peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,624 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-4622 EXP Directory traversal vulnerability in eFileGo 3.01 allows remote attackers to execute arbitrary code, read arbitrary files, and upload arbitrary files… Patch early 7.5 high 4.4% 2005-12-31
CVE-2006-2485 EXP PHP remote file inclusion vulnerability in includes/class_template.php in Quezza 1.0 and earlier, and possibly 1.1.0 allows remote attackers to execut… Patch early 7.5 high 4.4% 2006-05-19
CVE-2007-2656 EXP Stack-based buffer overflow in the Hewlett-Packard (HP) Magview ActiveX control in hpqvwocx.dll 1.0.0.309 allows remote attackers to cause a denial of… Patch early 7.8 high 4.4% 2007-05-14
CVE-2017-13875 EXP An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allo… Patch early 7.8 high 4.4% 2017-12-25
CVE-2007-0756 EXP Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large computer-name size value in a Serve… Patch early 7.8 high 4.4% 2007-02-06
CVE-2004-0246 EXP Multiple PHP remote file inclusion vulnerabilities in (1) fonctions.lib.php, (2) derniers_commentaires.php, and (3) admin.php in Les Commentaires 2.0… Patch early 10.0 high 4.4% 2004-11-23
CVE-2009-3578 EXP Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2… Patch early 9.3 high 4.4% 2009-11-24
CVE-2008-4135 EXP Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause a denial of service (device c… Patch early 7.8 high 4.4% 2008-09-19
CVE-2018-10504 EXP The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection. Patch early 7.8 high 4.4% 2018-04-27
CVE-2007-1394 EXP Direct static code injection vulnerability in startsession.php in Flat Chat 2.0 allows remote attackers to execute arbitrary PHP code via the Chat Nam… Patch early 10.0 high 4.4% 2007-03-10
CVE-2023-33243 EXP RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the password i… Patch early 8.1 high 4.4% 2023-06-15
CVE-2012-2986 EXP lhn/public/network/ping in HP SAN/iQ 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell met… Patch early 7.7 high 4.4% 2012-08-20
CVE-2007-2822 EXP TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the (1) loggedIn and (2) activate… Patch early 9.3 high 4.4% 2007-05-22
CVE-2008-1230 EXP Unrestricted file upload vulnerability in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to upload and execute arbitrary .jsp files via an unspec… Patch early 9.3 high 4.4% 2008-03-10
CVE-2006-0099 EXP PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/templates/categories/ PHP scripts… Patch early 7.5 high 4.4% 2006-01-06
CVE-2007-6036 EXP The parseRTSPRequestString function in LIVE555 Media Server 2007.11.01 and earlier allows remote attackers to cause a denial of service (daemon crash)… Patch early 7.1 high 4.4% 2007-11-20
CVE-2014-2084 EXP Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly restrict access to the Admin int… Patch early 8.5 high 4.4% 2014-05-17
CVE-2006-2908 EXP The domecode function in inc/functions_post.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows remote attackers to execute arbit… Patch early 7.5 high 4.4% 2006-06-13
CVE-2006-3966 EXP PHP remote file inclusion vulnerability in /lib/tree/layersmenu.inc.php in the PHP Layers Menu 2.3.5 package for MyNewsGroups :) 0.6b and earlier allo… Patch early 7.5 high 4.4% 2006-08-01
CVE-2007-0641 EXP Buffer overflow in the EnumPrintersA function in dapcnfsd.dll 0.6.4.0 in Shaffer Solutions (SSC) DiskAccess NFS Client allows remote attackers to exec… Patch early 7.5 high 4.4% 2007-01-31
CVE-2018-4139 EXP An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools" component. It allows attacker… Patch early 7.8 high 4.4% 2018-04-03
CVE-2007-3984 EXP Buffer overflow in a certain ActiveX control in the NixonMyPrograms class in sasatl.dll 1.5.0.531 in Zenturi ProgramChecker allows remote attackers to… Patch early 7.5 high 4.4% 2007-07-25
CVE-2016-1861 EXP The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denia… Patch early 7.8 high 4.4% 2016-06-19
CVE-2004-1327 EXP Buffer overflow in Crystal FTP Client 2.8 allows remote malicious servers to execute arbitrary code via a response to a LIST command that contains a f… Patch early 7.5 high 4.4% 2004-12-31
CVE-2001-0669 EXP Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Mo… Patch early 7.5 high 4.4% 2001-10-30
CVE-2006-1778 EXP Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (… Patch early 7.5 high 4.4% 2006-04-13
CVE-2017-2533 EXP An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "DiskArbitration" component. A race condit… Patch early 7.0 high 4.4% 2017-05-22
CVE-2018-14327 EXP The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before EE40_00_02.00_45 sets weak per… Patch early 7.8 high 4.4% 2018-09-26
CVE-2013-1612 EXP Buffer overflow in secars.dll in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1.x before 12.1.3, and Symantec Endpoint Pro… Patch early 7.9 high 4.4% 2013-06-20
CVE-2006-1353 EXP Multiple SQL injection vulnerabilities in ASPPortal 3.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the downloadid… Patch early 7.5 high 4.4% 2006-03-22
← previous page 202 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt