peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,185 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-2441 EXP RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes i… Patch early 8.5 high 8.5% 2012-04-28
CVE-2008-0151 EXP Heap-based buffer overflow in Foxit WAC Server 2.1.0.910, 2.0 Build 3503, and earlier allows remote attackers to cause a denial of service (crash) and… Patch early 10.0 high 8.5% 2008-01-09
CVE-2018-1038 EXP The Windows kernel in Windows 7 SP1 and Windows Server 2008 R2 SP1 allows an elevation of privilege vulnerability due to the way it handles objects in… Patch early 7.8 high 8.5% 2018-04-02
CVE-2017-9746 EXP The disassemble_bytes function in objdump.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application… Patch early 7.8 high 8.5% 2017-06-19
CVE-2017-9749 EXP The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer overflow and application cras… Patch early 7.8 high 8.5% 2017-06-19
CVE-2010-3313 EXP phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly… Patch early 7.5 high 8.5% 2010-09-22
CVE-2009-3710 EXP RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel, which allows remote attacker… Patch early 10.0 high 8.5% 2009-10-16
CVE-2018-20658 EXP The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD comman… Patch early 7.5 high 8.5% 2019-01-02
CVE-2006-4437 EXP Eval injection vulnerability in Tagger LE allows remote attackers to execute arbitrary PHP code via the query string in (1) tags.php, (2) sign.php, an… Patch early 7.5 high 8.5% 2006-09-14
CVE-2013-7392 EXP Gitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/. Patch early 7.5 high 8.5% 2014-07-22
CVE-2007-3701 EXP TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which might allow remote attackers to… Patch early 7.5 high 8.5% 2007-07-11
CVE-2017-14704 EXP Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remo… Patch early 8.8 high 8.5% 2017-09-26
CVE-2006-0549 EXP SQL injection vulnerability in the SYS.DBMS_METADATA_UTIL package in Oracle Database 10g, and possibly earlier versions, might allow remote attackers… Patch early 7.5 high 8.5% 2006-02-04
CVE-2017-2471 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. watchOS before 3.2 is affected. The is… Patch early 8.8 high 8.5% 2017-04-02
CVE-2017-1000499 EXP phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to… Patch early 8.8 high 8.5% 2018-01-03
CVE-2015-8566 EXP The Session package 1.x before 1.3.1 for Joomla! Framework allows remote attackers to execute arbitrary code via unspecified session values. Patch early 7.5 high 8.5% 2015-12-16
CVE-2007-5984 EXP classes/Url.php in Justin Hagstrom AutoIndex PHP Script before 2.2.4 allows remote attackers to cause a denial of service (CPU and memory consumption)… Patch early 7.8 high 8.5% 2007-11-15
CVE-2009-2110 EXP Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arb… Patch early 7.6 high 8.4% 2009-06-18
CVE-2006-0644 EXP Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 allow remote attackers to includ… Patch early 7.5 high 8.4% 2006-02-10
CVE-2015-7571 EXP Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploading a file with an executable ex… Patch early 7.8 high 8.4% 2017-08-07
CVE-2006-5820 EXP The LinkSBIcons method in the SuperBuddy ActiveX control (Sb.SuperBuddy.1) in America Online 9.0 Security Edition dereferences an arbitrary function p… Patch early 9.3 high 8.4% 2007-04-02
CVE-2006-4029 EXP Stack-based buffer overflow in sipd.dll in AGEphone 1.24 and 1.38.1 allows remote attackers to execute arbitrary code via a crafted UDP SIP packet. Patch early 7.5 high 8.4% 2006-08-09
CVE-2007-2271 EXP Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 9.4 high 8.4% 2007-04-25
CVE-2007-6332 EXP The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBC… Patch early 9.3 high 8.4% 2007-12-13
CVE-2000-0109 EXP The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily g… Patch early 10.0 high 8.4% 2000-01-31
CVE-2007-3934 EXP PHP remote file inclusion vulnerability in postscript/postscript.php in BBS E-Market allows remote attackers to execute arbitrary PHP code via a URL i… Patch early 7.5 high 8.4% 2007-07-21
CVE-2011-1249 EXP The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server… Patch early 7.2 high 8.4% 2011-06-16
CVE-2009-1236 EXP Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers… Patch early 10.0 high 8.4% 2009-04-02
CVE-2009-0680 EXP cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (device crash) via a crafted quer… Patch early 7.8 high 8.4% 2009-02-22
CVE-2002-1792 EXP Buffer overflow in Fake Identd 0.9 through 1.4 allows remote attackers to execute arbitrary code as root via a long request that is split into multipl… Patch early 10.0 high 8.4% 2002-12-31
← previous page 145 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt