peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,957 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

186,766 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-1608 EXP vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated users to execute arbitrary comm… Patch early 8.8 high 11.3% 2016-08-01
CVE-2010-4278 EXP operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters… Patch early 9.0 high 11.3% 2010-12-02
CVE-2009-4018 EXP The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and… Patch early 7.5 high 11.3% 2009-11-29
CVE-2007-1421 EXP Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root… Patch early 10.0 high 11.3% 2007-03-13
CVE-2010-3154 EXP Untrusted search path vulnerability in Adobe Extension Manager CS5 5.0.298 allows local users, and possibly remote attackers, to execute arbitrary cod… Patch early 9.3 high 11.3% 2010-08-27
CVE-2017-9430 EXP Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified ot… Patch early 9.8 critical 11.3% 2017-06-05
CVE-2010-0416 EXP Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix Player 1.0.6 and RealPlayer al… Patch early 7.5 high 11.3% 2010-02-18
CVE-2020-25762 EXP An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and… Patch early 9.1 critical 11.3% 2020-09-30
CVE-2017-17759 EXP Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the confi… Patch early 9.8 critical 11.3% 2017-12-19
CVE-2008-1461 EXP Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the command line. NO… Patch early 7.6 high 11.3% 2008-03-24
CVE-2006-4920 EXP Multiple PHP remote file inclusion vulnerabilities in Site@School (S@S) 2.4.02 and earlier allow remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 11.3% 2006-09-21
CVE-2017-2370 EXP An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. wa… Patch early 7.8 high 11.3% 2017-02-20
CVE-2018-11511 EXP The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' o… Patch early 9.8 critical 11.3% 2018-08-16
CVE-2008-4547 EXP Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows remote attackers to execute a… Patch early 9.3 high 11.3% 2008-10-14
CVE-2000-0944 EXP CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allow… Patch early 9.8 critical 11.3% 2000-12-19
CVE-2017-9812 EXP The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Ma… Patch early 7.5 high 11.3% 2017-07-17
CVE-2017-16953 EXP connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration o… Patch early 7.5 high 11.3% 2017-12-01
CVE-2002-0613 EXP dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user_logged_in or… Patch early 10.0 high 11.3% 2002-06-18
CVE-2020-15261 EXP On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally authenticated users with administr… Patch early 8.0 high 11.3% 2020-10-19
CVE-2019-6274 EXP Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified impa… Patch early 8.8 high 11.2% 2019-03-21
CVE-2013-5660 EXP Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file. Patch early 9.3 high 11.2% 2014-04-25
CVE-2013-7246 EXP Buffer overflow in the IconCreate method in an ActiveX control in the DaumGame ActiveX plugin 1.1.0.4 and 1.1.0.5 allows remote attackers to execute a… Patch early 9.3 high 11.2% 2014-01-30
CVE-2001-1163 EXP Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500. Patch early 10.0 high 11.2% 2001-06-16
CVE-2014-4927 EXP Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to c… Patch early 7.8 high 11.2% 2014-07-24
CVE-2004-2652 EXP The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attacke… Patch early 7.8 high 11.2% 2004-12-31
CVE-2004-1260 EXP Multiple buffer overflows in the (1) write_heading function in subs.cpp or (2) trim_title function in parse.cpp for abctab2ps 1.6.3 allow remote attac… Patch early 10.0 high 11.2% 2005-01-10
CVE-2009-1608 EXP Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrary code via… Patch early 9.3 high 11.2% 2009-05-11
CVE-2016-9651 EXP A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arb… Patch early 8.8 high 11.2% 2019-01-09
CVE-2015-2196 EXP SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id para… Patch early 7.5 high 11.2% 2015-03-03
CVE-2007-4061 EXP Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to create or overwrite ar… Patch early 9.3 high 11.2% 2007-07-30
← previous page 188 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt