peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,173 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

150,443 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-11526 EXP The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection. Patch early 7.8 high 5.1% 2018-06-19
CVE-2016-1803 EXP CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in… Patch early 7.8 high 5.1% 2016-05-20
CVE-2019-15092 EXP The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, f… Patch early 7.3 high 5.1% 2019-08-23
CVE-2009-0610 EXP Multiple static code injection vulnerabilities in post.php in Simple PHP News 1.0 final allow remote attackers to inject arbitrary PHP code into news.… Patch early 7.5 high 5.1% 2009-02-17
CVE-2017-2447 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… Patch early 8.1 high 5.1% 2017-04-02
CVE-2009-1087 EXP Multiple argument injection vulnerabilities in PPLive.exe in PPLive 1.9.21 and earlier allow remote attackers to execute arbitrary code via a UNC shar… Patch early 9.3 high 5.1% 2009-03-25
CVE-2016-1755 EXP The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privi… Patch early 7.8 high 5.1% 2016-03-24
CVE-2002-0336 EXP Buffer overflow in Galacticomm Worldgroup FTP server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbit… Patch early 7.5 high 5.1% 2002-06-25
CVE-2009-0734 EXP Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code via a long… Patch early 9.3 high 5.1% 2009-02-25
CVE-2009-2375 EXP Stack-based buffer overflow in Photo DVD Maker 8.02, and possibly earlier versions, allows remote attackers to execute arbitrary code via a long File_… Patch early 9.3 high 5.1% 2009-07-08
CVE-2015-5889 EXP rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving environment variables. Patch early 7.2 high 5.1% 2015-10-09
CVE-2007-0888 EXP Directory traversal vulnerability in the TFTP server in Kiwi CatTools before 3.2.0 beta allows remote attackers to read arbitrary files, and upload fi… Patch early 10.0 high 5.1% 2007-02-12
CVE-2009-2766 EXP httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remot… Patch early 7.5 high 5.1% 2009-08-14
CVE-2006-4852 EXP SQL injection vulnerability in browse.asp in QuadComm Q-Shop 3.5 allows remote attackers to execute arbitrary SQL commands via the OrderBy parameter. Patch early 7.5 high 5.1% 2006-09-19
CVE-2009-4453 EXP Insecure method vulnerability in SoftCab Sound Converter ActiveX control (sndConverter.ocx) 1.2 allows remote attackers to create or overwrite arbitra… Patch early 8.8 high 5.1% 2009-12-29
CVE-2009-2386 EXP Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to fo… Patch early 9.3 high 5.1% 2009-07-10
CVE-2008-6920 EXP Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary code by uploading a file with an… Patch early 7.5 high 5.1% 2009-08-10
CVE-2008-6921 EXP Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code by uploading a file with an ex… Patch early 7.5 high 5.1% 2009-08-10
CVE-2008-3178 EXP Unrestricted file upload vulnerability in upload_pictures.php in WebXell Editor 0.1.3 allows remote attackers to execute arbitrary code by uploading a… Patch early 7.5 high 5.1% 2008-07-15
CVE-2007-1766 EXP PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and earlier allows remote attackers to execute arbitr… Patch early 10.0 high 5.1% 2007-03-30
CVE-2017-13867 EXP An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchO… Patch early 7.8 high 5.1% 2017-12-25
CVE-2017-13876 EXP An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchO… Patch early 7.8 high 5.1% 2017-12-25
CVE-2017-2482 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchO… Patch early 7.8 high 5.1% 2017-04-02
CVE-2006-6864 EXP PHP remote file inclusion vulnerability in E2_header.inc.php in Enigma2 Coppermine Bridge 1.0 allows remote attackers to execute arbitrary PHP code vi… Patch early 10.0 high 5.1% 2006-12-31
CVE-2006-4024 EXP The FESTAHES_Load function in pce/hes.c in Festalon 0.5.0 through 0.5.5 allows user-assisted attackers to cause a denial of service (crash) and possib… Patch early 7.5 high 5.1% 2006-08-09
CVE-2005-1604 EXP PHP Advanced Transfer Manager (phpATM) 1.21 allows remote attackers to upload arbitrary files via filenames containing multiple file extensions, as de… Patch early 7.5 high 5.1% 2005-05-16
CVE-2016-7617 EXP An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth" component. It allows attackers… Patch early 7.8 high 5.1% 2017-02-20
CVE-2019-1476 EXP An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of… Patch early 7.8 high 5.1% 2019-12-10
CVE-2019-12788 EXP An issue was discovered in Photodex ProShow Producer v9.0.3797 (an application that runs with Administrator privileges). It is possible to perform a b… Patch early 7.8 high 5.1% 2019-06-10
CVE-2005-2564 EXP Direct static code injection vulnerability in editcss.php in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary PHP code, HTML, an… Patch early 7.5 high 5.1% 2005-08-16
← previous page 214 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt