peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,247 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-2332 EXP SQL injection vulnerability in serendipity/serendipity_admin.php in Serendipity before 1.6.1 allows remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 1.7% 2012-08-13
CVE-2019-14737 EXP Ubisoft Uplay 92.0.0.6280 has Insecure Permissions. Patch early 7.8 high 1.7% 2019-10-14
CVE-2024-47773 EXP Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response w… Patch early 8.2 high 1.7% 2024-10-08
CVE-2011-4710 EXP Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1) pixie_user… Patch early 7.5 high 1.7% 2011-12-08
CVE-2007-1021 EXP SQL injection vulnerability in inc_listnews.asp in CodeAvalanche News 1.x allows remote attackers to execute arbitrary SQL commands via the CAT_ID par… Patch early 10.0 high 1.7% 2007-02-21
CVE-2018-2698 EXP Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5… Patch early 8.8 high 1.7% 2018-01-18
CVE-2002-1364 EXP Buffer overflow in the get_origin function in traceroute-nanog allows attackers to execute arbitrary code via long WHOIS responses. Patch early 7.2 high 1.7% 2002-12-23
CVE-2016-8807 EXP For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability… Patch early 7.8 high 1.7% 2016-11-08
CVE-2005-4318 EXP SQL injection vulnerability in index.php in Limbo CMS 1.0.4.2 and earlier, with register_globals off, allows remote attackers to execute arbitrary SQL… Patch early 7.5 high 1.7% 2005-12-17
CVE-2005-1378 EXP SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitrary SQL commands via the p par… Patch early 7.5 high 1.7% 2005-05-03
CVE-2007-5222 EXP SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQL commands via a "Firefox ID="… Patch early 7.5 high 1.7% 2007-10-05
CVE-2018-9233 EXP Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which m… Patch early 7.8 high 1.7% 2018-04-05
CVE-2017-1000432 EXP Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access Patch early 8.0 high 1.6% 2018-01-02
CVE-2008-3784 EXP SQL injection vulnerability in scrape.php in BtiTracker 1.4.7 and earlier and xBtiTracker 2.0.542 and earlier allows remote attackers to execute arbit… Patch early 7.5 high 1.6% 2008-08-26
CVE-2007-3427 EXP SQL injection vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid par… Patch early 7.5 high 1.6% 2007-06-27
CVE-2017-10129 EXP Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to… Patch early 8.8 high 1.6% 2017-08-08
CVE-2006-6177 EXP SQL injection vulnerability in system/core/users/users.profile.inc.php in Neocrome Seditio 1.10 and earlier allows remote authenticated users to execu… Patch early 7.5 high 1.6% 2006-11-30
CVE-2017-14355 EXP A potential security vulnerability has been identified in HPE Connected Backup versions 8.6 and 8.8.6. The vulnerability could be exploited locally to… Patch early 7.8 high 1.6% 2017-12-05
CVE-2001-0735 EXP Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute arbitrary code via a long line… Patch early 7.2 high 1.6% 2001-10-18
CVE-2011-4066 EXP SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO. Patch early 7.5 high 1.6% 2011-11-04
CVE-2016-8806 EXP For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability… Patch early 7.8 high 1.6% 2016-11-08
CVE-2007-4918 EXP SQL injection vulnerability in classes/gelato.class.php in Gelato allows remote attackers to execute arbitrary SQL commands via the post parameter to… Patch early 7.5 high 1.6% 2007-09-17
CVE-2017-10204 EXP Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to… Patch early 8.8 high 1.6% 2017-08-08
CVE-2025-4871 EXP A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the compone… Patch early 7.3 high 1.6% 2025-05-18
CVE-2010-1591 EXP Beijing Rising International Rising Antivirus 2008 through 2010 does not properly validate input to certain IOCTLs, including 0x83003C07, which allows… Patch early 7.2 high 1.6% 2010-04-28
CVE-2006-3304 EXP SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier allows remote attackers to execute arbitrary SQL commands via the xmsn parameter. Patch early 7.5 high 1.6% 2006-06-29
CVE-2016-8812 EXP For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before GFE 3.1.0.52 contains a vulnera… Patch early 8.8 high 1.6% 2016-11-08
CVE-2000-0048 EXP get_it program in Corel Linux Update allows local users to gain root access by specifying an alternate PATH for the cp program. Patch early 7.2 high 1.6% 2000-01-12
CVE-2018-18856 EXP Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate w… Patch early 7.8 high 1.6% 2018-11-20
CVE-2002-1506 EXP Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG environment variable, which overflow… Patch early 7.2 high 1.6% 2003-04-02
← previous page 306 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt