peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,461 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

150,530 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-4220 EXP Directory traversal vulnerability in Motorola Timbuktu Pro before 8.6.5 for Windows allows remote attackers to create or delete arbitrary files via a… Patch early 7.8 high 4% 2007-08-29
CVE-2009-3753 EXP Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension… Patch early 7.5 high 4% 2009-10-22
CVE-2016-1744 EXP The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or… Patch early 7.8 high 4% 2016-03-24
CVE-2006-4060 EXP PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 4% 2006-08-10
CVE-2007-2495 EXP Multiple stack-based buffer overflows in the ExcelOCX ActiveX control in ExcelViewer.ocx 3.1.0.6 allow remote attackers to cause a denial of service (… Patch early 7.5 high 4% 2007-05-04
CVE-2006-5895 EXP PHP remote file inclusion vulnerability in core/core.php in EncapsCMS 0.3.6 allows remote attackers to execute arbitrary PHP code via a URL in the roo… Patch early 7.5 high 4% 2006-11-14
CVE-2007-1590 EXP The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device cra… Patch early 7.8 high 4% 2007-03-21
CVE-2017-15957 EXP my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file. Patch early 8.8 high 3.9% 2017-10-29
CVE-2008-2686 EXP webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overwriting a PHP file in webinc/bx… Patch early 7.5 high 3.9% 2008-06-13
CVE-2008-2092 EXP Linksys SPA-2102 Phone Adapter 3.3.6 allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE: the… Patch early 7.8 high 3.9% 2008-05-06
CVE-2000-0155 EXP Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when… Patch early 7.2 high 3.9% 2000-02-18
CVE-2014-9605 EXP WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a syste… Patch early 9.4 high 3.9% 2015-09-04
CVE-2006-7048 EXP Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarol… Patch early 7.5 high 3.9% 2007-02-24
CVE-2006-3930 EXP PHP remote file inclusion vulnerability in admin.a6mambohelpdesk.php in a6mambohelpdesk Mambo Component 18RC1 and earlier allows remote attackers to e… Patch early 7.5 high 3.9% 2006-07-31
CVE-2010-3888 EXP Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild… Patch early 7.2 high 3.9% 2010-10-08
CVE-2006-3884 EXP Multiple SQL injection vulnerabilities in links.php in Gonafish LinksCaffe 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) of… Patch early 7.5 high 3.9% 2006-07-27
CVE-2018-10900 EXP Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be… Patch early 7.8 high 3.9% 2018-07-26
CVE-2005-3019 EXP Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request paramete… Patch early 7.5 high 3.9% 2005-09-21
CVE-2000-0624 EXP Buffer overflow in Winamp 2.64 and earlier allows remote attackers to execute arbitrary commands via a long #EXTINF: extension in the M3U playlist. Patch early 7.5 high 3.9% 2000-07-20
CVE-2005-0419 EXP Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as demonstrate… Patch early 7.5 high 3.9% 2005-04-27
CVE-2005-2694 EXP Buffer overflow in WinAce 2.6.0.5, and possibly earlier versions, allows remote attackers to execute arbitrary code via a temporary (.tmp) file that c… Patch early 7.5 high 3.9% 2005-08-26
CVE-2007-5802 EXP Directory traversal vulnerability in index.php in Firewolf Technologies Synergiser 1.2 RC1 and earlier allows remote attackers to include and execute… Patch early 7.5 high 3.9% 2007-11-03
CVE-2006-7183 EXP PHP remote file inclusion vulnerability in styles.php in Exhibit Engine (EE) 1.22 and earlier allows remote attackers to execute arbitrary PHP code vi… Patch early 10.0 high 3.9% 2007-03-30
CVE-2006-4055 EXP Multiple PHP remote file inclusion vulnerabilities in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allow remote attackers to execu… Patch early 7.5 high 3.9% 2006-08-10
CVE-2006-4605 EXP PHP remote file inclusion vulnerability in index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to execute arbitrary PHP code via the… Patch early 7.5 high 3.9% 2006-09-07
CVE-2017-6989 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. Th… Patch early 7.8 high 3.9% 2017-05-22
CVE-2025-49741 EXP No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. Patch early 7.4 high 3.9% 2025-07-01
CVE-2006-2668 EXP Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 2.05 allow remote attackers to execute arbitrary PHP code via a URL in the lang param… Patch early 7.5 high 3.9% 2006-05-30
CVE-2007-5453 EXP Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing PHP sequen… Patch early 8.5 high 3.9% 2007-10-14
CVE-2009-1361 EXP dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter. NOTE: the prov… Patch early 10.0 high 3.9% 2009-04-22
← previous page 233 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt