peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,893 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-0496 EXP PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP… Patch early 10.0 high 3.8% 2007-01-25
CVE-2007-2792 EXP SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 for Mambo and Joomla! allows re… Patch early 7.5 high 3.8% 2007-05-22
CVE-2008-3164 EXP Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execu… Patch early 7.6 high 3.8% 2008-07-14
CVE-2021-31152 EXP Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change pass… Patch early 8.8 high 3.8% 2021-04-14
CVE-2007-2778 EXP Multiple directory traversal vulnerabilities in MolyX BOARD 2.5.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parame… Patch early 7.8 high 3.8% 2007-05-21
CVE-2022-26180 EXP qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI. Patch early 8.8 high 3.8% 2022-04-08
CVE-2009-2111 EXP Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP code via a crafted (1) url and… Patch early 10.0 high 3.7% 2009-06-18
CVE-2010-2959 EXP Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21,… Patch early 7.2 high 3.7% 2010-09-08
CVE-2010-2739 EXP Buffer overflow in the CreateDIBPalette function in win32k.sys in Microsoft Windows XP SP3, Server 2003 R2 Enterprise SP2, Vista Business SP1, Windows… Patch early 7.2 high 3.7% 2010-09-07
CVE-2013-2579 EXP TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 have an empty passw… Patch early 10.0 high 3.7% 2013-10-11
CVE-2008-2192 EXP Static code injection vulnerability in box/minichat/boxpop.php in IT!CMS (aka itcms) 1.9 allows remote attackers to inject arbitrary PHP code into box… Patch early 10.0 high 3.7% 2008-05-14
CVE-2008-6748 EXP Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the play action in a mega:// URI. Patch early 9.3 high 3.7% 2009-04-24
CVE-2007-2774 EXP Multiple PHP remote file inclusion vulnerabilities in SunLight CMS 5.3 allow remote attackers to execute arbitrary PHP code via a URL in the root para… Patch early 7.5 high 3.7% 2007-05-21
CVE-2014-10031 EXP Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary code via a long string in a U… Patch early 7.5 high 3.7% 2015-01-13
CVE-2017-14960 EXP xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL Injection. Patch early 7.5 high 3.7% 2018-01-04
CVE-2007-2367 EXP Buffer overflow in wserve_console.exe in Wserve HTTP Server (whttp) 4.6 allows remote attackers to cause a denial of service (forced application exit)… Patch early 10.0 high 3.7% 2007-04-30
CVE-2000-0776 EXP Mediahouse Statistics Server 5.02x allows remote attackers to execute arbitrary commands via a long HTTP GET request. Patch early 7.5 high 3.7% 2000-10-20
CVE-2001-0216 EXP PALS Library System pals-cgi program allows remote attackers to execute arbitrary commands via shell metacharacters in the documentName parameter. Patch early 7.5 high 3.7% 2001-06-02
CVE-2001-1160 EXP udirectory.pl in Microburst Technologies uDirectory 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in… Patch early 7.5 high 3.7% 2001-06-18
CVE-2025-60188 EXP Insertion of Sensitive Information Into Sent Data vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Retrieve Embedded Sensitive Da… Patch early 7.5 high 3.7% 2025-11-06
CVE-2008-7065 EXP Siemens C450 IP and C475 IP VoIP devices allow remote attackers to cause a denial of service (disconnected calls and device reboot) via a crafted SIP… Patch early 7.8 high 3.7% 2009-08-25
CVE-2008-4380 EXP The web interface in Samsung DVR SHR2040 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, related to the fil… Patch early 7.8 high 3.7% 2008-10-01
CVE-2014-1216 EXP FitNesse Wiki 20131110, 20140201, and earlier allows remote attackers to execute arbitrary commands by defining a COMMAND_PATTERN and TEST_RUNNER in t… Patch early 7.5 high 3.7% 2014-04-22
CVE-2016-4669 EXP An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watc… Patch early 7.8 high 3.7% 2017-02-20
CVE-2000-0325 EXP The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability. Patch early 7.2 high 3.7% 1999-08-20
CVE-2005-4087 EXP PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier… Patch early 7.5 high 3.7% 2005-12-08
CVE-2007-2599 EXP Multiple SQL injection vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to execute arbitrary SQL comma… Patch early 7.5 high 3.7% 2007-05-11
CVE-2013-4862 EXP MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmware via t… Patch early 8.1 high 3.7% 2020-01-28
CVE-2012-4772 EXP SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL commands via the plan_id paramet… Patch early 7.5 high 3.7% 2012-10-22
CVE-2005-1894 EXP Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer heade… Patch early 7.5 high 3.7% 2005-06-09
← previous page 215 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt