high 2.8% 2018-01-04
CVE-2017-1000405 EXP The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside the THP implementation. touch… Patch early 7.0 high 2.8% 2017-11-30
CVE-2007-3272 EXP Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the language para… Patch early 7.8 high 2.8% 2007-06-19
CVE-2002-1211 EXP Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE that points to code stored on… Patch early 7.5 high 2.8% 2002-11-12
CVE-2018-17428 EXP An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio parameter. Patch early 9.8 critical 2.8% 2018-10-03
CVE-2005-4275 EXP Scientific Atlanta DPX2100 Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and d… Patch early 7.8 high 2.8% 2005-12-16
CVE-2005-3503 EXP chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which a… Patch early 7.2 high 2.8% 2005-11-05
CVE-2007-0359 EXP PHP remote file inclusion vulnerability in frontpage.php in Uberghey CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 2.8% 2007-01-19
CVE-2007-0591 EXP PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attackers to execute arbitrary PHP c… Patch early 7.5 high 2.8% 2007-01-30
CVE-2007-0824 EXP PHP remote file inclusion vulnerability in inhalt.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dateie… Patch early 7.5 high 2.8% 2007-02-07
CVE-2007-0867 EXP PHP remote file inclusion vulnerability in classes/menu.php in Site-Assistant 0990 and earlier allows remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 2.8% 2007-02-09
CVE-2012-5849 EXP Multiple SQL injection vulnerabilities in ClipBucket 2.6 Revision 738 and earlier allow remote attackers to execute arbitrary SQL commands via the (1)… Patch early 7.5 high 2.8% 2015-05-14
CVE-2006-5232 EXP Multiple PHP remote file inclusion vulnerabilities in iSearch 2.16 allow remote attackers to execute arbitrary PHP code via a URL in the isearch_path… Patch early 7.5 high 2.8% 2006-10-11
CVE-2006-5831 EXP PHP remote file inclusion vulnerability in admin/code/index.php in All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to exe… Patch early 7.5 high 2.8% 2006-11-10
CVE-2006-5621 EXP PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PH… Patch early 7.5 high 2.8% 2006-10-31
CVE-2008-6799 EXP connection.php in FlashChat 5.0.8 allows remote attackers to bypass the role filter mechanism and gain administrative privileges by setting the s para… Patch early 7.5 high 2.8% 2009-05-07
CVE-2000-0100 EXP The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the progr… Patch early 7.2 high 2.8% 1999-12-29
CVE-2009-0460 EXP Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cooki… Patch early 7.5 high 2.8% 2009-02-10
CVE-2009-0461 EXP Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the… Patch early 7.5 high 2.8% 2009-02-10
CVE-2024-35540 EXP A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. Patch early 9.0 critical 2.8% 2024-08-20
CVE-2006-5587 EXP Multiple PHP remote file inclusion vulnerabilities in MDweb 1.3 and earlier (Mdweb132-postgres) allow remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 2.8% 2006-10-27
CVE-2008-1993 EXP Acidcat CMS 3.4.1 does not restrict access to the FCKEditor component, which allows remote attackers to upload arbitrary files. Patch early 7.5 high 2.8% 2008-04-27
CVE-2024-48839 EXP Improper Input Validation vulnerability allows Remote Code Execution.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02;… Patch early 10.0 critical 2.8% 2024-12-05
CVE-2007-4908 EXP Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .… Patch early 7.5 high 2.8% 2007-09-17
CVE-2008-1908 EXP Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot… Patch early 7.5 high 2.8% 2008-04-22
CVE-2004-1737 EXP SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via… Patch early 7.5 high 2.8% 2004-08-16
CVE-2024-46278 EXP Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console. Patch early 8.4 high 2.8% 2024-10-07
CVE-2006-3754 EXP PHP remote file inclusion vulnerability in Include/editor/rich_files/class.rich.php in FlushCMS 1.0.0-pre2 and earlier allows remote attackers to exec… Patch early 7.5 high 2.8% 2006-07-21
CVE-2006-4239 EXP PHP remote file inclusion vulnerability in include/urights.php in Outreach Project Tool (OPT) Max 1.2.6 and earlier allows remote attackers to execute… Patch early 7.5 high 2.8% 2006-08-21
← previous page 328 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt