peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,373 CVEs 1,739 on KEV 17,299 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2011-4834 EXP The GetInstalledPackages function in the configuration tool in HP Application Lifestyle Management (ALM) 11 on AIX, HP-UX, and Solaris allows local us… Patch early 4.6 medium 1.2% 2011-12-15
CVE-2013-3095 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR865L router (Rev. A1) with firmware before 1.05b07 allow remote attackers to h… Patch early 6.8 medium 1.2% 2013-11-20
CVE-2009-2172 EXP Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows remote registered users to inje… Patch early 4.3 medium 1.2% 2009-06-23
CVE-2014-2317 EXP SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the table param… Patch early 6.8 medium 1.2% 2014-03-09
CVE-2017-14489 EXP The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to cause a denial of service (pa… Patch early 5.5 medium 1.2% 2017-09-15
CVE-2004-1415 EXP SQL injection vulnerability in (1) disp_album.php and possibly (2) disp_img.php in 2Bgal 2.4 and 2.5.1 allows remote attackers to execute arbitrary SQ… Patch early 5.0 medium 1.2% 2004-12-31
CVE-2005-2232 EXP Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitrary code via a long command line argument. Patch early 4.6 medium 1.2% 2005-07-12
CVE-2012-2959 EXP Cross-site request forgery (CSRF) vulnerability in password-manager/changePasswords.do in BMC Identity Management Suite 7.5.00.103 allows remote attac… Patch early 5.1 medium 1.2% 2012-06-11
CVE-2008-6479 EXP Cross-site request forgery (CSRF) vulnerability in the "change password" feature in the VZPP web interface for Parallels Virtuozzo 25.4.swsoft (build… Patch early 6.8 medium 1.2% 2009-03-16
CVE-2007-4362 EXP SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL commands via the cat parameter. Patch early 6.8 medium 1.2% 2007-08-15
CVE-2024-47605 EXP silverstripe-asset-admin is a silverstripe assets gallery for asset management. When using the "insert media" functionality, the linked oEmbed JSON in… Patch early 5.4 medium 1.2% 2025-01-14
CVE-2007-3449 EXP SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the newsid parameter. Patch early 6.8 medium 1.1% 2007-06-27
CVE-2007-3979 EXP SQL injection vulnerability in index.php in BlogSite Professional (aka Blog System) 1.x allows remote attackers to execute arbitrary SQL commands via… Patch early 6.8 medium 1.1% 2007-07-25
CVE-2008-6657 EXP Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attac… Patch early 6.8 medium 1.1% 2009-04-07
CVE-2010-2039 EXP Cross-site request forgery (CSRF) vulnerability in gpEasy CMS 1.6.2, 1.6.1, and earlier allows remote attackers to hijack the authentication of admini… Patch early 6.8 medium 1.1% 2010-05-25
CVE-2010-3891 EXP Cross-site request forgery (CSRF) vulnerability in ESAdmin/security.do in the administrator interface in IBM OmniFind Enterprise Edition before 9.1 al… Patch early 6.8 medium 1.1% 2010-11-12
CVE-2006-2264 EXP Multiple SQL injection vulnerabilities in Ocean12 Calendar Manager Pro 1.00 allow remote attackers to execute arbitrary SQL commands via the (1) date… Patch early 6.5 medium 1.1% 2006-05-09
CVE-2024-30167 EXP /cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a POST reques… Patch early 6.3 medium 1.1% 2026-05-08
CVE-2016-8641 EXP A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the… Patch early 6.7 medium 1.1% 2018-08-01
CVE-2007-3447 EXP SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the "basic search b… Patch early 6.8 medium 1.1% 2007-06-27
CVE-2006-1773 EXP SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands via the con… Patch early 6.4 medium 1.1% 2006-04-13
CVE-2006-6383 EXP PHP 5.2.0 and 4.4 allows local users to bypass safe_mode and open_basedir restrictions via a malicious path and a null byte before a ";" in a session_… Patch early 4.6 medium 1.1% 2006-12-10
CVE-2006-2889 EXP Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL commands, and le… Patch early 5.1 medium 1.1% 2006-06-07
CVE-1999-0125 EXP Buffer overflow in SGI IRIX mailx program. Patch early 4.6 medium 1.1% 1998-01-25
CVE-2003-0955 EXP OpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code in 3.4 via a program wit… Patch early 4.6 medium 1.1% 2003-12-15
CVE-2017-7154 EXP An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. The is… Patch early 6.6 medium 1.1% 2017-12-27
CVE-2006-5676 EXP SQL injection vulnerability in consult/classement.php in Uni-Vert PhpLeague 0.82 and earlier allows remote attackers to execute arbitrary SQL commands… Patch early 6.4 medium 1.1% 2006-11-03
CVE-2012-5683 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to hijack the authentication of adminis… Patch early 6.8 medium 1.1% 2014-08-14
CVE-2014-2043 EXP SQL injection vulnerability in Resources/System/Templates/Data.aspx in Procentia IntelliPen before 1.1.18.1658 allows remote authenticated users to ex… Patch early 6.5 medium 1.1% 2014-03-13
CVE-2005-0993 EXP Buffer overflow in nwprint in SCO OpenServer 5.0.7 allows local users to execute arbitrary code via a long command line argument. Patch early 4.6 medium 1.1% 2005-05-02
← previous page 311 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt