peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,769 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-1749 EXP IOUSBFamily in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corru… Patch early 7.8 high 4.1% 2016-03-24
CVE-2006-2807 EXP ASPwebSoft Speedy Asp Discussion Forum allows remote attackers to change the password of any account via a modified account id and possibly arbitrary… Patch early 10.0 high 4.1% 2006-06-05
CVE-2018-10188 EXP phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.… Patch early 8.8 high 4.1% 2018-04-19
CVE-2024-25734 EXP An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is enter… Patch early 7.5 high 4.1% 2024-03-27
CVE-2013-1803 EXP Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) orderby param… Patch early 7.5 high 4% 2014-05-05
CVE-2007-0680 EXP PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and earlier allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 4% 2007-02-03
CVE-2008-6834 EXP Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.01 and 3.01a allow remote attackers to include and execute arbitrary local files via… Patch early 10.0 high 4% 2009-06-22
CVE-2008-1275 EXP Multiple unspecified vulnerabilities in the SMTP service in MailEnable Standard Edition 1.x, Professional Edition 3.x and earlier, and Enterprise Edit… Patch early 7.8 high 4% 2008-03-10
CVE-2003-1097 EXP Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option. Patch early 7.2 high 4% 2003-12-31
CVE-2006-0087 EXP SQL injection vulnerability in (1) pages.php and (2) detail.php in Lizard Cart CMS 1.04 allows remote attackers to execute arbitrary SQL commands via… Patch early 7.5 high 4% 2006-01-05
CVE-2009-4676 EXP Stack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute arbitrary code via a long titl… Patch early 9.3 high 4% 2010-03-05
CVE-2013-2784 EXP Triangle Research International (aka Tri) Nano-10 PLC devices with firmware before r81 use an incorrect algorithm for bounds checking of data in Modbu… Patch early 7.8 high 4% 2013-07-10
CVE-2003-0306 EXP Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClass… Patch early 7.2 high 4% 2003-06-09
CVE-2006-6568 EXP Directory traversal vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to include… Patch early 10.0 high 4% 2006-12-15
CVE-2006-7131 EXP PHP remote file inclusion vulnerability in extras/mt.php in Jinzora 2.6 allows remote attackers to execute arbitrary PHP code via the web_root paramet… Patch early 10.0 high 4% 2007-03-06
CVE-2007-2493 EXP PHP remote file inclusion vulnerability in faq.php in the FAQ & RULES 2.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary P… Patch early 10.0 high 4% 2007-05-04
CVE-2005-3682 EXP Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (1) the AuthID parameter in For… Patch early 7.5 high 4% 2005-11-18
CVE-2002-0250 EXP Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized users to bypass… Patch early 7.5 high 4% 2002-05-29
CVE-2008-3464 EXP afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly val… Patch early 7.2 high 4% 2008-10-15
CVE-2024-33896 EXP Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blackli… Patch early 7.2 high 4% 2024-08-02
CVE-2004-0323 EXP Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp paramet… Patch early 7.5 high 4% 2004-12-31
CVE-2006-7070 EXP Unrestricted file upload vulnerability in manager/media/ibrowser/scripts/rfiles.php in Etomite CMS 0.6.1 and earlier allows remote attackers to upload… Patch early 7.5 high 4% 2007-03-02
CVE-2008-4878 EXP Unrestricted file upload vulnerability in the "Add Image Macro" feature in WebCards 1.3 allows remote authenticated administrators to execute arbitrar… Patch early 8.5 high 4% 2008-11-01
CVE-2017-7178 EXP CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitra… Patch early 8.8 high 4% 2017-03-18
CVE-2006-0359 EXP Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device crash) via SIP INVITE commands w… Patch early 7.5 high 4% 2006-01-22
CVE-2006-1212 EXP Unspecified vulnerability in index.php in Core CoreNews 2.0.1 allows remote attackers to execute arbitrary commands via the page parameter, possibly d… Patch early 7.5 high 4% 2006-03-14
CVE-2008-4592 EXP Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and execute arbitrary local files vi… Patch early 10.0 high 4% 2008-10-16
CVE-2008-6677 EXP Unrestricted file upload vulnerability in fckeditor251/editor/filemanager/connectors/asp/upload.asp in QuickerSite 1.8.5 allows remote attackers to ex… Patch early 7.5 high 4% 2009-04-08
CVE-2015-2370 EXP The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and… Patch early 7.2 high 4% 2015-07-14
CVE-2016-0006 EXP The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2… Patch early 7.3 high 4% 2016-01-13
← previous page 209 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt