peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,370 CVEs 1,739 on KEV 17,299 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2011-1667 EXP SQL injection vulnerability in index.php in Anzeigenmarkt 2011 allows remote attackers to execute arbitrary SQL commands via the q parameter in a list… Patch early 7.5 high 1.4% 2011-04-10
CVE-2007-3909 EXP Multiple SQL injection vulnerabilities in Bandersnatch 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) date and (2) limit par… Patch early 7.5 high 1.4% 2007-07-19
CVE-2011-3918 EXP The Zygote process in Android 4.0.3 and earlier accepts fork requests from processes with arbitrary UIDs, which allows remote attackers to cause a den… Patch early 7.8 high 1.4% 2012-10-07
CVE-2004-1562 EXP SQL injection vulnerability in redir_url.php in w-Agora 4.1.6a allows remote attackers to execute arbitrary SQL commands via the key parameter. Patch early 7.5 high 1.4% 2004-12-31
CVE-2004-2263 EXP SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements via the v… Patch early 7.5 high 1.4% 2004-12-31
CVE-2004-2562 EXP SQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remote attackers to execute arbitra… Patch early 7.5 high 1.4% 2004-12-31
CVE-2005-1479 EXP SQL injection vulnerability in jgs_portal.php in JGS-Portal 3.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id par… Patch early 7.5 high 1.4% 2005-05-11
CVE-2005-3940 EXP SQL injection vulnerability in ringmaker.php in Orca Ringmaker 2.3c and earlier allows remote attackers to execute arbitrary SQL commands via the star… Patch early 7.5 high 1.4% 2005-12-01
CVE-2005-3941 EXP SQL injection vulnerability in blog.php in Orca Blog 1.3b and earlier allows remote attackers to execute arbitrary SQL commands via the msg parameter. Patch early 7.5 high 1.4% 2005-12-01
CVE-2005-3942 EXP SQL injection vulnerability in knowledgebase-control.php in Orca Knowledgebase 2.1b and earlier allows remote attackers to execute arbitrary SQL comma… Patch early 7.5 high 1.4% 2005-12-01
CVE-2015-7892 EXP Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in Samsung S6 Edge, allows local… Patch early 7.8 high 1.4% 2019-12-09
CVE-2014-8347 EXP An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.0… Patch early 7.8 high 1.4% 2020-02-11
CVE-2023-31873 EXP Gin 0.7.4 allows execution of arbitrary code when a crafted file is opened, e.g., via require('child_process'). Patch early 7.8 high 1.3% 2023-05-28
CVE-2007-6078 EXP Multiple SQL injection vulnerabilities in SkyPortal RC6 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) nc_… Patch early 7.5 high 1.3% 2007-11-21
CVE-2005-3937 EXP SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the… Patch early 7.5 high 1.3% 2005-12-01
CVE-2018-10712 EXP The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and Resta… Patch early 7.8 high 1.3% 2018-10-30
CVE-2000-0471 EXP Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname. Patch early 7.2 high 1.3% 2000-06-14
CVE-2017-8824 EXP The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of service… Patch early 7.8 high 1.3% 2017-12-05
CVE-2000-0193 EXP The default configuration of Dosemu in Corel Linux 1.0 allows local users to execute the system.com program and gain privileges. Patch early 7.2 high 1.3% 2000-03-02
CVE-2002-0004 EXP Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free… Patch early 7.2 high 1.3% 2002-02-27
CVE-2016-3653 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 al… Patch early 8.0 high 1.3% 2016-06-30
CVE-2015-1364 EXP SQL injection vulnerability in the getProfile function in system/profile.functions.php in Free Reprintables ArticleFR 3.0.5 allows remote attackers to… Patch early 7.5 high 1.3% 2015-01-27
CVE-2005-2062 EXP Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands via the catid parameter to (1)… Patch early 7.5 high 1.3% 2005-06-29
CVE-2004-1531 EXP SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands vi… Patch early 7.5 high 1.3% 2004-12-31
CVE-2010-4272 EXP SQL injection vulnerability in the Pulse Infotech Sponsor Wall (com_sponsorwall) component 1.1 for Joomla! allows remote attackers to execute arbitrar… Patch early 7.5 high 1.3% 2010-11-17
CVE-2009-1024 EXP Multiple SQL injection vulnerabilities in Beerwin PHPLinkAdmin 1.0 allow remote attackers to execute arbitrary SQL commands via the linkid parameter t… Patch early 7.5 high 1.3% 2009-03-20
CVE-2009-1742 EXP code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks via crafted keyword sequences th… Patch early 7.5 high 1.3% 2009-05-20
CVE-2001-0759 EXP Buffer overflow in bctool in Jetico BestCrypt 0.8.1 and earlier allows local users to execute arbitrary code via a file or directory with a long pathn… Patch early 7.2 high 1.3% 2001-10-18
CVE-2006-7071 EXP SQL injection vulnerability in classes/class_session.php in Invision Power Board (IPB) 2.1 up to 2.1.6 allows remote attackers to execute arbitrary SQ… Patch early 7.5 high 1.3% 2007-03-02
CVE-2017-15578 EXP In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php. Patch early 8.8 high 1.3% 2017-10-18
← previous page 313 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt