peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,620 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-2420 EXP site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter. Patch early 7.5 high 6.1% 2002-12-31
CVE-2007-4838 EXP Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via a long string in a (1) 0x21,… Patch early 7.5 high 6.1% 2007-09-12
CVE-2012-2998 EXP SQL injection vulnerability in the ad hoc query module in Trend Micro Control Manager (TMCM) before 5.5.0.1823 and 6.0 before 6.0.0.1449 allows remote… Patch early 7.5 high 6.1% 2012-09-28
CVE-2007-1992 EXP Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote attackers to execute arbitrary… Patch early 7.5 high 6.1% 2007-04-12
CVE-2007-2301 EXP Multiple PHP remote file inclusion vulnerabilities in audioCMS arash 0.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the arash… Patch early 7.5 high 6.1% 2007-04-26
CVE-2007-2313 EXP PHP remote file inclusion vulnerability in getinfo1.php in the Shotcast 1.0 RC2 module for mxBB allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 6.1% 2007-04-26
CVE-2007-2345 EXP PHP remote file inclusion vulnerability in include/include_stream.inc.php in CodeWand phpBrowse allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 6.1% 2007-04-27
CVE-2007-5771 EXP Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie. Patch early 7.5 high 6.1% 2007-11-01
CVE-2009-3428 EXP Stack-based buffer overflow in Easy Music Player 1.0.0.2 allows remote attackers to execute arbitrary code via a crafted .wav file. Patch early 9.3 high 6.1% 2009-09-25
CVE-2017-2369 EXP An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. Th… Patch early 8.8 high 6.1% 2017-02-20
CVE-2017-2373 EXP An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. Th… Patch early 8.8 high 6.1% 2017-02-20
CVE-2013-0526 EXP ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remo… Patch early 8.5 high 6.1% 2013-08-21
CVE-2007-2865 EXP Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the ser… Patch early 9.3 high 6.1% 2007-05-25
CVE-2014-100014 EXP Multiple stack-based buffer overflows in pdmwService.exe in SolidWorks Workgroup PDM 2014 SP2 allow remote attackers to execute arbitrary code via a l… Patch early 7.5 high 6.1% 2015-01-13
CVE-2009-0423 EXP Directory traversal vulnerability in index.php in Php Photo Album (PHPPA) 0.8 BETA allows remote attackers to include and execute arbitrary local file… Patch early 7.5 high 6.1% 2009-02-05
CVE-2009-1445 EXP Multiple directory traversal vulnerabilities in WebPortal CMS 0.8-beta allow remote attackers to (1) read arbitrary files via directory traversal sequ… Patch early 7.5 high 6.1% 2009-04-27
CVE-2005-0636 EXP Format string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via… Patch early 10.0 high 6.1% 2005-03-02
CVE-2017-17593 EXP Simple Chatting System 1.0 allows Arbitrary File Upload via view/my_profile.php, which places files under uploads/. Patch early 7.5 high 6.1% 2017-12-13
CVE-2009-3188 EXP PHP remote file inclusion vulnerability in save.php in phpSANE 0.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the file_save… Patch early 7.5 high 6.1% 2009-09-15
CVE-2010-4613 EXP Multiple directory traversal vulnerabilities in Hycus CMS 1.0.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot)… Patch early 7.5 high 6.1% 2010-12-29
CVE-2014-2579 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers to hijack the authentication o… Patch early 7.6 high 6% 2014-04-25
CVE-2017-2514 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" co… Patch early 8.8 high 6% 2017-05-22
CVE-2009-3810 EXP Heap-based buffer overflow in Acoustica MP3 Audio Mixer 2.471 allows remote attackers to cause a denial of service (crash) or execute arbitrary code v… Patch early 9.3 high 6% 2009-10-27
CVE-2022-35513 EXP The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage. Patch early 7.5 high 6% 2022-09-07
CVE-1999-0268 EXP MetaInfo MetaWeb web server allows users to upload, execute, and read scripts. Patch early 10.0 high 6% 1999-01-01
CVE-2021-28379 EXP web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different ori… Patch early 8.8 high 6% 2021-03-15
CVE-2025-32023 EXP Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use… Patch early 7.0 high 6% 2025-07-07
CVE-2015-7570 EXP Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate open… Patch early 7.2 high 6% 2017-04-24
CVE-2008-3209 EXP Heap-based buffer overflow in the OpenGifFile function in BiGif.dll in Black Ice Document Imaging SDK 10.95 allows remote attackers to execute arbitra… Patch early 9.3 high 6% 2008-07-18
CVE-2008-4548 EXP Stack-based buffer overflow in the PTZCamPanelCtrl ActiveX control (CamPanel.dll) in RTS Sentry 2.1.0.2 allows remote attackers to execute arbitrary c… Patch early 9.3 high 6% 2008-10-14
← previous page 177 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt