peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,295 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

149,809 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-1982 EXP The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmwar… Patch early 10.0 high 9.5% 2014-03-31
CVE-2006-6740 EXP Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 9.5% 2006-12-26
CVE-2017-7041 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 8.8 high 9.5% 2017-07-20
CVE-2009-0955 EXP Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image desc… Patch early 9.3 high 9.5% 2009-06-02
CVE-2017-15276 EXP OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticat… Patch early 8.8 high 9.5% 2017-10-13
CVE-2002-2015 EXP PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the ca… Patch early 7.5 high 9.5% 2002-12-31
CVE-2018-18924 EXP The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" because reje… Patch early 8.8 high 9.5% 2018-11-04
CVE-2000-0639 EXP The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbit… Patch early 7.5 high 9.5% 2000-06-11
CVE-2005-1532 EXP Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, whi… Patch early 7.5 high 9.5% 2005-05-12
CVE-2005-3934 EXP Buffer overflow in Symantec pcAnywhere 11.0.1, 11.5.1, and all other 32-bit versions allows remote attackers to cause a denial of service (application… Patch early 7.8 high 9.5% 2005-12-01
CVE-2006-3192 EXP PHP remote file inclusion vulnerability in Ad Manager Pro 2.6 allows remote attackers to execute arbitrary PHP code via a URL in the (1) ipath paramet… Patch early 7.5 high 9.5% 2006-06-23
CVE-2007-2456 EXP Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root pa… Patch early 7.5 high 9.5% 2007-05-02
CVE-2015-7259 EXP ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid username and password pairs, w… Patch early 8.8 high 9.5% 2017-08-24
CVE-1999-0926 EXP Apache allows remote attackers to conduct a denial of service via a large number of MIME headers. Patch early 10.0 high 9.4% 1999-09-03
CVE-2002-0068 EXP Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an ftp:// URL… Patch early 7.5 high 9.4% 2002-03-08
CVE-2005-0838 EXP Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possibly execute arbitrary code via… Patch early 7.5 high 9.4% 2005-05-02
CVE-1999-0266 EXP The info2www CGI script allows remote file access or remote command execution. Patch early 7.5 high 9.4% 1998-03-01
CVE-2007-4586 EXP Multiple buffer overflows in php_iisfunc.dll in the iisfunc extension for PHP 5.2.0 and earlier allow context-dependent attackers to execute arbitrary… Patch early 7.5 high 9.4% 2007-08-29
CVE-2007-2428 EXP Multiple PHP remote file inclusion vulnerabilities in page.php in Ahhp-Portal allow remote attackers to execute arbitrary PHP code via a URL in the (1… Patch early 7.5 high 9.4% 2007-05-02
CVE-2000-0011 EXP Buffer overflow in AnalogX SimpleServer:WWW HTTP server allows remote attackers to execute commands via a long GET request. Patch early 7.5 high 9.4% 1999-12-31
CVE-2009-3850 EXP Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad… Patch early 9.3 high 9.4% 2009-11-06
CVE-2010-4233 EXP The Linux installation on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 has a default passwo… Patch early 10.0 high 9.4% 2010-11-17
CVE-2015-3203 EXP Unrestricted file upload vulnerability in h5ai before 0.25.0 allows remote attackers to execute arbitrary code by uploading a file with an executable… Patch early 7.5 high 9.4% 2015-09-28
CVE-2012-2208 EXP Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a ..… Patch early 7.5 high 9.4% 2012-08-14
CVE-2007-2070 EXP Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary… Patch early 7.5 high 9.4% 2007-04-18
CVE-2010-4283 EXP PHP remote file inclusion vulnerability in extras/pandora_diag.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 9.4% 2010-12-02
CVE-2007-1164 EXP Multiple PHP remote file inclusion vulnerabilities in DBImageGallery 1.2.2 allow remote attackers to execute arbitrary PHP code via a URL in the donsi… Patch early 7.5 high 9.4% 2007-03-02
CVE-2008-3681 EXP components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the… Patch early 7.5 high 9.4% 2008-08-14
CVE-2007-3294 EXP Multiple buffer overflows in libtidy, as used in the Tidy extension for PHP 5.2.3 and possibly other products, allow context-dependent attackers to ex… Patch early 7.5 high 9.4% 2007-06-20
CVE-2007-4903 EXP Multiple buffer overflows in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allow remote attackers to execute… Patch early 7.5 high 9.4% 2007-09-17
← previous page 157 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt