peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,322 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-7228 EXP An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced a… Patch early 8.2 high 1.6% 2017-04-04
CVE-2014-5288 EXP A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages. Patch early 8.8 high 1.6% 2020-02-07
CVE-2016-9793 EXP The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows… Patch early 7.8 high 1.6% 2016-12-28
CVE-2018-15657 EXP An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter. Patch early 7.3 high 1.6% 2019-02-05
CVE-2018-0492 EXP Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation. Patch early 7.0 high 1.6% 2018-04-03
CVE-2015-2866 EXP SQL injection vulnerability on the Grandstream GXV3611_HD camera with firmware before 1.0.3.9 beta allows remote attackers to execute arbitrary SQL co… Patch early 7.5 high 1.6% 2015-07-08
CVE-2017-15595 EXP An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (unbounded recursion, stack consumption, and… Patch early 8.8 high 1.6% 2017-10-18
CVE-2016-7391 EXP For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability… Patch early 7.8 high 1.6% 2016-11-08
CVE-2001-0979 EXP Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long command line argument. Patch early 7.2 high 1.6% 2001-09-03
CVE-2002-0572 EXP FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the f… Patch early 7.2 high 1.6% 2002-07-03
CVE-2025-32370 EXP Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is… Patch early 7.2 high 1.6% 2025-04-06
CVE-2014-8507 EXP Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/WapPushManager.java in the WAPPus… Patch early 7.5 high 1.6% 2014-12-15
CVE-2018-5282 EXP Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password field in a SilentInstall XML docu… Patch early 7.8 high 1.5% 2018-01-08
CVE-2008-0735 EXP SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the albu… Patch early 10.0 high 1.5% 2008-02-13
CVE-2020-8424 EXP Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php. Patch early 8.8 high 1.5% 2020-01-28
CVE-2018-10711 EXP The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and Resta… Patch early 7.8 high 1.5% 2018-10-30
CVE-2012-6643 EXP Multiple SQL injection vulnerabilities in the update_counter function in includes/functions.php in ClipBucket 2.6 allow remote attackers to execute ar… Patch early 7.5 high 1.5% 2014-04-08
CVE-2014-9226 EXP The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0… Patch early 7.2 high 1.5% 2015-01-21
CVE-2017-3561 EXP Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5… Patch early 8.8 high 1.5% 2017-04-24
CVE-2017-3576 EXP Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5… Patch early 8.8 high 1.5% 2017-04-24
CVE-2014-9322 EXP arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register,… Patch early 7.8 high 1.5% 2014-12-17
CVE-2000-0194 EXP buildxconf in Corel Linux allows local users to modify or create arbitrary files via the -x or -f parameters. Patch early 7.2 high 1.5% 2000-02-24
CVE-2000-0195 EXP setxconf in Corel Linux allows local users to gain root access via the -T parameter, which executes the user's .xserverrc file. Patch early 7.2 high 1.5% 2000-02-24
CVE-2007-2810 EXP SQL injection vulnerability in down_indir.asp in Gazi Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.… Patch early 10.0 high 1.5% 2007-05-22
CVE-2016-7390 EXP For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability… Patch early 7.8 high 1.5% 2016-11-08
CVE-2016-8805 EXP For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability… Patch early 7.8 high 1.5% 2016-11-08
CVE-2016-8810 EXP For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability… Patch early 7.8 high 1.5% 2016-11-08
CVE-2014-2934 EXP Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers to execute arbitrary SQL commands via the tr parameter to (1) costview2/… Patch early 7.5 high 1.5% 2014-05-08
CVE-2001-1015 EXP Buffer overflow in Snes9x 1.37, when installed setuid root, allows local users to gain root privileges via a long command line argument. Patch early 7.2 high 1.5% 2001-10-16
CVE-2003-1461 EXP Buffer overflow in rwrite for HP-UX 11.0 could allow local users to execute arbitrary code via a long argument. NOTE: the vendor was unable to reprod… Patch early 7.2 high 1.5% 2003-12-31
← previous page 308 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt