peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,247 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-2454 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… Patch early 8.8 high 6.7% 2017-04-02
CVE-2017-2459 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… Patch early 8.8 high 6.7% 2017-04-02
CVE-2002-0554 EXP webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary files via a SQL injection attack i… Patch early 7.5 high 6.7% 2002-07-03
CVE-2017-7089 EXP An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected.… Patch early 6.1 medium 6.7% 2017-10-23
CVE-2022-36551 EXP A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authen… Patch early 6.5 medium 6.7% 2022-10-03
CVE-2007-6620 EXP Directory traversal vulnerability in include/images.inc.php in Joovili 2.x allows remote attackers to read arbitrary files via a .. (dot dot) in the p… Patch early 6.4 medium 6.7% 2008-01-04
CVE-2006-3814 EXP Buffer overflow in the Loader_XM::load_instrument_internal function in loader_xm.cpp for Cheese Tracker 0.9.9 and earlier allows user-assisted attacke… Patch early 5.1 medium 6.7% 2006-07-25
CVE-2004-1929 EXP SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and… Patch early 7.5 high 6.7% 2004-04-13
CVE-2008-4471 EXP Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Revit Archite… Patch early 9.3 high 6.7% 2008-10-07
CVE-2007-2283 EXP Buffer overflow in Fresh View 7.15 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file. Patch early 9.3 high 6.7% 2007-04-26
CVE-2007-2284 EXP Buffer overflow in ABC-View Manager 1.42 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file. Patch early 9.3 high 6.7% 2007-04-26
CVE-2006-1832 EXP sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action. Patch early 5.0 medium 6.7% 2006-04-19
CVE-2017-7047 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. wa… Patch early 8.8 high 6.7% 2017-07-20
CVE-2007-2043 EXP Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier module for Mambo and Joomla!… Patch early 7.5 high 6.7% 2007-04-16
CVE-2017-2524 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… Patch early 9.8 critical 6.7% 2017-05-22
CVE-2006-6426 EXP PHP remote file inclusion vulnerability in design/thinkedit/render.php in ThinkEdit 1.9.2 and earlier, when register_globals is enabled, allows remote… Patch early 6.8 medium 6.7% 2006-12-10
CVE-2017-7237 EXP The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directo… Patch early 9.8 critical 6.7% 2017-04-06
CVE-2009-3076 EXP Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operati… Patch early 9.3 high 6.7% 2009-09-10
CVE-2010-3468 EXP Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CMS 5 through 5.2, allows remote… Patch early 5.0 medium 6.7% 2010-09-29
CVE-2010-1866 EXP The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of se… Patch early 9.8 critical 6.7% 2010-05-07
CVE-2012-5048 EXP APIFTP Server in Optimalog Optima PLC 1.5.2 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon cras… Patch early 7.8 high 6.7% 2012-09-28
CVE-2022-34048 EXP Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter. Patch early 6.1 medium 6.7% 2022-07-20
CVE-2006-1336 EXP Cross-site scripting vulnerability in calendar.php in ExtCalendar 1.0 and possibly other versions before 2.0 allows remote attackers to inject arbitra… Patch early 5.0 medium 6.7% 2006-03-21
CVE-2006-3561 EXP BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication p… Patch early 5.0 medium 6.7% 2006-07-13
CVE-2008-7062 EXP Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows remote attackers to execute ar… Patch early 6.8 medium 6.7% 2009-08-25
CVE-2015-8309 EXP Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to… Patch early 4.3 medium 6.7% 2017-03-27
CVE-2007-6105 EXP Multiple PHP remote file inclusion vulnerabilities in TalkBack 2.2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) languag… Patch early 6.8 medium 6.7% 2007-11-23
CVE-2015-4668 EXP Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attack… Patch early 6.1 medium 6.7% 2017-09-25
CVE-2008-2898 EXP Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and execute arbitrary local files via… Patch early 9.3 high 6.7% 2008-06-27
CVE-2017-13794 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 6.7% 2017-11-13
← previous page 295 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt