peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,851 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-1616 EXP Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to gain root privileges via (1) su, (2) chsh, (3) passwd,… Patch early 7.2 high 3.9% 2002-08-01
CVE-2025-10162 EXP The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloade… Patch early 7.5 high 3.9% 2025-10-07
CVE-2007-3548 EXP Stack-based buffer overflow in W3Filer 2.1.3 allows remote FTP servers to cause a denial of service (application hang or crash) and possibly execute a… Patch early 7.1 high 3.9% 2007-07-03
CVE-2019-11416 EXP A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user. Patch early 8.8 high 3.9% 2019-04-22
CVE-2019-13494 EXP nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long variable string in a Map Objects… Patch early 7.8 high 3.9% 2019-07-12
CVE-2005-0994 EXP Multiple SQL injection vulnerabilities in ProductCart 2.7 allow remote attackers to execute arbitrary SQL commands via (1) the Category or resultCnt p… Patch early 7.5 high 3.9% 2005-05-02
CVE-2005-3302 EXP Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file… Patch early 7.3 high 3.9% 2005-10-24
CVE-2000-0836 EXP Buffer overflow in CamShot WebCam Trial2.6 allows remote attackers to execute arbitrary commands via a long Authorization header. Patch early 7.5 high 3.9% 2000-11-14
CVE-2000-0846 EXP Buffer overflow in Darxite 0.4 and earlier allows a remote attacker to execute arbitrary commands via a long username or password. Patch early 7.5 high 3.9% 2000-11-14
CVE-2006-1919 EXP PHP remote file inclusion vulnerability in index.php in Internet Photoshow 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 3.9% 2006-04-20
CVE-2002-2113 EXP search.cgi in AGH HTMLsearch 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the template parameter. Patch early 7.5 high 3.9% 2002-12-31
CVE-2001-0985 EXP shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter… Patch early 7.5 high 3.9% 2001-09-08
CVE-2008-5868 EXP Stack-based buffer overflow in IntelliTamper 2.07 and 2.08 allows user-assisted attackers to execute arbitrary code via a long ProxyLogin value in a c… Patch early 9.3 high 3.9% 2009-01-08
CVE-2017-12763 EXP An unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privileges by gaining access to loca… Patch early 8.8 high 3.9% 2017-08-29
CVE-2008-2638 EXP Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message p… Patch early 10.0 high 3.9% 2008-06-10
CVE-2009-1779 EXP PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 3.9% 2009-05-22
CVE-2005-4554 EXP Multiple SQL injection vulnerabilities in DEV web management system 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (… Patch early 7.5 high 3.8% 2005-12-28
CVE-1999-1112 EXP Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image type in a Phot… Patch early 7.5 high 3.8% 1999-11-09
CVE-2008-2480 EXP PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers to execute arbitrary PHP code v… Patch early 10.0 high 3.8% 2008-05-28
CVE-2006-5068 EXP PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.1 and earlier allows remote at… Patch early 7.5 high 3.8% 2006-09-28
CVE-2006-2843 EXP PHP remote file inclusion vulnerability in Redaxo 2.7.4 allows remote attackers to execute arbitrary PHP code via a URL in the (1) REX[INCLUDE_PATH] p… Patch early 7.5 high 3.8% 2006-06-06
CVE-2006-2844 EXP Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDE_PAT… Patch early 7.5 high 3.8% 2006-06-06
CVE-2006-2845 EXP PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDE_PAT… Patch early 7.5 high 3.8% 2006-06-06
CVE-2006-3690 EXP Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 3.8% 2006-07-21
CVE-2007-6538 EXP SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL… Patch early 7.5 high 3.8% 2007-12-27
CVE-2006-0959 EXP SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote attackers to execute arbitrary… Patch early 7.5 high 3.8% 2006-03-02
CVE-2020-35151 EXP The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection. Patch early 8.8 high 3.8% 2020-12-21
CVE-2006-6360 EXP PHP remote file inclusion vulnerability in activate.php in PHP Upload Center 2.0 allows remote attackers to execute arbitrary PHP code via a URL in th… Patch early 7.5 high 3.8% 2006-12-07
CVE-2012-5897 EXP The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly impleme… Patch early 9.3 high 3.8% 2012-11-17
CVE-2007-2496 EXP The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1)… Patch early 7.8 high 3.8% 2007-05-04
← previous page 212 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt