peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,415 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

150,518 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-5380 EXP Grand MA 300 allows retrieval of the access PIN from sniffed data. Patch early 7.5 high 4.3% 2020-01-13
CVE-2006-6567 EXP PHP remote file inclusion vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to ex… Patch early 10.0 high 4.3% 2006-12-15
CVE-2020-5726 EXP The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker c… Patch early 7.5 high 4.3% 2020-03-30
CVE-2006-5206 EXP SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.p… Patch early 7.5 high 4.3% 2006-10-10
CVE-2006-4531 EXP PHP remote file inclusion vulnerability in lib/config.php in Pheap CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 4.3% 2006-09-01
CVE-2017-14680 EXP ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document. Patch early 7.5 high 4.3% 2017-09-21
CVE-2018-16302 EXP MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file. Patch early 7.8 high 4.3% 2018-09-01
CVE-2014-1214 EXP views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attackers to upload and execute arb… Patch early 8.8 high 4.3% 2019-11-13
CVE-2007-4009 EXP PHP remote file inclusion vulnerability in admin/business_inc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1 allows remote attackers to exe… Patch early 9.3 high 4.3% 2007-07-26
CVE-2008-0141 EXP actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to o… Patch early 7.5 high 4.3% 2008-01-08
CVE-2016-6663 EXP Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x before 10.… Patch early 7.0 high 4.3% 2016-12-13
CVE-2023-31702 EXP SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to dump entire database and gain w… Patch early 7.2 high 4.3% 2023-05-17
CVE-2007-4634 EXP Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 bef… Patch early 9.3 high 4.3% 2007-08-31
CVE-2017-6978 EXP An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Accessibility Framework" component. It al… Patch early 7.8 high 4.3% 2017-05-22
CVE-2019-0836 EXP An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privil… Patch early 7.8 high 4.3% 2019-04-09
CVE-2008-3361 EXP Stack-based buffer overflow in IntelliTamper 2.07 allows remote web sites to execute arbitrary code via a long HTTP Server header. Patch early 7.5 high 4.3% 2008-07-29
CVE-2006-3727 EXP Multiple SQL injection vulnerabilities in Eskolar CMS 0.9.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) gr_1_id, (2) gr_2_i… Patch early 7.5 high 4.3% 2006-07-21
CVE-2006-5928 EXP Multiple PHP remote file inclusion vulnerabilities in Phpjobscheduler 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the instal… Patch early 7.5 high 4.3% 2006-11-16
CVE-2017-7852 EXP D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's se… Patch early 8.8 high 4.3% 2017-04-24
CVE-2006-4081 EXP preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute commands via shell metacharacters… Patch early 7.5 high 4.3% 2006-08-11
CVE-2006-3683 EXP PHP remote file inclusion vulnerability in poll.php in Flipper Poll 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 4.3% 2006-07-21
CVE-2006-0502 EXP PHP remote file inclusion vulnerability in loginout.php in FarsiNews 2.1 Beta 2 and earlier, with register_globals enabled, allows remote attackers to… Patch early 7.5 high 4.3% 2006-02-01
CVE-2004-0676 EXP Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary file… Patch early 10.0 high 4.3% 2004-08-06
CVE-2006-0206 EXP Eval injection vulnerability in Light Weight Calendar (LWC) 1.0 (20040909) and earlier allows remote attackers to execute arbitrary PHP code via the d… Patch early 7.5 high 4.3% 2006-01-13
CVE-2002-2385 EXP Buffer overflow in hotfoon4.exe in Hotfoon 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a… Patch early 7.5 high 4.3% 2002-12-31
CVE-2002-0676 EXP SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrar… Patch early 7.5 high 4.3% 2002-07-11
CVE-2011-4558 EXP Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters. Patch early 7.2 high 4.3% 2020-01-27
CVE-2007-6234 EXP index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a loggedin parameter with a value o… Patch early 10.0 high 4.3% 2007-12-04
CVE-2015-9222 EXP In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400,… Patch early 7.5 high 4.3% 2018-04-18
CVE-2010-2860 EXP The EMC Celerra Network Attached Storage (NAS) appliance accepts external network traffic to IP addresses intended for an intranet network within the… Patch early 9.3 high 4.3% 2010-08-05
← previous page 226 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt