peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,674 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-2539 EXP Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of… Patch early 8.8 high 4.3% 2017-02-07
CVE-2017-2353 EXP An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth" component. It allows attackers… Patch early 7.8 high 4.3% 2017-02-20
CVE-2006-4558 EXP DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploa… Patch early 7.5 high 4.3% 2006-09-06
CVE-2018-10257 EXP A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that w… Patch early 8.8 high 4.2% 2018-05-01
CVE-2012-2277 EXP The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial o… Patch early 7.8 high 4.2% 2012-05-14
CVE-2017-2456 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchO… Patch early 7.0 high 4.2% 2017-04-02
CVE-2004-0318 EXP Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSF_EAUTH_UID environment variable, if it exists, instead of the real UID of the user, which co… Patch early 10.0 high 4.2% 2004-11-23
CVE-2016-10010 EXP sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gai… Patch early 7.0 high 4.2% 2017-01-05
CVE-2012-5861 EXP These Sinapsi devices do not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not requir… Patch early 7.8 high 4.2% 2012-11-23
CVE-2007-0790 EXP Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner. Patch early 7.5 high 4.2% 2007-02-06
CVE-2014-100003 EXP SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for WordPress allows remote attackers… Patch early 7.5 high 4.2% 2015-01-13
CVE-2006-1668 EXP newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to… Patch early 9.0 high 4.2% 2006-04-07
CVE-2017-7221 EXP OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute ar… Patch early 8.8 high 4.2% 2017-04-25
CVE-2004-1421 EXP Multiple PHP remote file inclusion vulnerabilities (1) step_one.php, (2) step_one_tables.php, (3) step_two_tables.php in WHM AutoPilot 2.4.6.5 and ear… Patch early 7.5 high 4.2% 2004-12-31
CVE-2016-7612 EXP An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. Th… Patch early 7.8 high 4.2% 2017-02-20
CVE-2008-6669 EXP viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in the var_filename parameter in a… Patch early 7.5 high 4.2% 2009-04-08
CVE-2017-6995 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. Th… Patch early 7.8 high 4.2% 2017-05-22
CVE-2017-6996 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. Th… Patch early 7.8 high 4.2% 2017-05-22
CVE-2017-6998 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. Th… Patch early 7.8 high 4.2% 2017-05-22
CVE-2007-6414 EXP admin/administrator.php in Adult Script 1.6 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to bypass… Patch early 7.5 high 4.2% 2007-12-17
CVE-2017-6994 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. Th… Patch early 7.8 high 4.2% 2017-05-22
CVE-2008-7167 EXP Unrestricted file upload vulnerability in upload.php in Page Manager 2006-02-04 allows remote attackers to execute arbitrary code by uploading a file… Patch early 7.5 high 4.2% 2009-09-08
CVE-2013-1763 EXP Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows local users to gain privileges… Patch early 7.2 high 4.2% 2013-02-28
CVE-2008-2478 EXP scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with reseller privileges to exe… Patch early 8.5 high 4.2% 2008-05-28
CVE-2007-1017 EXP PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows remote attackers to execute arbi… Patch early 9.3 high 4.2% 2007-02-21
CVE-2006-4741 EXP PHP remote file inclusion vulnerability in bits_listings.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute arbitrary code via the… Patch early 7.5 high 4.2% 2006-09-13
CVE-2002-0575 EXP Buffer overflow in OpenSSH before 2.9.9, and 3.x before 3.2.1, with Kerberos/AFS support and KerberosTgtPassing or AFSTokenPassing enabled, allows rem… Patch early 7.5 high 4.2% 2002-06-18
CVE-2008-4767 EXP Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploading a file w… Patch early 9.0 high 4.2% 2008-10-28
CVE-2021-29995 EXP A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in u… Patch early 8.8 high 4.2% 2021-06-09
CVE-2007-3980 EXP PHP remote file inclusion vulnerability in page.php in RCMS Pro RGameScript Pro allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 10.0 high 4.2% 2007-07-25
← previous page 205 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt