peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,121 CVEs 1,733 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-7945 EXP The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13… Patch early 7.5 high 9.4% 2017-08-18
CVE-2004-2631 EXP Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary P… Patch early 7.5 high 9.4% 2004-12-31
CVE-2007-0634 EXP Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system crash) via certain ICMP packe… Patch early 7.8 high 9.4% 2007-01-31
CVE-2018-16946 EXP LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log &… Patch early 7.5 high 9.3% 2018-09-12
CVE-2018-4306 EXP A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… Patch early 8.8 high 9.3% 2019-04-03
CVE-2018-4312 EXP A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… Patch early 8.8 high 9.3% 2019-04-03
CVE-2018-4317 EXP A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… Patch early 8.8 high 9.3% 2019-04-03
CVE-2018-4318 EXP A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… Patch early 8.8 high 9.3% 2019-04-03
CVE-2007-1014 EXP Stack-based buffer overflow in VicFTPS before 5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitr… Patch early 10.0 high 9.3% 2007-02-21
CVE-2007-4255 EXP Buffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a long first argument to the msql_… Patch early 7.5 high 9.3% 2007-08-08
CVE-2004-1988 EXP PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by… Patch early 7.5 high 9.3% 2004-04-30
CVE-2004-1989 EXP PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modif… Patch early 7.5 high 9.3% 2004-04-30
CVE-2005-4694 EXP Unspecified vulnerability in the www_add method in Asset.pm in Plain Black WebGUI 6.3.0 and other versions before 6.7.6 allows attackers to execute ar… Patch early 7.5 high 9.3% 2005-12-31
CVE-2004-1796 EXP PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header]… Patch early 7.5 high 9.3% 2004-12-31
CVE-2001-1002 EXP The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by… Patch early 7.5 high 9.3% 2001-08-31
CVE-2009-0641 EXP sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older… Patch early 9.3 high 9.3% 2009-02-20
CVE-2005-2108 EXP SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that… Patch early 7.5 high 9.3% 2005-07-05
CVE-2007-2540 EXP Multiple PHP remote file inclusion vulnerabilities in PMECMS 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the con… Patch early 7.5 high 9.3% 2007-05-09
CVE-2010-2004 EXP Stack-based buffer overflow in BS.Global BS.Player 2.51 Build 1022 Free, and possibly other versions, allows user-assisted remote attackers to execute… Patch early 9.3 high 9.3% 2010-05-20
CVE-2007-4391 EXP Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application cras… Patch early 9.3 high 9.3% 2007-08-17
CVE-2022-26149 EXP MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Upl… Patch early 7.2 high 9.3% 2022-02-26
CVE-2008-6922 EXP Multiple stack-based buffer overflows in CMailCOM.dll in CMailServer 5.4.6 allow remote attackers to execute arbitrary code via a long argument to the… Patch early 9.3 high 9.3% 2009-08-10
CVE-2019-14347 EXP Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/… Patch early 8.8 high 9.3% 2019-08-06
CVE-2007-5305 EXP Multiple PHP remote file inclusion vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) co… Patch early 7.5 high 9.3% 2007-10-09
CVE-2015-3704 EXP runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly drop privileges, which allows att… Patch early 9.3 high 9.3% 2015-07-03
CVE-2014-1631 EXP Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php. Patch early 7.5 high 9.3% 2018-01-31
CVE-2008-2910 EXP Buffer overflow in the DXTTextOutEffect ActiveX control (aka the Text-Effect DXT Filter), as distributed in TextOut.dll 6.0.18.1 and mvtextout.dll, in… Patch early 9.3 high 9.3% 2008-06-30
CVE-2009-0833 EXP Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute arbitrary code via a playlist… Patch early 9.3 high 9.3% 2009-03-05
CVE-2016-1328 EXP goform/WClientMACList on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long h_sortWireless parameter… Patch early 7.5 high 9.3% 2016-07-03
CVE-2016-1336 EXP goform/Docsis_system on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long LanguageSelect parameter,… Patch early 7.5 high 9.3% 2016-07-03
← previous page 136 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt