peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,534 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

187,512 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-7626 EXP An issue was discovered in certain Apple products. iOS before 10.2 is affected. tvOS before 10.1 is affected. watchOS before 3.1.1 is affected. The is… Patch early 8.8 high 5.4% 2017-02-20
CVE-2008-5705 EXP The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier, when user triggers are enab… Patch early 9.3 high 5.4% 2008-12-22
CVE-2023-31068 EXP An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMF… Patch early 9.8 critical 5.4% 2023-09-11
CVE-2000-0985 EXP Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO" command. Patch early 10.0 high 5.4% 2000-12-19
CVE-2013-1852 EXP SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote attackers to execute arbitrary S… Patch early 7.5 high 5.4% 2014-02-05
CVE-2017-4915 EXP VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of… Patch early 7.8 high 5.4% 2017-05-22
CVE-2017-17970 EXP Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to login.php… Patch early 9.8 critical 5.4% 2018-01-12
CVE-2007-2895 EXP Buffer overflow in a certain ActiveX control in LTRDF14e.DLL 14.5.0.44 in LeadTools Raster Dialog File Object allows remote attackers to execute arbit… Patch early 7.5 high 5.4% 2007-05-30
CVE-2008-4452 EXP Buffer overflow in Cambridge Computer Corporation vxFtpSrv 2.0.3 allows remote attackers to cause a denial of service (crash and hang) and possibly ex… Patch early 9.0 high 5.4% 2008-10-06
CVE-2001-0288 EXP Cisco switches and routers running IOS 12.1 and earlier produce predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoo… Patch early 7.5 high 5.4% 2001-05-03
CVE-2002-0328 EXP Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonboard users and steal cookies v… Patch early 7.5 high 5.4% 2002-06-25
CVE-2005-3315 EXP Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers to execute arbitrary SQL comman… Patch early 7.5 high 5.4% 2005-10-30
CVE-2007-1260 EXP Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execute arbitrary code via a long st… Patch early 7.5 high 5.4% 2007-03-03
CVE-2013-3532 EXP SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrar… Patch early 7.5 high 5.4% 2013-05-10
CVE-2008-2111 EXP The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in t… Patch early 9.3 high 5.4% 2008-05-07
CVE-2007-2487 EXP Stack-based buffer overflow in AtomixMP3 allows remote attackers to execute arbitrary code via a long filename in an MP3 file, a different vector than… Patch early 7.5 high 5.4% 2007-05-03
CVE-2007-4060 EXP Multiple buffer overflows in the HttpSprockMake function in http.c in Frank Yaul corehttp 0.5.3alpha allow remote attackers to execute arbitrary code… Patch early 9.0 high 5.4% 2007-07-30
CVE-2017-3622 EXP Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (CDE)). The supported version th… Patch early 7.8 high 5.4% 2017-04-24
CVE-2008-6935 EXP Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cau… Patch early 10.0 high 5.4% 2009-08-11
CVE-2004-1717 EXP Multiple buffer overflows in the psscan function in ps.c for gv (ghostview) allow remote attackers to execute arbitrary code via a Postscript file wit… Patch early 7.5 high 5.4% 2004-08-16
CVE-2020-18662 EXP SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php. Patch early 9.8 critical 5.4% 2021-06-24
CVE-2023-34723 EXP An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information via /config/system.conf. Patch early 7.5 high 5.4% 2023-08-25
CVE-2003-1210 EXP Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands v… Patch early 7.5 high 5.4% 2003-12-31
CVE-2008-0337 EXP Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to execute arbitrary c… Patch early 7.5 high 5.4% 2008-01-17
CVE-2024-30896 EXP InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access… Patch early 9.1 critical 5.4% 2024-11-21
CVE-2003-1160 EXP FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.h… Patch early 10.0 high 5.4% 2003-10-30
CVE-2022-40347 EXP SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allow… Patch early 9.8 critical 5.3% 2023-02-17
CVE-2005-0633 EXP Buffer overflow in Trillian 3.0 and Pro 3.0 allows remote attackers to execute arbitrary code via a crafted PNG image file. Patch early 7.5 high 5.3% 2005-03-02
CVE-2015-6970 EXP The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML… Patch early 9.8 critical 5.3% 2020-02-18
CVE-2009-0241 EXP Stack-based buffer overflow in the process_path function in gmetad/server.c in Ganglia 3.1.1 allows remote attackers to cause a denial of service (cra… Patch early 7.5 high 5.3% 2009-01-21
← previous page 263 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt