peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,546 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-13794 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 6.7% 2017-11-13
CVE-2015-7257 EXP ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin pa… Patch early 7.5 high 6.7% 2017-08-24
CVE-2004-1752 EXP Stack-based buffer overflow in Gaucho 1.4 Build 145 allows remote attackers to execute arbitrary code via a POP3 email with a long Content-Type header… Patch early 7.5 high 6.7% 2004-08-24
CVE-2004-1868 EXP Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag. Patch early 7.5 high 6.7% 2004-03-25
CVE-2009-4654 EXP Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to execute arbitrary code v… Patch early 9.0 high 6.7% 2010-02-26
CVE-2013-6234 EXP Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by… Patch early 8.0 high 6.7% 2019-11-22
CVE-2006-6445 EXP Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files vi… Patch early 7.5 high 6.7% 2006-12-10
CVE-2002-2190 EXP ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords v… Patch early 7.5 high 6.7% 2002-12-31
CVE-2015-1560 EXP SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (… Patch early 7.5 high 6.7% 2015-07-14
CVE-2018-6889 EXP An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the w… Patch early 8.8 high 6.7% 2018-02-12
CVE-2009-2258 EXP Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attac… Patch early 7.8 high 6.7% 2009-06-30
CVE-2007-1718 EXP CRLF injection vulnerability in the mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows remote attackers to inject arbitrary e-mai… Patch early 7.8 high 6.7% 2007-03-28
CVE-2002-2295 EXP Buffer overflow in Pico Server (pServ) 2.0 beta 1 through beta 5 allows remote attackers to cause a denial of service (crash) and possibly execute arb… Patch early 7.5 high 6.7% 2002-12-31
CVE-2007-5636 EXP Buffer overflow in the Nortel UNIStim IP Softphone 2050 allows remote attackers to cause a denial of service (application abort) and possibly execute… Patch early 7.5 high 6.7% 2007-10-23
CVE-2017-6191 EXP Buffer overflow in APNGDis 2.8 and below allows a remote attacker to execute arbitrary code via a crafted filename. Patch early 7.8 high 6.7% 2017-03-23
CVE-2008-7012 EXP courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before F… Patch early 7.8 high 6.7% 2009-08-19
CVE-2016-10081 EXP /usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishan… Patch early 7.8 high 6.7% 2016-12-29
CVE-2001-1202 EXP Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page, which allows rem… Patch early 7.5 high 6.7% 2001-12-28
CVE-2005-1520 EXP Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attac… Patch early 7.5 high 6.7% 2005-05-26
CVE-2002-1147 EXP The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration enabled, does… Patch early 7.1 high 6.7% 2002-10-11
CVE-2021-46398 EXP A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get… Patch early 8.8 high 6.7% 2022-02-04
CVE-2003-1227 EXP PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remot… Patch early 7.5 high 6.7% 2003-12-31
CVE-2013-3613 EXP Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a repla… Patch early 7.8 high 6.7% 2013-09-17
CVE-2002-1885 EXP PHP remote file inclusion vulnerability in showhits.php3 for PowerPhlogger (PPhlogger) 2.0.9 through 2.2.2 allows remote attackers to execute arbitrar… Patch early 7.5 high 6.7% 2002-12-31
CVE-2008-1886 EXP The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for a KeyCode that blocks unautho… Patch early 7.5 high 6.7% 2008-04-18
CVE-2006-6661 EXP Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execut… Patch early 7.5 high 6.7% 2006-12-20
CVE-2007-0462 EXP The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote att… Patch early 10.0 high 6.7% 2007-01-26
CVE-2014-6607 EXP M/Monit 3.3.2 and earlier does not verify the original password before changing passwords, which allows remote attackers to change the password of oth… Patch early 7.5 high 6.6% 2014-10-06
CVE-2006-4869 EXP PHP remote file inclusion vulnerability in phpunity-postcard.php in phpunity.postcard allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 6.6% 2006-09-19
CVE-2008-7086 EXP Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie cookie to a… Patch early 7.5 high 6.6% 2009-08-26
← previous page 169 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt