peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,660 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-4009 EXP PHP remote file inclusion vulnerability in admin/business_inc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1 allows remote attackers to exe… Patch early 9.3 high 4.3% 2007-07-26
CVE-2008-0141 EXP actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to o… Patch early 7.5 high 4.3% 2008-01-08
CVE-2016-6663 EXP Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x before 10.… Patch early 7.0 high 4.3% 2016-12-13
CVE-2023-31702 EXP SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to dump entire database and gain w… Patch early 7.2 high 4.3% 2023-05-17
CVE-2007-4634 EXP Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 bef… Patch early 9.3 high 4.3% 2007-08-31
CVE-2017-6978 EXP An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Accessibility Framework" component. It al… Patch early 7.8 high 4.3% 2017-05-22
CVE-2019-0836 EXP An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privil… Patch early 7.8 high 4.3% 2019-04-09
CVE-2008-3361 EXP Stack-based buffer overflow in IntelliTamper 2.07 allows remote web sites to execute arbitrary code via a long HTTP Server header. Patch early 7.5 high 4.3% 2008-07-29
CVE-2006-3727 EXP Multiple SQL injection vulnerabilities in Eskolar CMS 0.9.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) gr_1_id, (2) gr_2_i… Patch early 7.5 high 4.3% 2006-07-21
CVE-2006-5928 EXP Multiple PHP remote file inclusion vulnerabilities in Phpjobscheduler 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the instal… Patch early 7.5 high 4.3% 2006-11-16
CVE-2017-7852 EXP D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's se… Patch early 8.8 high 4.3% 2017-04-24
CVE-2006-4081 EXP preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute commands via shell metacharacters… Patch early 7.5 high 4.3% 2006-08-11
CVE-2006-3683 EXP PHP remote file inclusion vulnerability in poll.php in Flipper Poll 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 4.3% 2006-07-21
CVE-2006-0502 EXP PHP remote file inclusion vulnerability in loginout.php in FarsiNews 2.1 Beta 2 and earlier, with register_globals enabled, allows remote attackers to… Patch early 7.5 high 4.3% 2006-02-01
CVE-2004-0676 EXP Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary file… Patch early 10.0 high 4.3% 2004-08-06
CVE-2006-0206 EXP Eval injection vulnerability in Light Weight Calendar (LWC) 1.0 (20040909) and earlier allows remote attackers to execute arbitrary PHP code via the d… Patch early 7.5 high 4.3% 2006-01-13
CVE-2002-2385 EXP Buffer overflow in hotfoon4.exe in Hotfoon 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a… Patch early 7.5 high 4.3% 2002-12-31
CVE-2002-0676 EXP SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrar… Patch early 7.5 high 4.3% 2002-07-11
CVE-2011-4558 EXP Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters. Patch early 7.2 high 4.3% 2020-01-27
CVE-2007-6234 EXP index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a loggedin parameter with a value o… Patch early 10.0 high 4.3% 2007-12-04
CVE-2015-9222 EXP In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400,… Patch early 7.5 high 4.3% 2018-04-18
CVE-2010-2860 EXP The EMC Celerra Network Attached Storage (NAS) appliance accepts external network traffic to IP addresses intended for an intranet network within the… Patch early 9.3 high 4.3% 2010-08-05
CVE-2005-1029 EXP Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir… Patch early 7.5 high 4.3% 2005-04-06
CVE-2017-2490 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchO… Patch early 7.8 high 4.3% 2017-04-02
CVE-2007-6544 EXP Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter to (1) br… Patch early 7.5 high 4.3% 2007-12-28
CVE-2021-46416 EXP Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie h… Patch early 8.1 high 4.3% 2022-04-07
CVE-2017-8222 EXP Wireless IP Camera (P2P) WIFICAM devices have an "Apple Production IOS Push Services" private RSA key and certificate stored in /system/www/pem/ck.pem… Patch early 7.5 high 4.3% 2017-04-25
CVE-1999-0493 EXP rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be use… Patch early 7.5 high 4.3% 1999-06-07
CVE-2002-0608 EXP Buffer overflow in Matu FTP client 1.74 allows remote FTP servers to execute arbitrary code via a long "220" banner. Patch early 7.5 high 4.3% 2002-06-18
CVE-2008-0939 EXP Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arbi… Patch early 7.5 high 4.3% 2008-02-25
← previous page 204 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt