peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,599 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-45639 EXP OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter.… Patch early 7.8 high 4.7% 2023-01-24
CVE-2005-4243 EXP Multiple SQL injection vulnerabilities in QuickPayPro 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) popupid parameter in po… Patch early 7.5 high 4.7% 2005-12-15
CVE-2007-2644 EXP A certain ActiveX control in Morovia Barcode ActiveX Professional 3.3.1304 allows remote attackers to overwrite arbitrary files by calling the Save me… Patch early 9.4 high 4.6% 2007-05-13
CVE-2008-0634 EXP Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote… Patch early 7.5 high 4.6% 2008-02-06
CVE-2008-3583 EXP Buffer overflow in the HTML parser in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a long URL in the SRC attribute of an I… Patch early 7.5 high 4.6% 2008-08-10
CVE-2013-3530 EXP SQL injection vulnerability in playlist.php in the Spiffy XSPF Player plugin 0.1 for WordPress allows remote attackers to execute arbitrary SQL comman… Patch early 7.5 high 4.6% 2013-05-10
CVE-2008-5305 EXP Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable. Patch early 10.0 high 4.6% 2008-12-10
CVE-2007-0182 EXP Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbitrary PHP code via a URL in th… Patch early 7.5 high 4.6% 2007-01-12
CVE-2001-0440 EXP Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary command… Patch early 7.5 high 4.6% 2001-07-02
CVE-2014-9178 EXP Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-document-manage… Patch early 7.5 high 4.6% 2014-12-02
CVE-2018-5725 EXP MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of the web server. Patch early 7.5 high 4.6% 2018-01-16
CVE-2008-5754 EXP Stack-based buffer overflow in BulletProof FTP Client allows user-assisted attackers to execute arbitrary code via a .bps file (aka Session-File) with… Patch early 9.3 high 4.6% 2008-12-30
CVE-2004-0524 EXP Buffer overflow in the chpasswd command in the Change_passwd plugin before 4.0, as used in SquirrelMail, allows local users to gain root privileges vi… Patch early 10.0 high 4.6% 2004-08-06
CVE-2008-4470 EXP Stack-based buffer overflow in Numark CUE 5.0 rev2 allows user-assisted attackers to cause a denial of service (application crash) or execute arbitrar… Patch early 9.3 high 4.6% 2008-10-07
CVE-2019-5796 EXP Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a craft… Patch early 7.5 high 4.6% 2019-05-23
CVE-2006-0797 EXP Nokia N70 cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed… Patch early 7.8 high 4.6% 2006-02-19
CVE-2002-2232 EXP Buffer overflow in Enceladus Server Suite 3.9 allows remote attackers to execute arbitrary code via a long CD (CWD) command. Patch early 8.5 high 4.6% 2002-12-31
CVE-2008-6826 EXP dhtml.pl in MHF Media Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter, as demonstrated using… Patch early 10.0 high 4.6% 2009-06-08
CVE-2008-5090 EXP Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email… Patch early 10.0 high 4.6% 2008-11-14
CVE-2007-6089 EXP PHP remote file inclusion vulnerability in index.php in meBiblio 0.4.5 allows remote attackers to execute arbitrary PHP code via a URL in the action p… Patch early 9.3 high 4.6% 2007-11-22
CVE-2017-6552 EXP Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing table size: it can be filled w… Patch early 7.5 high 4.6% 2017-03-09
CVE-2014-10013 EXP SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 4.6% 2015-01-13
CVE-2014-5189 EXP SQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin for WordPress allows remote attackers to execute arbitrary SQL comm… Patch early 7.5 high 4.6% 2014-08-07
CVE-2014-5201 EXP SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the viewid p… Patch early 7.5 high 4.6% 2014-08-12
CVE-2014-9175 EXP SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote attackers to execute arbitrar… Patch early 7.5 high 4.6% 2014-12-02
CVE-2020-15238 EXP Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-mechanism is prone to an argumen… Patch early 7.1 high 4.6% 2020-10-27
CVE-2000-0026 EXP Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password authorization string. Patch early 10.0 high 4.6% 1999-12-21
CVE-2016-6754 EXP A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote at… Patch early 8.8 high 4.6% 2016-11-25
CVE-2007-6176 EXP kb_whois.cgi in K+B-Bestellsystem (aka KB-Bestellsystem) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) dom… Patch early 10.0 high 4.6% 2007-11-30
CVE-2017-2472 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchO… Patch early 7.8 high 4.6% 2017-04-02
← previous page 199 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt