peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,166 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-6618 EXP Multiple SQL injection vulnerabilities in ClassSystem 2.3 allow remote attackers to execute arbitrary SQL commands via the teacher_id parameter in (1)… Patch early 7.5 high 1.9% 2009-04-06
CVE-1999-1491 EXP abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via… Patch early 7.2 high 1.9% 1996-02-02
CVE-2007-2598 EXP SQL injection vulnerability in print.php in SimpleNews 1.0.0 FINAL allows remote attackers to execute arbitrary SQL commands via the news_id parameter… Patch early 10.0 high 1.9% 2007-05-11
CVE-2017-6008 EXP A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution a… Patch early 7.8 high 1.9% 2017-09-13
CVE-2016-4625 EXP Use-after-free vulnerability in IOSurface in Apple OS X before 10.11.6 allows local users to gain privileges via unspecified vectors. Patch early 7.8 high 1.9% 2016-07-22
CVE-2018-1124 EXP procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privil… Patch early 7.8 high 1.9% 2018-05-23
CVE-2017-14757 EXP OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone t… Patch early 8.8 high 1.9% 2017-10-03
CVE-2007-5430 EXP Multiple SQL injection vulnerabilities in Stride 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the p parameter to main.php in t… Patch early 7.5 high 1.9% 2007-10-12
CVE-2004-1555 EXP Multiple SQL injection vulnerabilities in BroadBoard Instant ASP Message Board allow remote attackers to run arbitrary SQL commands via the (1) keywor… Patch early 7.5 high 1.9% 2004-12-31
CVE-2005-3290 EXP SQL injection vulnerability in Accelerated Mortgage Manager allows remote attackers to execute arbitrary SQL commands via the password field. Patch early 7.5 high 1.9% 2005-10-23
CVE-2017-8836 EXP CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-buil… Patch early 8.8 high 1.9% 2017-06-05
CVE-2007-3884 EXP SQL injection vulnerability in philboard_forum.asp in husrevforum 1.0.1 allows remote attackers to execute arbitrary SQL commands via the forumid para… Patch early 7.5 high 1.9% 2007-07-18
CVE-2007-2339 EXP Multiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified recipients… Patch early 7.5 high 1.9% 2007-04-27
CVE-2026-34473 EXP Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H208N, H367N, H181A, and H196Q.… Patch early 7.5 high 1.9% 2026-05-06
CVE-2006-0311 EXP SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter. Patch early 7.5 high 1.9% 2006-01-19
CVE-2006-0774 EXP SQL injection vulnerability in deleteSession() in DB_eSession library 1.0.2 and earlier, as used in multiple products, allows remote attackers to exec… Patch early 7.5 high 1.9% 2006-02-19
CVE-2006-0775 EXP Multiple SQL injection vulnerabilities in show.php in BirthSys 3.1 allow remote attackers to execute arbitrary SQL commands via the $month variable.… Patch early 7.5 high 1.9% 2006-02-19
CVE-2006-1081 EXP SQL injection vulnerability in forgotten_password.php in Jonathan Beckett PluggedOut Nexus 0.1 allows remote attackers to execute arbitrary SQL comman… Patch early 7.5 high 1.9% 2006-03-09
CVE-2004-2000 EXP SQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL via the (1) orderby o… Patch early 7.5 high 1.9% 2004-05-05
CVE-2007-3789 EXP SQL injection vulnerability in admin/index.php in Inmostore 4.0 allows remote attackers to execute arbitrary SQL commands via the Password field. NOT… Patch early 7.5 high 1.9% 2007-07-15
CVE-2006-4284 EXP SQL injection vulnerability in comments.asp in LBlog 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. Patch early 7.5 high 1.9% 2006-08-22
CVE-2005-0252 EXP SQL injection vulnerability in BibORB 1.3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the (1) User… Patch early 7.5 high 1.9% 2005-05-02
CVE-2006-0234 EXP SQL injection vulnerability in index.php in microBlog 2.0 RC-10 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) ye… Patch early 7.5 high 1.9% 2006-01-18
CVE-2006-5885 EXP SQL injection vulnerability in Products.asp in NuStore 1.0 allows remote attackers to execute arbitrary SQL commands via the SubCatagoryID parameter. Patch early 7.5 high 1.9% 2006-11-14
CVE-2006-4042 EXP Multiple SQL injection vulnerabilities in trackback.php in myWebland myBloggie 2.1.4 and earlier allow remote attackers to execute arbitrary SQL comma… Patch early 7.5 high 1.9% 2006-08-09
CVE-2006-6859 EXP SQL injection vulnerability in coupon_detail.asp in Website Designs For Less Click N' Print Coupons 2005.01 and earlier allows remote attackers to exe… Patch early 10.0 high 1.9% 2006-12-31
CVE-2017-1085 EXP In FreeBSD before 11.2-RELEASE, an application which calls setrlimit() to increase RLIMIT_STACK may turn a read-only memory region below the stack int… Patch early 7.8 high 1.9% 2018-09-12
CVE-2010-2134 EXP Multiple SQL injection vulnerabilities in login.php in Project Man 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1… Patch early 7.5 high 1.8% 2010-06-02
CVE-2006-0759 EXP Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid… Patch early 7.5 high 1.8% 2006-02-18
CVE-2006-0199 EXP SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hi… Patch early 7.5 high 1.8% 2006-01-13
← previous page 301 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt