peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,660 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-1058 EXP Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin… Patch early 10.0 high 4.4% 2002-10-04
CVE-2007-2755 EXP The PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll, when Internet Explorer 6 is used, allows remote attackers to overwrite arbitra… Patch early 10.0 high 4.4% 2007-05-17
CVE-2025-44177 EXP A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ endpoint. An u… Patch early 8.2 high 4.4% 2025-07-09
CVE-2009-4549 EXP Stack-based buffer overflow in A2 Media Player Pro 2.51 allows remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .m3l… Patch early 9.3 high 4.4% 2010-01-04
CVE-2014-5200 EXP SQL injection vulnerability in game_play.php in the FB Gorilla plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the… Patch early 7.5 high 4.4% 2014-08-12
CVE-2007-5094 EXP Heap-based buffer overflow in iaspam.dll in the SMTP Server in Ipswitch IMail Server 8.01 through 8.11 allows remote attackers to execute arbitrary co… Patch early 7.5 high 4.4% 2007-09-26
CVE-2012-5347 EXP TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunctions.inc… Patch early 7.5 high 4.4% 2012-10-09
CVE-2018-1002000 EXP There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exp… Patch early 7.2 high 4.4% 2018-12-03
CVE-2019-0730 EXP An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privil… Patch early 7.8 high 4.4% 2019-04-09
CVE-2019-0731 EXP An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privil… Patch early 7.8 high 4.4% 2019-04-09
CVE-2017-6803 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 al… Patch early 8.8 high 4.4% 2017-03-20
CVE-2001-0032 EXP Format string vulnerability in ssldump possibly allows remote attackers to cause a denial of service and possibly gain root privileges via malicious f… Patch early 10.0 high 4.3% 2001-02-16
CVE-2002-1034 EXP none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via an absolute pathname in the argument. Patch early 10.0 high 4.3% 2002-10-04
CVE-2006-6785 EXP The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote att… Patch early 7.5 high 4.3% 2006-12-28
CVE-2017-8665 EXP The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin.iOS Elevation Of Privilege Vu… Patch early 7.8 high 4.3% 2017-08-15
CVE-2007-2623 EXP Multiple buffer overflows in RControl.dll in Remote Display Dev kit 1.2.1.0 allow remote attackers to cause a denial of service (Internet Explorer 7 c… Patch early 7.8 high 4.3% 2007-05-11
CVE-2007-2658 EXP Unspecified vulnerability in the ID Automation Linear Barcode 1.6.0.5 ActiveX control in IDAutomationLinear6.dll allows remote attackers to cause a de… Patch early 7.8 high 4.3% 2007-05-14
CVE-2008-6822 EXP Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader) 1.0 allows remote attackers… Patch early 7.5 high 4.3% 2009-06-04
CVE-2024-25736 EXP An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET request. Patch early 7.5 high 4.3% 2024-03-27
CVE-2017-8223 EXP On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streaming without authentication via t… Patch early 7.5 high 4.3% 2017-04-25
CVE-2008-6916 EXP Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to bypass authentication via an invalid Host header, possibly involving a t… Patch early 10.0 high 4.3% 2009-08-07
CVE-2013-5755 EXP config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin (uoCbM.VEiKQto) for… Patch early 10.0 high 4.3% 2014-07-16
CVE-2014-5380 EXP Grand MA 300 allows retrieval of the access PIN from sniffed data. Patch early 7.5 high 4.3% 2020-01-13
CVE-2006-6567 EXP PHP remote file inclusion vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to ex… Patch early 10.0 high 4.3% 2006-12-15
CVE-2020-5726 EXP The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker c… Patch early 7.5 high 4.3% 2020-03-30
CVE-2006-5206 EXP SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.p… Patch early 7.5 high 4.3% 2006-10-10
CVE-2006-4531 EXP PHP remote file inclusion vulnerability in lib/config.php in Pheap CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 4.3% 2006-09-01
CVE-2017-14680 EXP ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document. Patch early 7.5 high 4.3% 2017-09-21
CVE-2018-16302 EXP MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file. Patch early 7.8 high 4.3% 2018-09-01
CVE-2014-1214 EXP views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attackers to upload and execute arb… Patch early 8.8 high 4.3% 2019-11-13
← previous page 203 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt