peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,955 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-1247 EXP SQL injection vulnerability in login.php in Acute Control Panel 1.0.0 allows remote attackers to execute arbitrary SQL commands via the username param… Patch early 7.5 high 13.7% 2009-04-06
CVE-2011-2443 EXP Multiple buffer overflows in Adobe Photoshop Elements 8.0 and earlier allow remote attackers to cause a denial of service (memory corruption and appli… Patch early 9.3 high 13.7% 2011-10-04
CVE-2003-0963 EXP Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9 and earlier allow remote HTTP servers to execute arbitrary code via l… Patch early 7.5 high 13.7% 2004-01-05
CVE-2017-8870 EXP Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file. Patch early 7.8 high 13.7% 2017-07-27
CVE-2007-3536 EXP Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers to execute arbitrary code via… Patch early 7.6 high 13.7% 2007-07-03
CVE-2008-3657 EXP The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of input… Patch early 7.5 high 13.7% 2008-08-13
CVE-2009-1759 EXP Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent) 3.3.2 and probably earlier, a… Patch early 9.3 high 13.7% 2009-05-22
CVE-2016-7998 EXP The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML fil… Patch early 8.8 high 13.6% 2017-01-18
CVE-2010-4254 EXP Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote a… Patch early 7.5 high 13.6% 2010-12-06
CVE-2012-3577 EXP Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to ex… Patch early 7.5 high 13.6% 2012-06-17
CVE-2025-50286 EXP A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct… Patch early 8.1 high 13.6% 2025-08-06
CVE-2022-30286 EXP pyscriptjs (aka PyScript Demonstrator) in PyScript through 2022-05-04 allows a remote user to read Python source code. Patch early 7.5 high 13.6% 2022-05-09
CVE-2010-3144 EXP Untrusted search path vulnerability in the Internet Connection Signup Wizard in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local user… Patch early 9.3 high 13.6% 2010-08-27
CVE-2010-3148 EXP Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the curr… Patch early 9.3 high 13.6% 2010-08-27
CVE-2024-11728 EXP The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter… Patch early 7.5 high 13.6% 2024-12-06
CVE-2007-5849 EXP Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute… Patch early 9.3 high 13.6% 2007-12-19
CVE-2019-7391 EXP ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF. Patch early 8.8 high 13.6% 2019-03-21
CVE-2002-0189 EXP Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that explo… Patch early 7.5 high 13.6% 2002-05-29
CVE-2002-0682 EXP Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /s… Patch early 7.5 high 13.6% 2002-07-23
CVE-2010-4711 EXP Double free vulnerability in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allows remote attackers to… Patch early 10.0 high 13.6% 2011-01-31
CVE-2012-4415 EXP Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of… Patch early 7.5 high 13.6% 2012-10-01
CVE-2004-0277 EXP Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via for… Patch early 10.0 high 13.6% 2004-11-23
CVE-2015-6589 EXP Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0… Patch early 8.8 high 13.6% 2020-02-13
CVE-2010-3149 EXP Untrusted search path vulnerability in Adobe Device Central CS5 3.0.0(376), 3.0.1.0 (3027), and probably other versions allows local users, and possib… Patch early 9.3 high 13.6% 2010-08-27
CVE-2010-3153 EXP Untrusted search path vulnerability in Adobe InDesign CS4 6.0, InDesign CS5 7.0.2 and earlier, Adobe InDesign Server CS5 7.0.2 and earlier, and Adobe… Patch early 9.3 high 13.6% 2010-08-27
CVE-2008-4310 EXP httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CP… Patch early 7.8 high 13.6% 2008-12-09
CVE-2004-2425 EXP Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and poss… Patch early 7.5 high 13.5% 2004-12-31
CVE-2007-1357 EXP The atalk_sum_skb function in AppleTalk for Linux kernel 2.6.x before 2.6.21, and possibly 2.4.x, allows remote attackers to cause a denial of service… Patch early 7.8 high 13.5% 2007-04-11
CVE-2007-1685 EXP Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a de… Patch early 10.0 high 13.5% 2007-06-08
CVE-2007-5467 EXP Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long… Patch early 10.0 high 13.5% 2007-10-15
← previous page 106 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt