peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,829 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-15957 EXP my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file. Patch early 8.8 high 3.9% 2017-10-29
CVE-2008-2686 EXP webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overwriting a PHP file in webinc/bx… Patch early 7.5 high 3.9% 2008-06-13
CVE-2008-2092 EXP Linksys SPA-2102 Phone Adapter 3.3.6 allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE: the… Patch early 7.8 high 3.9% 2008-05-06
CVE-2000-0155 EXP Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when… Patch early 7.2 high 3.9% 2000-02-18
CVE-2014-9605 EXP WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a syste… Patch early 9.4 high 3.9% 2015-09-04
CVE-2006-7048 EXP Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarol… Patch early 7.5 high 3.9% 2007-02-24
CVE-2006-3930 EXP PHP remote file inclusion vulnerability in admin.a6mambohelpdesk.php in a6mambohelpdesk Mambo Component 18RC1 and earlier allows remote attackers to e… Patch early 7.5 high 3.9% 2006-07-31
CVE-2010-3888 EXP Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild… Patch early 7.2 high 3.9% 2010-10-08
CVE-2006-3884 EXP Multiple SQL injection vulnerabilities in links.php in Gonafish LinksCaffe 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) of… Patch early 7.5 high 3.9% 2006-07-27
CVE-2018-10900 EXP Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be… Patch early 7.8 high 3.9% 2018-07-26
CVE-2000-0624 EXP Buffer overflow in Winamp 2.64 and earlier allows remote attackers to execute arbitrary commands via a long #EXTINF: extension in the M3U playlist. Patch early 7.5 high 3.9% 2000-07-20
CVE-2005-3019 EXP Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request paramete… Patch early 7.5 high 3.9% 2005-09-21
CVE-2005-0419 EXP Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as demonstrate… Patch early 7.5 high 3.9% 2005-04-27
CVE-2005-2694 EXP Buffer overflow in WinAce 2.6.0.5, and possibly earlier versions, allows remote attackers to execute arbitrary code via a temporary (.tmp) file that c… Patch early 7.5 high 3.9% 2005-08-26
CVE-2007-5802 EXP Directory traversal vulnerability in index.php in Firewolf Technologies Synergiser 1.2 RC1 and earlier allows remote attackers to include and execute… Patch early 7.5 high 3.9% 2007-11-03
CVE-2006-7183 EXP PHP remote file inclusion vulnerability in styles.php in Exhibit Engine (EE) 1.22 and earlier allows remote attackers to execute arbitrary PHP code vi… Patch early 10.0 high 3.9% 2007-03-30
CVE-2006-4055 EXP Multiple PHP remote file inclusion vulnerabilities in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allow remote attackers to execu… Patch early 7.5 high 3.9% 2006-08-10
CVE-2006-4605 EXP PHP remote file inclusion vulnerability in index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to execute arbitrary PHP code via the… Patch early 7.5 high 3.9% 2006-09-07
CVE-2017-6989 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. Th… Patch early 7.8 high 3.9% 2017-05-22
CVE-2025-49741 EXP No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. Patch early 7.4 high 3.9% 2025-07-01
CVE-2006-2668 EXP Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 2.05 allow remote attackers to execute arbitrary PHP code via a URL in the lang param… Patch early 7.5 high 3.9% 2006-05-30
CVE-2007-5453 EXP Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing PHP sequen… Patch early 8.5 high 3.9% 2007-10-14
CVE-2009-1361 EXP dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter. NOTE: the prov… Patch early 10.0 high 3.9% 2009-04-22
CVE-2025-60690 EXP A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.t… Patch early 8.8 high 3.9% 2025-11-13
CVE-2013-4630 EXP Stack-based buffer overflow on Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 debugging is enabled, allows remote attackers to execute… Patch early 7.6 high 3.9% 2013-06-20
CVE-2009-4790 EXP Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modify arbitrary files via crafted… Patch early 9.0 high 3.9% 2010-04-22
CVE-2003-0723 EXP Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code. Patch early 7.5 high 3.9% 2003-10-20
CVE-2013-3691 EXP AirLive POE-2600HD allows remote attackers to cause a denial of service (device reset) via a long URL. Patch early 7.5 high 3.9% 2019-12-11
CVE-2009-4146 EXP The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the LD_PRELOAD environmen… Patch early 7.2 high 3.9% 2009-12-02
CVE-2009-1416 EXP lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might… Patch early 7.5 high 3.9% 2009-04-30
← previous page 211 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt