peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,085 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

150,069 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-1929 EXP SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and… Patch early 7.5 high 6.7% 2004-04-13
CVE-2007-2283 EXP Buffer overflow in Fresh View 7.15 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file. Patch early 9.3 high 6.7% 2007-04-26
CVE-2007-2284 EXP Buffer overflow in ABC-View Manager 1.42 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file. Patch early 9.3 high 6.7% 2007-04-26
CVE-2008-4471 EXP Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Revit Archite… Patch early 9.3 high 6.7% 2008-10-07
CVE-2017-7047 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. wa… Patch early 8.8 high 6.7% 2017-07-20
CVE-2007-2043 EXP Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier module for Mambo and Joomla!… Patch early 7.5 high 6.7% 2007-04-16
CVE-2009-3076 EXP Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operati… Patch early 9.3 high 6.7% 2009-09-10
CVE-2012-5048 EXP APIFTP Server in Optimalog Optima PLC 1.5.2 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon cras… Patch early 7.8 high 6.7% 2012-09-28
CVE-2008-2898 EXP Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and execute arbitrary local files via… Patch early 9.3 high 6.7% 2008-06-27
CVE-2017-13794 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 6.7% 2017-11-13
CVE-2015-7257 EXP ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin pa… Patch early 7.5 high 6.7% 2017-08-24
CVE-2004-1752 EXP Stack-based buffer overflow in Gaucho 1.4 Build 145 allows remote attackers to execute arbitrary code via a POP3 email with a long Content-Type header… Patch early 7.5 high 6.7% 2004-08-24
CVE-2004-1868 EXP Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag. Patch early 7.5 high 6.7% 2004-03-25
CVE-2009-4654 EXP Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to execute arbitrary code v… Patch early 9.0 high 6.7% 2010-02-26
CVE-2013-6234 EXP Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by… Patch early 8.0 high 6.7% 2019-11-22
CVE-2006-6445 EXP Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files vi… Patch early 7.5 high 6.7% 2006-12-10
CVE-2002-2190 EXP ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords v… Patch early 7.5 high 6.7% 2002-12-31
CVE-2015-1560 EXP SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (… Patch early 7.5 high 6.7% 2015-07-14
CVE-2018-6889 EXP An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the w… Patch early 8.8 high 6.7% 2018-02-12
CVE-2009-2258 EXP Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attac… Patch early 7.8 high 6.7% 2009-06-30
CVE-2007-1718 EXP CRLF injection vulnerability in the mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows remote attackers to inject arbitrary e-mai… Patch early 7.8 high 6.7% 2007-03-28
CVE-2002-2295 EXP Buffer overflow in Pico Server (pServ) 2.0 beta 1 through beta 5 allows remote attackers to cause a denial of service (crash) and possibly execute arb… Patch early 7.5 high 6.7% 2002-12-31
CVE-2007-5636 EXP Buffer overflow in the Nortel UNIStim IP Softphone 2050 allows remote attackers to cause a denial of service (application abort) and possibly execute… Patch early 7.5 high 6.7% 2007-10-23
CVE-2017-6191 EXP Buffer overflow in APNGDis 2.8 and below allows a remote attacker to execute arbitrary code via a crafted filename. Patch early 7.8 high 6.7% 2017-03-23
CVE-2008-7012 EXP courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before F… Patch early 7.8 high 6.7% 2009-08-19
CVE-2016-10081 EXP /usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishan… Patch early 7.8 high 6.7% 2016-12-29
CVE-2001-1202 EXP Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page, which allows rem… Patch early 7.5 high 6.7% 2001-12-28
CVE-2005-1520 EXP Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attac… Patch early 7.5 high 6.7% 2005-05-26
CVE-2002-1147 EXP The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration enabled, does… Patch early 7.1 high 6.7% 2002-10-11
CVE-2021-46398 EXP A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get… Patch early 8.8 high 6.7% 2022-02-04
← previous page 191 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt