peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,707 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

187,600 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-4470 EXP Stack-based buffer overflow in Numark CUE 5.0 rev2 allows user-assisted attackers to cause a denial of service (application crash) or execute arbitrar… Patch early 9.3 high 4.6% 2008-10-07
CVE-2019-5796 EXP Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a craft… Patch early 7.5 high 4.6% 2019-05-23
CVE-2006-0797 EXP Nokia N70 cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed… Patch early 7.8 high 4.6% 2006-02-19
CVE-2002-2232 EXP Buffer overflow in Enceladus Server Suite 3.9 allows remote attackers to execute arbitrary code via a long CD (CWD) command. Patch early 8.5 high 4.6% 2002-12-31
CVE-2008-6826 EXP dhtml.pl in MHF Media Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter, as demonstrated using… Patch early 10.0 high 4.6% 2009-06-08
CVE-2008-5090 EXP Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email… Patch early 10.0 high 4.6% 2008-11-14
CVE-2007-6089 EXP PHP remote file inclusion vulnerability in index.php in meBiblio 0.4.5 allows remote attackers to execute arbitrary PHP code via a URL in the action p… Patch early 9.3 high 4.6% 2007-11-22
CVE-2017-6552 EXP Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing table size: it can be filled w… Patch early 7.5 high 4.6% 2017-03-09
CVE-2014-10013 EXP SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 4.6% 2015-01-13
CVE-2014-5189 EXP SQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin for WordPress allows remote attackers to execute arbitrary SQL comm… Patch early 7.5 high 4.6% 2014-08-07
CVE-2014-5201 EXP SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the viewid p… Patch early 7.5 high 4.6% 2014-08-12
CVE-2014-9175 EXP SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote attackers to execute arbitrar… Patch early 7.5 high 4.6% 2014-12-02
CVE-2015-2090 EXP SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for Wordpress allows remote atta… Patch early 7.5 high 4.6% 2015-02-26
CVE-2020-15238 EXP Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-mechanism is prone to an argumen… Patch early 7.1 high 4.6% 2020-10-27
CVE-2000-0026 EXP Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password authorization string. Patch early 10.0 high 4.6% 1999-12-21
CVE-2016-6754 EXP A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote at… Patch early 8.8 high 4.6% 2016-11-25
CVE-2007-6176 EXP kb_whois.cgi in K+B-Bestellsystem (aka KB-Bestellsystem) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) dom… Patch early 10.0 high 4.6% 2007-11-30
CVE-2017-2472 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchO… Patch early 7.8 high 4.6% 2017-04-02
CVE-2004-2715 EXP edituser.php3 in PHPMyChat 0.14.5 allow remote attackers to bypass authentication and gain administrative privileges by setting the do_not_login param… Patch early 7.5 high 4.6% 2004-12-31
CVE-2021-26830 EXP SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the… Patch early 9.1 critical 4.6% 2021-04-16
CVE-2010-0619 EXP Stack-based buffer overflow in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE components on certain Lexmark laser pr… Patch early 7.3 high 4.6% 2010-03-24
CVE-2006-6865 EXP Directory traversal vulnerability in SAFileUpSamples/util/viewsrc.asp in SoftArtisans FileUp (SAFileUp) 5.0.14 allows remote attackers to read arbitra… Patch early 7.8 high 4.6% 2006-12-31
CVE-2016-1337 EXP Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requests during the early part of… Patch early 8.1 high 4.6% 2016-07-03
CVE-2003-0496 EXP Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored… Patch early 7.2 high 4.6% 2003-08-18
CVE-2018-5752 EXP The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev2… Patch early 8.8 high 4.6% 2018-06-16
CVE-2021-31950 EXP Microsoft SharePoint Server Spoofing Vulnerability Patch early 7.6 high 4.6% 2021-06-08
CVE-2004-1875 EXP Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) emai… Patch early 9.3 high 4.6% 2004-03-30
CVE-2002-1798 EXP MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access… Patch early 9.1 critical 4.6% 2002-12-31
CVE-2006-5911 EXP Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 4.6% 2006-11-15
CVE-2018-17980 EXP NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file located in the same directory as… Patch early 7.8 high 4.6% 2018-10-15
← previous page 275 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt