peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,415 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

150,518 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-1029 EXP Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir… Patch early 7.5 high 4.3% 2005-04-06
CVE-2017-2490 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchO… Patch early 7.8 high 4.3% 2017-04-02
CVE-2007-6544 EXP Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter to (1) br… Patch early 7.5 high 4.3% 2007-12-28
CVE-2021-46416 EXP Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie h… Patch early 8.1 high 4.3% 2022-04-07
CVE-2017-8222 EXP Wireless IP Camera (P2P) WIFICAM devices have an "Apple Production IOS Push Services" private RSA key and certificate stored in /system/www/pem/ck.pem… Patch early 7.5 high 4.3% 2017-04-25
CVE-1999-0493 EXP rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be use… Patch early 7.5 high 4.3% 1999-06-07
CVE-2008-0939 EXP Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arbi… Patch early 7.5 high 4.3% 2008-02-25
CVE-2002-0608 EXP Buffer overflow in Matu FTP client 1.74 allows remote FTP servers to execute arbitrary code via a long "220" banner. Patch early 7.5 high 4.3% 2002-06-18
CVE-2016-2539 EXP Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of… Patch early 8.8 high 4.3% 2017-02-07
CVE-2017-2353 EXP An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth" component. It allows attackers… Patch early 7.8 high 4.3% 2017-02-20
CVE-2006-4558 EXP DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploa… Patch early 7.5 high 4.3% 2006-09-06
CVE-2018-10257 EXP A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that w… Patch early 8.8 high 4.2% 2018-05-01
CVE-2012-2277 EXP The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial o… Patch early 7.8 high 4.2% 2012-05-14
CVE-2017-2456 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchO… Patch early 7.0 high 4.2% 2017-04-02
CVE-2004-0318 EXP Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSF_EAUTH_UID environment variable, if it exists, instead of the real UID of the user, which co… Patch early 10.0 high 4.2% 2004-11-23
CVE-2016-10010 EXP sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gai… Patch early 7.0 high 4.2% 2017-01-05
CVE-2012-5861 EXP These Sinapsi devices do not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not requir… Patch early 7.8 high 4.2% 2012-11-23
CVE-2007-0790 EXP Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner. Patch early 7.5 high 4.2% 2007-02-06
CVE-2014-100003 EXP SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for WordPress allows remote attackers… Patch early 7.5 high 4.2% 2015-01-13
CVE-2006-1668 EXP newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to… Patch early 9.0 high 4.2% 2006-04-07
CVE-2017-7221 EXP OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute ar… Patch early 8.8 high 4.2% 2017-04-25
CVE-2004-1421 EXP Multiple PHP remote file inclusion vulnerabilities (1) step_one.php, (2) step_one_tables.php, (3) step_two_tables.php in WHM AutoPilot 2.4.6.5 and ear… Patch early 7.5 high 4.2% 2004-12-31
CVE-2016-7612 EXP An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. Th… Patch early 7.8 high 4.2% 2017-02-20
CVE-2008-6669 EXP viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in the var_filename parameter in a… Patch early 7.5 high 4.2% 2009-04-08
CVE-2017-6995 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. Th… Patch early 7.8 high 4.2% 2017-05-22
CVE-2017-6996 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. Th… Patch early 7.8 high 4.2% 2017-05-22
CVE-2017-6998 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. Th… Patch early 7.8 high 4.2% 2017-05-22
CVE-2007-6414 EXP admin/administrator.php in Adult Script 1.6 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to bypass… Patch early 7.5 high 4.2% 2007-12-17
CVE-2017-6994 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. Th… Patch early 7.8 high 4.2% 2017-05-22
CVE-2008-7167 EXP Unrestricted file upload vulnerability in upload.php in Page Manager 2006-02-04 allows remote attackers to execute arbitrary code by uploading a file… Patch early 7.5 high 4.2% 2009-09-08
← previous page 227 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt