peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,997 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

150,025 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-2648 EXP Stack-based buffer overflow in the Clever Database Comparer 2.2 ActiveX control (comparerax.ocx) allows remote attackers to execute arbitrary code via… Patch early 9.3 high 7% 2007-05-14
CVE-2015-6763 EXP Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service or possibly have other impact v… Patch early 7.5 high 7% 2015-10-15
CVE-2013-4859 EXP INSTEON Hub 2242-222 lacks Web and API authentication Patch early 8.1 high 7% 2019-12-27
CVE-2001-1104 EXP SonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions. Patch early 7.5 high 7% 2001-07-25
CVE-2007-4067 EXP Absolute path traversal vulnerability in the clInetSuiteX6.clWebDav ActiveX control in CLINETSUITEX6.OCX in Clever Internet ActiveX Suite 6.2 allows r… Patch early 9.3 high 7% 2007-07-30
CVE-2017-3316 EXP Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions that are affected are VirtualBox… Patch early 8.4 high 7% 2017-01-27
CVE-2019-10652 EXP An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .php files, related to the addon… Patch early 7.2 high 7% 2019-03-30
CVE-2018-10255 EXP A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command th… Patch early 8.8 high 7% 2018-05-01
CVE-2006-4885 EXP PHP remote file inclusion vulnerability in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ro… Patch early 7.5 high 7% 2006-09-19
CVE-2006-4904 EXP Dynamic variable evaluation vulnerability in cmpi.php in Qualiteam X-Cart 4.1.3 and earlier allows remote attackers to overwrite arbitrary program var… Patch early 7.5 high 7% 2006-09-21
CVE-2006-4921 EXP PHP remote file inclusion vulnerability in Site@School (S@S) 2.4.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 7% 2006-09-21
CVE-2010-4332 EXP Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values… Patch early 7.5 high 7% 2010-12-22
CVE-2001-0838 EXP Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -… Patch early 7.5 high 7% 2001-12-06
CVE-2003-0765 EXP The IN_MIDI.DLL plugin 3.01 and earlier, as used in Winamp 2.91, allows remote attackers to execute arbitrary code via a MIDI file with a large "Track… Patch early 7.5 high 7% 2003-09-17
CVE-2007-1041 EXP Multiple stack-based buffer overflows in S&H Computer Systems News Rover 12.1 Rev 1 allow remote attackers to execute arbitrary code via a .nzb file w… Patch early 9.3 high 6.9% 2007-02-21
CVE-2023-2636 EXP The AN_GradeBook WordPress plugin through 5.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL… Patch early 8.8 high 6.9% 2023-07-17
CVE-2001-1044 EXP Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which cou… Patch early 7.5 high 6.9% 2001-01-11
CVE-2002-1427 EXP The print_html_to_file function in edit.cgi for Easy Homepage Creator 1.0 does not check user credentials, which allows remote attackers to modify hom… Patch early 7.5 high 6.9% 2003-04-11
CVE-2004-1724 EXP The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execut… Patch early 7.5 high 6.9% 2004-08-18
CVE-2005-1366 EXP Pico Server (pServ) 3.2 and earlier allows remote attackers to obtain the source code for CGI scripts via "dirname/../cgi-bin" in a URL. Patch early 7.5 high 6.9% 2005-05-16
CVE-2019-8765 EXP Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Processing maliciously crafted web… Patch early 8.8 high 6.9% 2019-12-18
CVE-2004-1854 EXP Buffer overflow in the logging function in Picophone 1.63 and earlier allows remote attackers to execute arbitrary code via a large packet. Patch early 7.5 high 6.9% 2004-03-24
CVE-2004-2037 EXP Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute a… Patch early 7.5 high 6.9% 2004-03-24
CVE-2005-2767 EXP Buffer overflow in LeapFTP allows remote attackers to execute arbitrary code via a long Host string in a Site Queue (.lsq) file. Patch early 7.5 high 6.9% 2005-09-02
CVE-2010-3136 EXP Untrusted search path vulnerability in Skype 4.2.0.169 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and co… Patch early 9.3 high 6.9% 2010-08-26
CVE-2002-1463 EXP Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/1200/1300, and Gateway Security 5… Patch early 7.5 high 6.9% 2003-06-09
CVE-2015-6639 EXP The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted… Patch early 7.8 high 6.9% 2016-01-06
CVE-2008-3285 EXP The Filesys::SmbClientParser module 2.7 and earlier for Perl allows remote SMB servers to execute arbitrary code via a folder name containing shell me… Patch early 9.3 high 6.9% 2008-07-24
CVE-2003-1240 EXP PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in… Patch early 7.5 high 6.9% 2003-12-31
CVE-2019-8624 EXP An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5.3. A remote attacker may be able to leak memory. Patch early 7.5 high 6.9% 2019-12-18
← previous page 188 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt