peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,908 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

150,376 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-1933 EXP Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a… Patch early 7.5 high 6.3% 2007-04-10
CVE-2007-3932 EXP uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to… Patch early 7.5 high 6.3% 2007-07-21
CVE-2008-6535 EXP admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the administrative password via a direc… Patch early 7.5 high 6.3% 2009-03-26
CVE-2004-1535 EXP PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by m… Patch early 7.5 high 6.3% 2004-12-31
CVE-2005-0513 EXP PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions includi… Patch early 7.5 high 6.3% 2005-02-19
CVE-2007-6041 EXP Buffer overflow in the Sequencer::queueMessage function in sequencer.cpp in the server in Rigs of Rods (RoR) before 0.33d SP1 allows remote attackers… Patch early 7.5 high 6.3% 2007-11-20
CVE-2006-6690 EXP rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote auth… Patch early 7.5 high 6.3% 2006-12-21
CVE-2007-2777 EXP Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execut… Patch early 7.5 high 6.3% 2007-05-21
CVE-2008-6761 EXP Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject arbitrary PHP code into const.in… Patch early 10.0 high 6.3% 2009-04-28
CVE-2012-4057 EXP Buffer overflow in the Player in Remote-Anything 5.60.15 allows remote attackers to execute arbitrary code via a crafted flm file. Patch early 9.3 high 6.3% 2012-07-25
CVE-2017-7039 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 8.8 high 6.3% 2017-07-20
CVE-2017-7040 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 8.8 high 6.3% 2017-07-20
CVE-2017-7043 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 8.8 high 6.3% 2017-07-20
CVE-2007-3168 EXP A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attacker… Patch early 7.8 high 6.3% 2007-06-11
CVE-2006-1495 EXP SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attack… Patch early 7.5 high 6.3% 2006-03-30
CVE-2008-0143 EXP PHP remote file inclusion vulnerability in common/db.php in samPHPweb, possibly 4.2.2 and others, as provided with SAM Broadcaster, allows remote atta… Patch early 7.5 high 6.3% 2008-01-08
CVE-2014-9448 EXP Buffer overflow in Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 allows remote attackers to execute arbitrary code or cause a denial of service (cra… Patch early 7.5 high 6.3% 2015-01-02
CVE-2002-0388 EXP Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Piperm… Patch early 7.5 high 6.3% 2002-06-18
CVE-2007-6593 EXP Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as used by IBM Lotus Notes 5.x through 8.x, allow user-… Patch early 8.8 high 6.3% 2007-12-28
CVE-2008-3486 EXP Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier,… Patch early 7.5 high 6.3% 2008-08-06
CVE-2022-47879 EXP A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the… Patch early 7.5 high 6.3% 2023-05-12
CVE-2014-4018 EXP The ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK has a default password of admin for the admin account, which makes it easier for remote att… Patch early 7.8 high 6.3% 2014-07-16
CVE-2018-10286 EXP The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credenti… Patch early 8.8 high 6.3% 2018-04-22
CVE-2008-4664 EXP Heap-based buffer overflow in QvodInsert.QvodCtrl.1 ActiveX control (QvodInsert.dll) in QVOD Player before 2.1.5 build 0053 allows remote attackers to… Patch early 9.3 high 6.3% 2008-10-22
CVE-2008-2076 EXP Directory traversal vulnerability in admin.php in ActualScripts ActualAnalyzer Lite 2.78 allows remote attackers to include and execute arbitrary loca… Patch early 7.5 high 6.3% 2008-05-05
CVE-2020-25453 EXP An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution. Patch early 8.8 high 6.3% 2020-09-15
CVE-2012-4865 EXP Buffer overflow in Oreans Themida 2.1.8.0 allows remote attackers to execute arbitrary code via a crafted .TMD file. Patch early 9.3 high 6.3% 2012-09-06
CVE-2012-5324 EXP Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange 3.60.0128 allow remote attack… Patch early 9.3 high 6.3% 2012-10-08
CVE-2006-4898 EXP PHP remote file inclusion vulnerability in include/phpxd/phpXD.php in guanxiCRM 0.9.1 and earlier allows remote attackers to execute arbitrary PHP cod… Patch early 7.5 high 6.3% 2006-09-19
CVE-2006-4912 EXP PHP remote file inclusion vulnerability in PHP DocWriter 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the script… Patch early 7.5 high 6.3% 2006-09-21
← previous page 196 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt