peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,602 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

187,536 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-4453 EXP Insecure method vulnerability in SoftCab Sound Converter ActiveX control (sndConverter.ocx) 1.2 allows remote attackers to create or overwrite arbitra… Patch early 8.8 high 5.1% 2009-12-29
CVE-2009-2386 EXP Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to fo… Patch early 9.3 high 5.1% 2009-07-10
CVE-2008-6920 EXP Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary code by uploading a file with an… Patch early 7.5 high 5.1% 2009-08-10
CVE-2008-6921 EXP Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code by uploading a file with an ex… Patch early 7.5 high 5.1% 2009-08-10
CVE-2008-3178 EXP Unrestricted file upload vulnerability in upload_pictures.php in WebXell Editor 0.1.3 allows remote attackers to execute arbitrary code by uploading a… Patch early 7.5 high 5.1% 2008-07-15
CVE-2007-1766 EXP PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and earlier allows remote attackers to execute arbitr… Patch early 10.0 high 5.1% 2007-03-30
CVE-2017-13867 EXP An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchO… Patch early 7.8 high 5.1% 2017-12-25
CVE-2017-13876 EXP An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchO… Patch early 7.8 high 5.1% 2017-12-25
CVE-2017-2482 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchO… Patch early 7.8 high 5.1% 2017-04-02
CVE-2006-6864 EXP PHP remote file inclusion vulnerability in E2_header.inc.php in Enigma2 Coppermine Bridge 1.0 allows remote attackers to execute arbitrary PHP code vi… Patch early 10.0 high 5.1% 2006-12-31
CVE-2006-4024 EXP The FESTAHES_Load function in pce/hes.c in Festalon 0.5.0 through 0.5.5 allows user-assisted attackers to cause a denial of service (crash) and possib… Patch early 7.5 high 5.1% 2006-08-09
CVE-2005-1604 EXP PHP Advanced Transfer Manager (phpATM) 1.21 allows remote attackers to upload arbitrary files via filenames containing multiple file extensions, as de… Patch early 7.5 high 5.1% 2005-05-16
CVE-2016-7617 EXP An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth" component. It allows attackers… Patch early 7.8 high 5.1% 2017-02-20
CVE-2019-1476 EXP An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of… Patch early 7.8 high 5.1% 2019-12-10
CVE-2019-12788 EXP An issue was discovered in Photodex ProShow Producer v9.0.3797 (an application that runs with Administrator privileges). It is possible to perform a b… Patch early 7.8 high 5.1% 2019-06-10
CVE-2005-2564 EXP Direct static code injection vulnerability in editcss.php in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary PHP code, HTML, an… Patch early 7.5 high 5.1% 2005-08-16
CVE-2022-39285 EXP ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a cross site scripting vulnerabil… Patch early 7.6 high 5.1% 2022-10-07
CVE-2009-3577 EXP Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript s… Patch early 9.3 high 5.1% 2009-11-24
CVE-2016-3989 EXP The NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M3… Patch early 8.1 high 5.1% 2016-07-03
CVE-2017-3629 EXP Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11… Patch early 7.8 high 5.1% 2017-06-22
CVE-2009-1422 EXP Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to gain privi… Patch early 10.0 high 5.1% 2009-07-14
CVE-2017-11322 EXP The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileges via a dollar sign ($) metac… Patch early 8.2 high 5.1% 2017-10-03
CVE-2005-2651 EXP gorum/prod.php in Zorum 3.5 allows remote attackers to execute arbitrary code via shell metacharacters in the argv parameter. Patch early 7.5 high 5.1% 2005-08-23
CVE-2004-0733 EXP Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via forma… Patch early 7.5 high 5.1% 2004-07-27
CVE-2002-1452 EXP Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a long searchTarget parameter. Patch early 7.5 high 5.1% 2002-08-14
CVE-2014-7178 EXP Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP… Patch early 9.3 high 5.1% 2014-11-28
CVE-2019-7652 EXP TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the vulnerability, an attacker mus… Patch early 7.7 high 5.1% 2019-05-09
CVE-2010-2701 EXP Multiple buffer overflows in the FathFTP ActiveX control 1.7 allow remote attackers to execute arbitrary code via (1) the GetFromURL member or (2) a l… Patch early 9.3 high 5.1% 2010-07-12
CVE-2009-1646 EXP Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long rtsp URL in a .ram file. Patch early 9.3 high 5.1% 2009-05-15
CVE-2003-0705 EXP Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code. Patch early 7.5 high 5.1% 2003-09-17
← previous page 267 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt