peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,602 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

187,536 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-7070 EXP Argument injection vulnerability in the URI handler in KVIrc 3.4.2 Shiny allows remote attackers to execute arbitrary commands via a " (quote) followe… Patch early 9.3 high 5.1% 2009-08-25
CVE-2008-2922 EXP Stack-based buffer overflow in artegic Dana IRC client 1.3 and earlier allows remote attackers to cause a denial of service (application crash) or pos… Patch early 7.5 high 5% 2008-06-30
CVE-2008-2481 EXP PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, when register_globals is enabled,… Patch early 10.0 high 5% 2008-05-28
CVE-2012-1198 EXP base_ag_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allows remote attackers to execute arbitrary code by uploading contents of the fil… Patch early 7.5 high 5% 2012-02-18
CVE-2007-1391 EXP PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows remote attackers to execute arb… Patch early 10.0 high 5% 2007-03-10
CVE-2002-2300 EXP Buffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial of service (crash) via a long… Patch early 7.5 high 5% 2002-12-31
CVE-2007-1416 EXP PHP remote file inclusion vulnerability in createurl.php in JCcorp (aka James Coyle) URLshrink allows remote attackers to execute arbitrary PHP code v… Patch early 10.0 high 5% 2007-03-12
CVE-2017-13847 EXP An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The issue involves the "IOKit" compo… Patch early 7.8 high 5% 2017-12-25
CVE-2014-9173 EXP SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute arbitrary SQL… Patch early 7.5 high 5% 2014-12-02
CVE-2011-1047 EXP Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress allow remote attackers to execut… Patch early 7.5 high 5% 2011-02-21
CVE-2007-1195 EXP Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unspecified vectors. NOTE: this is… Patch early 7.5 high 5% 2007-03-02
CVE-2017-7402 EXP Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager… Patch early 9.8 critical 5% 2017-04-03
CVE-2014-9097 EXP Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly as distributed before 2014-07… Patch early 7.5 high 5% 2014-11-26
CVE-2014-8358 EXP Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before V200R003B015D02SP0… Patch early 7.8 high 5% 2017-12-11
CVE-2007-0368 EXP Stack-based buffer overflow in mbse-bbs 0.70 and earlier allows local users to execute arbitrary code via a long string in the MBSE_ROOT environment v… Patch early 10.0 high 5% 2007-01-19
CVE-2007-1628 EXP Multiple PHP remote file inclusion vulnerabilities in Study planner (Studiewijzer) 0.15 and earlier, when register_globals is enabled, allow remote at… Patch early 9.3 high 5% 2007-03-23
CVE-2005-1873 EXP Multiple buffer overflows in Crob FTP 3.6.1, and possibly earlier versions, allow remote attackers to execute arbitrary code via (1) an FTP command wi… Patch early 7.5 high 5% 2005-06-09
CVE-2002-1891 EXP Buffer overflow in IRCIT 0.3.1 IRC client allows remote attackers to execute arbitrary code via a long invite request. Patch early 7.5 high 5% 2002-12-31
CVE-2000-0523 EXP Buffer overflow in the logging feature of EServ 2.9.2 and earlier allows an attacker to execute arbitrary commands via a long MKD command. Patch early 10.0 high 5% 2000-06-06
CVE-2016-1767 EXP QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafte… Patch early 7.8 high 5% 2016-03-24
CVE-2016-1769 EXP QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafte… Patch early 7.8 high 5% 2016-03-24
CVE-2009-3421 EXP login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrativ… Patch early 9.8 critical 5% 2009-09-25
CVE-2012-3808 EXP Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification. Patch early 7.5 high 5% 2020-01-09
CVE-2012-3809 EXP Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification. Patch early 7.5 high 5% 2020-01-09
CVE-2012-3810 EXP Samsung Kies before 2.5.0.12094_27_11 has registry modification. Patch early 7.5 high 5% 2020-01-09
CVE-2026-29053 EXP Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the se… Patch early 7.6 high 5% 2026-03-05
CVE-2022-37255 EXP TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL075526460603. Patch early 7.5 high 5% 2023-04-16
CVE-2019-15742 EXP A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application. A local attacker can exploit… Patch early 7.8 high 5% 2020-01-17
CVE-2007-0172 EXP Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 5% 2007-01-11
CVE-2022-42953 EXP Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?s… Patch early 7.5 high 5% 2022-12-25
← previous page 268 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt