peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,707 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

187,600 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-3292 EXP SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL commands via queries with the "LIKE" k… Patch early 7.5 high 4.7% 2006-06-28
CVE-2012-1239 EXP The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x throug… Patch early 10.0 high 4.7% 2012-04-06
CVE-2023-0963 EXP A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. This issue affects some unknown processing of the f… Patch early 7.3 high 4.7% 2023-02-22
CVE-2026-80428 EXP ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to ex… Patch early 9.8 critical 4.7% 2026-08-26
CVE-2017-6997 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. Th… Patch early 7.8 high 4.7% 2017-05-22
CVE-2017-6999 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. Th… Patch early 7.8 high 4.7% 2017-05-22
CVE-2005-1110 EXP Stack-based buffer overflow in the RespondeHTTPPendiente function in the HTTP server for SUMUS 0.2.2 allows remote attackers to execute arbitrary code… Patch early 7.5 high 4.7% 2005-05-02
CVE-2000-0128 EXP The Finger Server 0.82 allows remote attackers to execute commands via shell metacharacters. Patch early 10.0 high 4.7% 2000-02-04
CVE-2020-13259 EXP A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to… Patch early 8.8 high 4.7% 2020-09-16
CVE-2007-5230 EXP admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform administra… Patch early 7.5 high 4.7% 2007-10-05
CVE-2007-0309 EXP SQL injection vulnerability in blocks/block-Old_Articles.php in Francisco Burzi PHP-Nuke 7.9 and earlier, when register_globals is enabled and magic_q… Patch early 7.5 high 4.7% 2007-01-18
CVE-2016-1793 EXP AppleGraphicsDeviceControlClient in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of… Patch early 7.8 high 4.7% 2016-05-20
CVE-2016-1794 EXP The AppleGraphicsControlClient::checkArguments method in AppleGraphicsControl in Apple OS X before 10.11.5 allows attackers to execute arbitrary code… Patch early 7.8 high 4.7% 2016-05-20
CVE-2017-15956 EXP ConverTo Video Downloader & Converter 1.4.1 allows Arbitrary File Download via the token parameter to download.php. Patch early 7.5 high 4.7% 2017-10-29
CVE-2022-45639 EXP OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter.… Patch early 7.8 high 4.7% 2023-01-24
CVE-2021-42136 EXP A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute J… Patch early 9.0 critical 4.7% 2022-04-13
CVE-2016-7400 EXP Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter… Patch early 9.8 critical 4.7% 2017-02-07
CVE-2012-5190 EXP Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability Patch early 9.8 critical 4.7% 2020-01-21
CVE-2005-4243 EXP Multiple SQL injection vulnerabilities in QuickPayPro 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) popupid parameter in po… Patch early 7.5 high 4.7% 2005-12-15
CVE-2007-2644 EXP A certain ActiveX control in Morovia Barcode ActiveX Professional 3.3.1304 allows remote attackers to overwrite arbitrary files by calling the Save me… Patch early 9.4 high 4.6% 2007-05-13
CVE-2008-0634 EXP Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote… Patch early 7.5 high 4.6% 2008-02-06
CVE-2008-3583 EXP Buffer overflow in the HTML parser in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a long URL in the SRC attribute of an I… Patch early 7.5 high 4.6% 2008-08-10
CVE-2013-3530 EXP SQL injection vulnerability in playlist.php in the Spiffy XSPF Player plugin 0.1 for WordPress allows remote attackers to execute arbitrary SQL comman… Patch early 7.5 high 4.6% 2013-05-10
CVE-2008-5305 EXP Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable. Patch early 10.0 high 4.6% 2008-12-10
CVE-2018-12052 EXP SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php. Patch early 9.8 critical 4.6% 2018-06-08
CVE-2001-0440 EXP Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary command… Patch early 7.5 high 4.6% 2001-07-02
CVE-2014-9178 EXP Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-document-manage… Patch early 7.5 high 4.6% 2014-12-02
CVE-2018-5725 EXP MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of the web server. Patch early 7.5 high 4.6% 2018-01-16
CVE-2008-5754 EXP Stack-based buffer overflow in BulletProof FTP Client allows user-assisted attackers to execute arbitrary code via a .bps file (aka Session-File) with… Patch early 9.3 high 4.6% 2008-12-30
CVE-2004-0524 EXP Buffer overflow in the chpasswd command in the Change_passwd plugin before 4.0, as used in SquirrelMail, allows local users to gain root privileges vi… Patch early 10.0 high 4.6% 2004-08-06
← previous page 274 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt