peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,247 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-0320 EXP SQL injection vulnerability in admin/processlogin.php in Bit 5 Blog 8.01 allows remote attackers to execute arbitrary SQL commands and bypass authenti… Patch early 7.5 high 1.6% 2006-01-19
CVE-2009-4628 EXP SQL injection vulnerability in the TemplatePlaza.com TPDugg (com_tpdugg) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL co… Patch early 7.5 high 1.6% 2010-01-18
CVE-1999-1384 EXP Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan hor… Patch early 7.2 high 1.6% 1996-10-30
CVE-2016-8808 EXP For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability… Patch early 7.8 high 1.6% 2016-11-08
CVE-2016-8809 EXP For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability… Patch early 7.8 high 1.6% 2016-11-08
CVE-2016-8811 EXP For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability… Patch early 7.8 high 1.6% 2016-11-08
CVE-2018-18857 EXP Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate w… Patch early 7.8 high 1.6% 2018-11-20
CVE-2016-7508 EXP Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL commands by using a certain char… Patch early 7.5 high 1.6% 2017-06-21
CVE-2004-0186 EXP smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a… Patch early 7.2 high 1.6% 2004-03-15
CVE-2018-5410 EXP Dokan, versions between 1.0.0.5000 and 1.2.0.1000, are vulnerable to a stack-based buffer overflow in the dokan1.sys driver. An attacker can create a… Patch early 7.8 high 1.6% 2019-01-07
CVE-2006-6367 EXP Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitrary SQL c… Patch early 7.5 high 1.6% 2006-12-07
CVE-2010-1338 EXP SQL injection vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers to execute a… Patch early 7.5 high 1.6% 2010-04-09
CVE-2010-1855 EXP SQL injection vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to execute arbitrary SQL commands via the id… Patch early 7.5 high 1.6% 2010-05-07
CVE-2010-4780 EXP SQL injection vulnerability in the check_banlist function in includes/sessions.php in Enano CMS 1.1.7pl1; 1.0.6pl2; and possibly other versions before… Patch early 7.5 high 1.6% 2011-04-07
CVE-2010-5003 EXP SQL injection vulnerability in the AutarTimonial (com_autartimonial) component 1.0.8 for Joomla! allows remote attackers to execute arbitrary SQL comm… Patch early 7.5 high 1.6% 2011-11-01
CVE-2002-1896 EXP Buffer overflow in Alsaplayer 0.99.71, when installed setuid root, allows local users to execute arbitrary code via a long (1) -f or (2) -o command li… Patch early 7.2 high 1.6% 2002-12-31
CVE-2007-6172 EXP Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewimage.ph… Patch early 10.0 high 1.6% 2007-11-30
CVE-2010-2909 EXP SQL injection vulnerability in ttvideo.php in the TTVideo (com_ttvideo) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL com… Patch early 7.5 high 1.6% 2010-07-28
CVE-2010-4865 EXP SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 1.6% 2011-10-05
CVE-2025-57642 EXP A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP shell scripts on the server, lead… Patch early 7.2 high 1.6% 2025-09-10
CVE-2007-1034 EXP SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attackers to execu… Patch early 7.5 high 1.6% 2007-02-21
CVE-2003-0127 EXP The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to a… Patch early 7.2 high 1.6% 2003-03-31
CVE-2018-13108 EXP All ADB broadband gateways / routers based on the Epicentro platform are affected by a local root jailbreak vulnerability where attackers are able to… Patch early 7.8 high 1.6% 2018-07-06
CVE-2023-6538 EXP SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Ser… Patch early 7.6 high 1.6% 2023-12-11
CVE-2001-0956 EXP speechd 0.54 and earlier, with the Festival or rsynth speech synthesis package, allows attackers to execute arbitrary commands via shell metacharacter… Patch early 7.2 high 1.6% 2001-09-11
CVE-2006-4392 EXP The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local users to gain privi… Patch early 7.2 high 1.6% 2006-10-03
CVE-2017-0313 EXP All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implementation of the SubmitCommandV… Patch early 7.8 high 1.6% 2017-02-15
CVE-2008-3768 EXP Multiple SQL injection vulnerabilities in class.ajax.php in Turnkey Web Tools SunShop Shopping Cart before 4.1.5 allow remote attackers to execute arb… Patch early 7.5 high 1.6% 2008-08-22
CVE-2018-18858 EXP Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate w… Patch early 7.8 high 1.6% 2018-11-20
CVE-2018-18859 EXP Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate w… Patch early 7.8 high 1.6% 2018-11-20
← previous page 307 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt