peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,729 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

187,611 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-10504 EXP The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection. Patch early 7.8 high 4.4% 2018-04-27
CVE-2007-1394 EXP Direct static code injection vulnerability in startsession.php in Flat Chat 2.0 allows remote attackers to execute arbitrary PHP code via the Chat Nam… Patch early 10.0 high 4.4% 2007-03-10
CVE-2023-33243 EXP RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the password i… Patch early 8.1 high 4.4% 2023-06-15
CVE-2006-4428 EXP PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to execute arbitrary PHP code via a URL in the templ… Patch early 9.8 critical 4.4% 2006-08-29
CVE-2012-2986 EXP lhn/public/network/ping in HP SAN/iQ 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell met… Patch early 7.7 high 4.4% 2012-08-20
CVE-2007-2822 EXP TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the (1) loggedIn and (2) activate… Patch early 9.3 high 4.4% 2007-05-22
CVE-2008-1230 EXP Unrestricted file upload vulnerability in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to upload and execute arbitrary .jsp files via an unspec… Patch early 9.3 high 4.4% 2008-03-10
CVE-2006-0099 EXP PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/templates/categories/ PHP scripts… Patch early 7.5 high 4.4% 2006-01-06
CVE-2007-6036 EXP The parseRTSPRequestString function in LIVE555 Media Server 2007.11.01 and earlier allows remote attackers to cause a denial of service (daemon crash)… Patch early 7.1 high 4.4% 2007-11-20
CVE-2014-2084 EXP Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly restrict access to the Admin int… Patch early 8.5 high 4.4% 2014-05-17
CVE-2006-2908 EXP The domecode function in inc/functions_post.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows remote attackers to execute arbit… Patch early 7.5 high 4.4% 2006-06-13
CVE-2024-48841 EXP Network access can be used to execute arbitrary code with elevated privileges. This issue affects FLXEON 9.3.4 and older. Patch early 10.0 critical 4.4% 2025-01-27
CVE-2006-3966 EXP PHP remote file inclusion vulnerability in /lib/tree/layersmenu.inc.php in the PHP Layers Menu 2.3.5 package for MyNewsGroups :) 0.6b and earlier allo… Patch early 7.5 high 4.4% 2006-08-01
CVE-2007-0641 EXP Buffer overflow in the EnumPrintersA function in dapcnfsd.dll 0.6.4.0 in Shaffer Solutions (SSC) DiskAccess NFS Client allows remote attackers to exec… Patch early 7.5 high 4.4% 2007-01-31
CVE-2018-4139 EXP An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools" component. It allows attacker… Patch early 7.8 high 4.4% 2018-04-03
CVE-2007-3984 EXP Buffer overflow in a certain ActiveX control in the NixonMyPrograms class in sasatl.dll 1.5.0.531 in Zenturi ProgramChecker allows remote attackers to… Patch early 7.5 high 4.4% 2007-07-25
CVE-2016-1861 EXP The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denia… Patch early 7.8 high 4.4% 2016-06-19
CVE-2006-1778 EXP Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (… Patch early 7.5 high 4.4% 2006-04-13
CVE-2001-0669 EXP Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Mo… Patch early 7.5 high 4.4% 2001-10-30
CVE-2017-2533 EXP An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "DiskArbitration" component. A race condit… Patch early 7.0 high 4.4% 2017-05-22
CVE-2018-14327 EXP The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before EE40_00_02.00_45 sets weak per… Patch early 7.8 high 4.4% 2018-09-26
CVE-2013-1612 EXP Buffer overflow in secars.dll in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1.x before 12.1.3, and Symantec Endpoint Pro… Patch early 7.9 high 4.4% 2013-06-20
CVE-2023-23162 EXP Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php. Patch early 9.8 critical 4.4% 2023-02-10
CVE-2023-23163 EXP Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter. Patch early 9.8 critical 4.4% 2023-02-10
CVE-2006-1353 EXP Multiple SQL injection vulnerabilities in ASPPortal 3.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the downloadid… Patch early 7.5 high 4.4% 2006-03-22
CVE-2002-1058 EXP Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin… Patch early 10.0 high 4.4% 2002-10-04
CVE-2017-17591 EXP Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter. Patch early 9.8 critical 4.4% 2017-12-13
CVE-2007-2755 EXP The PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll, when Internet Explorer 6 is used, allows remote attackers to overwrite arbitra… Patch early 10.0 high 4.4% 2007-05-17
CVE-2025-44177 EXP A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ endpoint. An u… Patch early 8.2 high 4.4% 2025-07-09
CVE-2009-4549 EXP Stack-based buffer overflow in A2 Media Player Pro 2.51 allows remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .m3l… Patch early 9.3 high 4.4% 2010-01-04
← previous page 278 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt