peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,413 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

150,518 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-9351 EXP An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error allows an attacker to upload a… Patch early 7.0 high 4.5% 2017-02-13
CVE-2004-1836 EXP SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the… Patch early 7.5 high 4.4% 2004-12-31
CVE-2005-0047 EXP Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to e… Patch early 7.2 high 4.4% 2005-05-02
CVE-2019-8591 EXP A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A… Patch early 7.1 high 4.4% 2019-12-18
CVE-2019-19363 EXP An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation.… Patch early 7.8 high 4.4% 2020-01-24
CVE-2004-1165 EXP Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP… Patch early 7.5 high 4.4% 2005-01-10
CVE-2014-8681 EXP SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.6.x before 0.5.6.1025 Beta a… Patch early 7.5 high 4.4% 2014-11-21
CVE-2008-5284 EXP The web server in IEA Software RadiusNT and RadiusX 5.1.38 and other versions before 5.1.44, Emerald 5.0.49 and other versions before 5.0.52, Air Mars… Patch early 10.0 high 4.4% 2008-11-29
CVE-2005-0958 EXP Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabled, allows remote attackers to… Patch early 7.5 high 4.4% 2005-05-02
CVE-2005-4622 EXP Directory traversal vulnerability in eFileGo 3.01 allows remote attackers to execute arbitrary code, read arbitrary files, and upload arbitrary files… Patch early 7.5 high 4.4% 2005-12-31
CVE-2006-2485 EXP PHP remote file inclusion vulnerability in includes/class_template.php in Quezza 1.0 and earlier, and possibly 1.1.0 allows remote attackers to execut… Patch early 7.5 high 4.4% 2006-05-19
CVE-2007-2656 EXP Stack-based buffer overflow in the Hewlett-Packard (HP) Magview ActiveX control in hpqvwocx.dll 1.0.0.309 allows remote attackers to cause a denial of… Patch early 7.8 high 4.4% 2007-05-14
CVE-2017-13875 EXP An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allo… Patch early 7.8 high 4.4% 2017-12-25
CVE-2007-0756 EXP Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large computer-name size value in a Serve… Patch early 7.8 high 4.4% 2007-02-06
CVE-2004-0246 EXP Multiple PHP remote file inclusion vulnerabilities in (1) fonctions.lib.php, (2) derniers_commentaires.php, and (3) admin.php in Les Commentaires 2.0… Patch early 10.0 high 4.4% 2004-11-23
CVE-2009-3578 EXP Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2… Patch early 9.3 high 4.4% 2009-11-24
CVE-2008-4135 EXP Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause a denial of service (device c… Patch early 7.8 high 4.4% 2008-09-19
CVE-2018-10504 EXP The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection. Patch early 7.8 high 4.4% 2018-04-27
CVE-2007-1394 EXP Direct static code injection vulnerability in startsession.php in Flat Chat 2.0 allows remote attackers to execute arbitrary PHP code via the Chat Nam… Patch early 10.0 high 4.4% 2007-03-10
CVE-2023-33243 EXP RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the password i… Patch early 8.1 high 4.4% 2023-06-15
CVE-2012-2986 EXP lhn/public/network/ping in HP SAN/iQ 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell met… Patch early 7.7 high 4.4% 2012-08-20
CVE-2007-2822 EXP TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the (1) loggedIn and (2) activate… Patch early 9.3 high 4.4% 2007-05-22
CVE-2008-1230 EXP Unrestricted file upload vulnerability in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to upload and execute arbitrary .jsp files via an unspec… Patch early 9.3 high 4.4% 2008-03-10
CVE-2006-0099 EXP PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/templates/categories/ PHP scripts… Patch early 7.5 high 4.4% 2006-01-06
CVE-2007-6036 EXP The parseRTSPRequestString function in LIVE555 Media Server 2007.11.01 and earlier allows remote attackers to cause a denial of service (daemon crash)… Patch early 7.1 high 4.4% 2007-11-20
CVE-2014-2084 EXP Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly restrict access to the Admin int… Patch early 8.5 high 4.4% 2014-05-17
CVE-2006-2908 EXP The domecode function in inc/functions_post.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows remote attackers to execute arbit… Patch early 7.5 high 4.4% 2006-06-13
CVE-2006-3966 EXP PHP remote file inclusion vulnerability in /lib/tree/layersmenu.inc.php in the PHP Layers Menu 2.3.5 package for MyNewsGroups :) 0.6b and earlier allo… Patch early 7.5 high 4.4% 2006-08-01
CVE-2007-0641 EXP Buffer overflow in the EnumPrintersA function in dapcnfsd.dll 0.6.4.0 in Shaffer Solutions (SSC) DiskAccess NFS Client allows remote attackers to exec… Patch early 7.5 high 4.4% 2007-01-31
CVE-2018-4139 EXP An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools" component. It allows attacker… Patch early 7.8 high 4.4% 2018-04-03
← previous page 224 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt