peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,522 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2000-0926 EXP SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable. Patch early 7.5 high 7% 2000-12-19
CVE-2002-0589 EXP PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass an… Patch early 7.5 high 7% 2002-06-18
CVE-2002-0734 EXP b2edit.showposts.php in B2 2.0.6pre2 and earlier does not properly load the b2config.php file in some configurations, which allows remote attackers to… Patch early 7.5 high 7% 2002-08-12
CVE-2013-3614 EXP Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to obtain access via a brute-force… Patch early 9.3 high 7% 2013-09-17
CVE-2017-7018 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 8.8 high 7% 2017-07-20
CVE-2015-7897 EXP The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9 allows remote… Patch early 7.5 high 7% 2015-11-16
CVE-2009-2403 EXP Heap-based buffer overflow in SCMPX 1.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a lon… Patch early 9.3 high 7% 2009-07-09
CVE-2003-0508 EXP Buffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earlier allows remote attackers to execute arbitrary co… Patch early 7.5 high 7% 2003-08-07
CVE-2014-8868 EXP EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain the administrator username and… Patch early 7.8 high 7% 2014-12-07
CVE-2007-4735 EXP Buffer overflow in Next Generation Software Virtual DJ (VDJ) 5.0 allows user-assisted remote attackers to execute arbitrary code via a long file path… Patch early 9.3 high 7% 2007-09-06
CVE-2003-0332 EXP The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing… Patch early 7.6 high 7% 2003-06-09
CVE-2016-7786 EXP Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demon… Patch early 8.8 high 7% 2017-04-07
CVE-2017-17088 EXP The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The web server does not check bounds… Patch early 7.5 high 7% 2017-12-19
CVE-2006-3698 EXP Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB01 for Change Data Cap… Patch early 10.0 high 7% 2006-07-21
CVE-2013-4776 EXP NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier, GS748Tv4 5.4.1.14, and GS510TP 5.0.4.4 allows remote attackers to cause a de… Patch early 7.8 high 7% 2013-12-19
CVE-2011-1974 EXP NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly v… Patch early 7.2 high 7% 2011-08-10
CVE-2013-7420 EXP Buffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attribute in a TEXTART XML element… Patch early 7.5 high 7% 2015-01-12
CVE-2016-4997 EXP The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow loc… Patch early 7.8 high 7% 2016-07-03
CVE-2002-0923 EXP CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2) pfooter p… Patch early 7.5 high 7% 2002-10-04
CVE-2013-1668 EXP The uploadFile function in upload/index.php in CosCMS before 1.822 allows remote administrators to execute arbitrary commands via shell metacharacters… Patch early 8.5 high 7% 2014-05-23
CVE-2007-2526 EXP Heap-based buffer overflow in the ConnectAsyncEx function in VNC Viewer ActiveX control (scvncctrl.dll) in the SmartCode VNC Manager 3.6 allows remote… Patch early 9.3 high 7% 2007-05-08
CVE-2007-2648 EXP Stack-based buffer overflow in the Clever Database Comparer 2.2 ActiveX control (comparerax.ocx) allows remote attackers to execute arbitrary code via… Patch early 9.3 high 7% 2007-05-14
CVE-2015-6763 EXP Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service or possibly have other impact v… Patch early 7.5 high 7% 2015-10-15
CVE-2013-4859 EXP INSTEON Hub 2242-222 lacks Web and API authentication Patch early 8.1 high 7% 2019-12-27
CVE-2001-1104 EXP SonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions. Patch early 7.5 high 7% 2001-07-25
CVE-2007-4067 EXP Absolute path traversal vulnerability in the clInetSuiteX6.clWebDav ActiveX control in CLINETSUITEX6.OCX in Clever Internet ActiveX Suite 6.2 allows r… Patch early 9.3 high 7% 2007-07-30
CVE-2017-3316 EXP Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions that are affected are VirtualBox… Patch early 8.4 high 7% 2017-01-27
CVE-2019-10652 EXP An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .php files, related to the addon… Patch early 7.2 high 7% 2019-03-30
CVE-2018-10255 EXP A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command th… Patch early 8.8 high 7% 2018-05-01
CVE-2006-4885 EXP PHP remote file inclusion vulnerability in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ro… Patch early 7.5 high 7% 2006-09-19
← previous page 165 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt