peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,908 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

320,993 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-1982 EXP The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmwar… Patch early 10.0 high 9.4% 2014-03-31
CVE-2012-2208 EXP Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a ..… Patch early 7.5 high 9.4% 2012-08-14
CVE-2010-2507 EXP Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read a… Patch early 6.8 medium 9.4% 2010-06-28
CVE-2007-1380 EXP The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-dependent attackers to obtain… Patch early 5.0 medium 9.4% 2007-03-10
CVE-2006-6352 EXP FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to cause a denial of service (infinite loop) via a crafted ACE file… Patch early 5.0 medium 9.4% 2006-12-07
CVE-2007-2070 EXP Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary… Patch early 7.5 high 9.4% 2007-04-18
CVE-2012-6050 EXP The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router versi… Patch early 6.4 medium 9.4% 2012-11-27
CVE-2010-4283 EXP PHP remote file inclusion vulnerability in extras/pandora_diag.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code v… Patch early 7.5 high 9.4% 2010-12-02
CVE-2007-1164 EXP Multiple PHP remote file inclusion vulnerabilities in DBImageGallery 1.2.2 allow remote attackers to execute arbitrary PHP code via a URL in the donsi… Patch early 7.5 high 9.4% 2007-03-02
CVE-2008-3681 EXP components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the… Patch early 7.5 high 9.4% 2008-08-14
CVE-2007-3294 EXP Multiple buffer overflows in libtidy, as used in the Tidy extension for PHP 5.2.3 and possibly other products, allow context-dependent attackers to ex… Patch early 7.5 high 9.4% 2007-06-20
CVE-2007-4903 EXP Multiple buffer overflows in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allow remote attackers to execute… Patch early 7.5 high 9.4% 2007-09-17
CVE-2018-4197 EXP A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… Patch early 8.8 high 9.4% 2019-04-03
CVE-2018-4315 EXP A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… Patch early 8.8 high 9.4% 2019-04-03
CVE-2010-3490 EXP Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlie… Patch early 6.5 medium 9.4% 2010-09-28
CVE-2007-1199 EXP Adobe Reader and Acrobat Trial allow remote attackers to read arbitrary files via a file:// URI in a PDF document, as demonstrated with <</URI(file://… Patch early 4.3 medium 9.4% 2007-03-02
CVE-2004-1095 EXP Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (… Patch early 10.0 high 9.4% 2005-01-10
CVE-2019-1978 EXP A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Fi… Patch early 5.8 medium 9.4% 2019-11-05
CVE-2012-0981 EXP Directory traversal vulnerability in phpShowtime 2.0 allows remote attackers to list arbitrary directories and image files via a .. (dot dot) in the r… Patch early 5.0 medium 9.4% 2012-02-02
CVE-2006-0565 EXP PHP remote file include vulnerability in inc/backend_settings.php in Loudblog 0.4 and earlier allows remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 9.4% 2006-02-06
CVE-2007-1943 EXP Integer overflow in ACDSee Photo Manager 9.0 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via l… Patch early 9.3 high 9.4% 2007-04-11
CVE-2010-2931 EXP Stack-based buffer overflow in SigPlus Pro 3.74 ActiveX control allows remote attackers to execute arbitrary code via a long eighth argument (HexStrin… Patch early 9.3 high 9.4% 2010-08-05
CVE-2010-1719 EXP Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attackers to read arbitrary files and… Patch early 6.8 medium 9.4% 2010-05-04
CVE-2004-2565 EXP Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, when the administrative IP… Patch early 5.0 medium 9.4% 2004-12-31
CVE-1999-0492 EXP The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses. Patch early 10.0 high 9.4% 1999-04-23
CVE-2006-2896 EXP profile.php in FunkBoard CF0.71 allows remote attackers to change arbitrary passwords via a modified uid hidden form field in an Edit Profile action. Patch early 5.0 medium 9.4% 2006-06-07
CVE-2006-3735 EXP Multiple PHP remote file inclusion vulnerabilities in Mail2Forum (module for phpBB) 1.2 and earlier allow remote attackers to execute arbitrary PHP co… Patch early 5.1 medium 9.4% 2006-07-21
CVE-2009-2535 EXP Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumpti… Patch early 5.0 medium 9.4% 2009-07-20
CVE-2019-14280 EXP In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so,… Patch early 5.3 medium 9.4% 2019-07-26
CVE-2007-2270 EXP The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) character in the From header, and… Patch early 7.8 high 9.4% 2007-04-25
← previous page 219 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt