peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,355 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-7382 EXP SQL injection vulnerability in install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary SQL comm… Patch early 7.5 high 1.5% 2015-09-28
CVE-2002-0740 EXP Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges via a long -d (SPOOLDIR) argu… Patch early 7.2 high 1.5% 2002-08-12
CVE-2017-12579 EXP An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and earlier allows a non-root user to… Patch early 7.8 high 1.5% 2017-10-19
CVE-2024-51546 EXP Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXU… Patch early 7.5 high 1.5% 2024-12-05
CVE-2007-3629 EXP SQL injection vulnerability in oku.asp in Levent Veysi Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOT… Patch early 10.0 high 1.5% 2007-07-09
CVE-2016-7384 EXP For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability… Patch early 7.8 high 1.5% 2016-11-08
CVE-2006-6861 EXP Multiple SQL injection vulnerabilities in Outfront Spooky Login 2.7 allow remote attackers to execute arbitrary SQL commands via (1) the UserUpdate pa… Patch early 10.0 high 1.5% 2006-12-31
CVE-2015-2023 EXP Buffer overflow in IBM i Access 7.1 on Windows allows local users to gain privileges via unspecified vectors. Patch early 8.8 high 1.5% 2016-01-02
CVE-2012-0289 EXP Buffer overflow in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.710x and Symantec Network Access Control (SNAC) 11.0.600x through 11.0.71… Patch early 7.2 high 1.5% 2012-05-23
CVE-2017-3587 EXP Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Shared Folder). Supported versions that are affected are P… Patch early 8.4 high 1.5% 2017-04-24
CVE-2005-3838 EXP Multiple SQL injection vulnerabilities in search.php in IsolSoft Support Center 2.2 and earlier allow remote attackers to execute arbitrary SQL comman… Patch early 7.5 high 1.5% 2005-11-26
CVE-2002-1447 EXP Buffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative privileges via a long profile name… Patch early 7.2 high 1.5% 2002-05-28
CVE-2014-9632 EXP The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protection before 2015.5315 allows l… Patch early 7.2 high 1.5% 2015-02-06
CVE-2015-5602 EXP sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcard… Patch early 7.2 high 1.5% 2015-11-17
CVE-2006-3507 EXP Multiple stack-based buffer overflows in the AirPort wireless driver on Apple Mac OS X 10.3.9 and 10.4.7 allow physically proximate attackers to execu… Patch early 7.2 high 1.5% 2006-09-21
CVE-2006-1917 EXP SQL injection vulnerability in member.php in Blackorpheus ClanMemberSkript 1.0 allows remote attackers to execute arbitrary SQL commands via the userI… Patch early 7.5 high 1.5% 2006-04-20
CVE-2004-2202 EXP Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other comma… Patch early 7.5 high 1.5% 2004-12-31
CVE-2017-1000408 EXP A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that… Patch early 7.8 high 1.5% 2018-02-01
CVE-2008-4715 EXP SQL injection vulnerability in the Jpad (com_jpad) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid par… Patch early 7.5 high 1.5% 2008-10-23
CVE-2017-0312 EXP All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscapeID 0x100008… Patch early 7.8 high 1.4% 2017-02-15
CVE-2012-1603 EXP Multiple SQL injection vulnerabilities in ajaxserver.php in NextBBS 0.6 allow remote attackers to execute arbitrary SQL commands via the (1) curstr pa… Patch early 7.5 high 1.4% 2012-10-01
CVE-2026-54646 EXP CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values i… Patch early 7.2 high 1.4% 2026-09-17
CVE-2026-54647 EXP CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled do… Patch early 7.2 high 1.4% 2026-09-17
CVE-2017-5717 EXP Type Confusion in Content Protection HECI Service in Intel Graphics Driver allows unprivileged user to elevate privileges via local access. Patch early 7.8 high 1.4% 2017-12-12
CVE-2001-0764 EXP Buffer overflow in ntping in scotty 2.1.0 allows local users to execute arbitrary code via a long hostname as a command line argument. Patch early 7.2 high 1.4% 2001-10-18
CVE-2017-7952 EXP INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter. Patch early 8.8 high 1.4% 2017-05-16
CVE-2017-3575 EXP Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5… Patch early 7.9 high 1.4% 2017-04-24
CVE-2007-5449 EXP SQL injection vulnerability in searchresult.php in Softbiz Recipes Portal Script allows remote attackers to execute arbitrary SQL commands via the sbc… Patch early 7.5 high 1.4% 2007-10-14
CVE-2006-6365 EXP SQL injection vulnerability in detail.asp in DUware DUpaypal 3.1, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via… Patch early 7.5 high 1.4% 2006-12-07
CVE-2002-0767 EXP simpleinit on Linux systems does not close a read/write FIFO file descriptor before creating a child process, which allows the child process to cause… Patch early 7.2 high 1.4% 2002-08-12
← previous page 310 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt