peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,899 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-5826 EXP Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote attackers to create or overwri… Patch early 9.3 high 3.7% 2007-11-05
CVE-2008-0427 EXP Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the file paramet… Patch early 7.8 high 3.7% 2008-01-23
CVE-2007-3974 EXP admin/ajoutaut.php in JBlog 1.0 does not require authentication, which allows remote attackers to create arbitrary accounts via modified mot and droit… Patch early 7.5 high 3.7% 2007-07-25
CVE-2000-0589 EXP SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configuration. Patch early 7.5 high 3.7% 2000-06-26
CVE-2001-0308 EXP UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling th… Patch early 7.5 high 3.7% 2001-05-03
CVE-2011-0751 EXP Directory traversal vulnerability in nhttpd (aka Nostromo webserver) before 1.9.4 allows remote attackers to execute arbitrary programs or read arbitr… Patch early 7.5 high 3.7% 2011-03-16
CVE-2016-0173 EXP The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R… Patch early 7.8 high 3.7% 2016-05-11
CVE-2016-7188 EXP The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles library loading, which allows local… Patch early 7.8 high 3.7% 2016-10-14
CVE-2019-0735 EXP An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, a… Patch early 7.8 high 3.7% 2019-04-09
CVE-2007-2373 EXP SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote attackers to execute arbitrary SQ… Patch early 7.5 high 3.7% 2007-04-30
CVE-2013-4147 EXP Multiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attackers to cause a denial of service… Patch early 7.5 high 3.7% 2013-08-09
CVE-2012-0992 EXP interface/fax/fax_dispatch.php in OpenEMR 4.1.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the file p… Patch early 8.5 high 3.7% 2012-02-07
CVE-2015-2508 EXP The Adobe Type Manager Library in Microsoft Windows 10 allows local users to gain privileges via a crafted application, aka "Font Driver Elevation of… Patch early 7.2 high 3.7% 2015-09-09
CVE-2006-4166 EXP PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the image… Patch early 7.5 high 3.7% 2006-08-16
CVE-2007-1986 EXP Multiple PHP remote file inclusion vulnerabilities in barnraiser AROUNDMe 0.7.7 allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 3.7% 2007-04-12
CVE-2003-1092 EXP Unknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) Tool version of the file package before 3.41, related to "a memory alloc… Patch early 7.5 high 3.7% 2003-12-31
CVE-2005-1224 EXP Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChannel parame… Patch early 7.5 high 3.7% 2005-05-02
CVE-2005-1550 EXP easymsgb.pl in Easy Message Board allows remote attackers to execute arbitrary commands via shell metacharacters in the print parameter. Patch early 7.5 high 3.7% 2005-05-14
CVE-2005-1307 EXP The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the produ… Patch early 7.2 high 3.7% 2005-05-17
CVE-2006-1793 EXP Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) clas… Patch early 7.6 high 3.6% 2006-04-17
CVE-2007-0637 EXP Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local file… Patch early 7.5 high 3.6% 2007-01-31
CVE-2007-0702 EXP Multiple PHP remote file inclusion vulnerabilities in phpEventMan 1.0.2 allow remote attackers to execute arbitrary PHP code via a URL in the level pa… Patch early 7.5 high 3.6% 2007-02-04
CVE-2008-4439 EXP PHP remote file inclusion vulnerability in admin/bin/patch.php in MartinWood Datafeed Studio before 1.6.3 allows remote attackers to execute arbitrary… Patch early 10.0 high 3.6% 2008-10-03
CVE-2006-3692 EXP PHP remote file inclusion vulnerability in enduser/listmessenger.php in ListMessenger 0.9.3 allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 3.6% 2006-07-21
CVE-2007-3400 EXP The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.7, allows remote attackers to… Patch early 9.3 high 3.6% 2007-06-26
CVE-2009-0465 EXP The SaveDoc method in the All_In_The_Box.AllBox ActiveX control in ALL_IN_THE_BOX.OCX in Synactis ALL In-The-Box ActiveX 3 allows remote attackers to… Patch early 9.3 high 3.6% 2009-02-10
CVE-2002-2360 EXP The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary fi… Patch early 9.3 high 3.6% 2002-12-31
CVE-2007-0535 EXP Multiple eval injection vulnerabilities in Vote! Pro 4.0, and possibly earlier, allow remote attackers to execute arbitrary code via requests to unspe… Patch early 7.5 high 3.6% 2007-01-26
CVE-2007-2527 EXP Multiple PHP remote file inclusion vulnerabilities in DynamicPAD before 1.03.31 allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 3.6% 2007-05-08
CVE-2019-6214 EXP A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.… Patch early 8.6 high 3.6% 2019-03-05
← previous page 217 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt