peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,573 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

149,897 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-4244 EXP PHP remote file inclusion vulnerability in langset.php in J! Reactions (com_jreactions) 1.8.1 and earlier, a Joomla! component, allows remote attacker… Patch early 7.5 high 7.8% 2007-08-08
CVE-2010-3126 EXP Untrusted search path vulnerability in avast! Free Antivirus version 5.0.594 and earlier allows local users, and possibly remote attackers, to execute… Patch early 9.3 high 7.8% 2010-08-26
CVE-2010-3137 EXP Untrusted search path vulnerability in Nullsoft Winamp 5.581, and probably other versions, allows local users, and possibly remote attackers, to execu… Patch early 9.3 high 7.8% 2010-08-26
CVE-2013-6343 EXP Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow remote attackers to execute a… Patch early 10.0 high 7.8% 2014-01-22
CVE-2002-0982 EXP Microsoft SQL Server 2000 SP2, when configured as a distributor, allows attackers to execute arbitrary code via the @scriptfile parameter to the sp_MS… Patch early 7.5 high 7.8% 2002-09-24
CVE-2018-10608 EXP SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects to a malicious FTP server, wh… Patch early 7.5 high 7.8% 2018-07-24
CVE-2012-3816 EXP WinRadius Server 2009 allows remote attackers to cause a denial of service (crash) via a long password in an Access-Request packet. Patch early 7.8 high 7.8% 2012-06-27
CVE-2008-6178 EXP Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4 CMS, Nuke… Patch early 7.5 high 7.8% 2009-02-19
CVE-2019-19142 EXP Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmware.cfg URI. Patch early 7.5 high 7.8% 2020-01-17
CVE-2000-0688 EXP Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for t… Patch early 7.5 high 7.8% 2000-10-20
CVE-2000-0689 EXP Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges fo… Patch early 7.5 high 7.8% 2000-10-20
CVE-2008-3360 EXP Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code via a long URL in the HREF att… Patch early 9.3 high 7.8% 2008-07-29
CVE-2012-3549 EXP The SCTP implementation in FreeBSD 8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted… Patch early 7.8 high 7.8% 2012-10-09
CVE-2019-11446 EXP An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files se… Patch early 8.8 high 7.8% 2019-04-22
CVE-2021-27825 EXP A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL. Patch early 7.5 high 7.8% 2023-05-29
CVE-2013-3956 EXP The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2 on Windows Vista and Windows… Patch early 7.2 high 7.8% 2013-07-31
CVE-2006-5196 EXP The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with… Patch early 7.8 high 7.8% 2006-10-10
CVE-2012-6470 EXP Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a denial of serv… Patch early 9.3 high 7.8% 2013-01-02
CVE-2007-1568 EXP Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via a yEnc (yEncode) encoded arti… Patch early 10.0 high 7.8% 2007-03-21
CVE-2018-19277 EXP securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file Patch early 8.8 high 7.8% 2018-11-14
CVE-2017-2468 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… Patch early 8.8 high 7.8% 2017-04-02
CVE-2019-15104 EXP An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via… Patch early 8.8 high 7.8% 2019-08-16
CVE-2019-15105 EXP An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration… Patch early 8.8 high 7.8% 2019-08-16
CVE-2017-17538 EXP MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets. Patch early 7.5 high 7.8% 2017-12-13
CVE-2007-2594 EXP PHP remote file inclusion vulnerability in inc/articles.inc.php in phpMyPortal 3.0.0 RC3 allows remote attackers to execute arbitrary PHP code via a U… Patch early 7.5 high 7.8% 2007-05-11
CVE-2007-6179 EXP Multiple PHP remote file inclusion vulnerabilities in Charray's CMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the ccms_l… Patch early 7.5 high 7.8% 2007-11-30
CVE-2002-0335 EXP Buffer overflow in Galacticomm Worldgroup web server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbit… Patch early 10.0 high 7.8% 2002-06-25
CVE-2017-15012 EXP OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILE RPC-comma… Patch early 8.8 high 7.8% 2017-10-13
CVE-2007-4596 EXP The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eval… Patch early 7.5 high 7.8% 2007-08-30
CVE-2003-0595 EXP Buffer overflow in WiTango Application Server and Tango 2000 allows remote attackers to execute arbitrary code via a long cookie to Witango_UserRefere… Patch early 7.5 high 7.8% 2003-08-27
← previous page 175 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt