peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,567 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

149,897 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-4254 EXP Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 allows local users to gain privileges via unspecified vectors. Patch early 7.5 high 7.9% 2006-08-21
CVE-2005-4171 EXP The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbi… Patch early 7.5 high 7.9% 2005-12-11
CVE-2006-3845 EXP Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a L… Patch early 9.3 high 7.9% 2006-07-25
CVE-2006-5289 EXP Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 7.9% 2006-10-13
CVE-2006-3019 EXP Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPCMS_INC… Patch early 7.5 high 7.9% 2006-06-15
CVE-2006-4834 EXP PHP remote file inclusion vulnerability in index.php in Jule Slootbeek phpQuiz 0.01 allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 7.9% 2006-09-15
CVE-2016-3986 EXP Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a crafted PE file, related to a… Patch early 7.8 high 7.9% 2016-04-12
CVE-2016-9349 EXP An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system and extract files that can re… Patch early 7.5 high 7.9% 2017-02-13
CVE-2001-0857 EXP Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users… Patch early 7.5 high 7.9% 2001-12-06
CVE-2008-6947 EXP Collabtive 0.4.8 allows remote attackers to bypass authentication and create new users, including administrators, via unspecified vectors associated w… Patch early 7.5 high 7.9% 2009-08-12
CVE-2001-0307 EXP Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP req… Patch early 7.5 high 7.9% 2001-05-03
CVE-2009-4679 EXP Directory traversal vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.5 for Joomla! allows remote attackers to include a… Patch early 7.5 high 7.9% 2010-03-08
CVE-2022-39290 EXP ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by mod… Patch early 8.0 high 7.9% 2022-10-07
CVE-2016-4469 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to hijack the authentication of… Patch early 8.8 high 7.9% 2016-07-28
CVE-2007-3266 EXP Directory traversal vulnerability in webif.cgi in ifnet WEBIF allows remote attackers to include and execute arbitrary local files a .. (dot dot) in t… Patch early 9.0 high 7.9% 2007-06-19
CVE-2017-9747 EXP The ieee_archive_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow r… Patch early 7.8 high 7.9% 2017-06-19
CVE-2017-9748 EXP The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow re… Patch early 7.8 high 7.9% 2017-06-19
CVE-2015-1265 EXP Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a denial of service or possibly have other impact v… Patch early 7.5 high 7.9% 2015-05-20
CVE-2005-0305 EXP CRLF injection vulnerability in users.php in Siteman 1.1.10 and earlier allows remote attackers to add arbitrary users and gain privileges via the lin… Patch early 7.5 high 7.9% 2005-05-02
CVE-2002-0330 EXP Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to execute arbitrary script and stea… Patch early 7.5 high 7.9% 2002-06-25
CVE-2019-11660 EXP Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability coul… Patch early 7.8 high 7.8% 2019-09-13
CVE-2006-4824 EXP PHP remote file inclusion vulnerability in lib/activeutil.php in Quicksilver Forums (QSF) 1.2.1 and earlier allows remote attackers to execute arbitra… Patch early 7.5 high 7.8% 2006-09-15
CVE-2006-4918 EXP Multiple PHP remote file inclusion vulnerabilities in Simple Discussion Board 0.1.0 allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 7.8% 2006-09-21
CVE-2020-12712 EXP A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows attackers to dec… Patch early 7.5 high 7.8% 2020-06-11
CVE-2007-0020 EXP Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote attackers to execute arbitrary cod… Patch early 9.3 high 7.8% 2007-01-24
CVE-1999-0101 EXP Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names. Patch early 10.0 high 7.8% 1996-12-10
CVE-2008-4472 EXP The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review… Patch early 9.3 high 7.8% 2008-10-07
CVE-2007-1890 EXP Integer overflow in the msg_receive function in PHP 4 before 4.4.5 and PHP 5 before 5.2.1, on FreeBSD and possibly other platforms, allows context-dep… Patch early 7.5 high 7.8% 2007-04-06
CVE-2010-3130 EXP Untrusted search path vulnerability in TechSmith Snagit all versions 10.x and 11.x allows local users, and possibly remote attackers, to execute arbit… Patch early 9.3 high 7.8% 2010-08-26
CVE-2026-46368 EXP luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt commun… Patch early 8.8 high 7.8% 2026-05-26
← previous page 174 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt