peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,734 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

187,612 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-4767 EXP Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploading a file w… Patch early 9.0 high 4.2% 2008-10-28
CVE-2021-29995 EXP A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in u… Patch early 8.8 high 4.2% 2021-06-09
CVE-2007-1621 EXP PHP remote file inclusion vulnerability in templates/head.php in Active PHP Bookmark Notes (APB) 0.2.5 and earlier allows remote attackers to execute… Patch early 10.0 high 4.2% 2007-03-23
CVE-2007-1778 EXP PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remote attackers to execute arbitra… Patch early 10.0 high 4.2% 2007-03-30
CVE-2007-3980 EXP PHP remote file inclusion vulnerability in page.php in RCMS Pro RGameScript Pro allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 10.0 high 4.2% 2007-07-25
CVE-1999-0944 EXP IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections. Patch early 10.0 high 4.2% 1999-10-24
CVE-2021-27946 EXP SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3). Patch early 8.8 high 4.2% 2021-03-15
CVE-2006-4974 EXP Buffer overflow in Ipswitch WS_FTP Limited Edition (LE) 5.08 allows remote FTP servers to execute arbitrary code via a long response to a PASV command… Patch early 7.5 high 4.2% 2006-09-25
CVE-2010-2744 EXP The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2… Patch early 7.2 high 4.2% 2010-10-13
CVE-2006-2487 EXP Multiple PHP remote file inclusion vulnerabilities in ScozNews 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 4.2% 2006-05-19
CVE-2017-2360 EXP An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. wa… Patch early 7.8 high 4.2% 2017-02-20
CVE-2024-53584 EXP OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter. Patch early 9.8 critical 4.2% 2025-01-31
CVE-2007-5187 EXP SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remote attack… Patch early 7.5 high 4.2% 2007-10-03
CVE-2017-2501 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… Patch early 7.0 high 4.2% 2017-05-22
CVE-2006-2507 EXP Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing 0.2.0 through 0.7.0, as used with phpBB, allow remote attackers to execute arb… Patch early 7.5 high 4.2% 2006-05-22
CVE-2015-1318 EXP The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport fi… Patch early 7.2 high 4.2% 2015-04-17
CVE-2002-2417 EXP acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or mi… Patch early 10.0 high 4.2% 2002-12-31
CVE-2018-18619 EXP internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently… Patch early 9.8 critical 4.2% 2018-11-29
CVE-2005-4216 EXP The Administration Service (FMSAdmin.exe) in Macromedia Flash Media Server 2.0 r1145 allows remote attackers to cause a denial of service (application… Patch early 7.8 high 4.2% 2005-12-14
CVE-2010-0552 EXP Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via mu… Patch early 7.5 high 4.2% 2010-02-04
CVE-2010-4232 EXP The web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allo… Patch early 10.0 high 4.2% 2010-11-17
CVE-2015-8284 EXP SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions. Patch early 8.8 high 4.2% 2017-04-13
CVE-2007-1076 EXP Multiple directory traversal vulnerabilities in phpTrafficA 1.4.1, and possibly earlier, allow remote attackers to include arbitrary local files via a… Patch early 7.5 high 4.2% 2007-02-22
CVE-2006-6376 EXP Multiple directory traversal vulnerabilities in fm.php in Simple File Manager (SFM) 0.24a allow remote attackers to use ".." sequences to (1) read arb… Patch early 7.5 high 4.2% 2006-12-07
CVE-2014-1204 EXP SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated users to execute arbitrary SQL com… Patch early 7.5 high 4.2% 2014-01-31
CVE-2015-2878 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of admini… Patch early 8.8 high 4.2% 2017-10-23
CVE-2005-0185 EXP Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap packet that con… Patch early 7.5 high 4.2% 2005-05-02
CVE-2010-0702 EXP SQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 4.2% 2010-02-23
CVE-2015-7068 EXP IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privi… Patch early 7.8 high 4.2% 2015-12-11
CVE-2007-4446 EXP Format string vulnerability in the server in Toribash 2.71 and earlier allows remote attackers to execute arbitrary code via format string specifiers… Patch early 7.5 high 4.2% 2007-08-21
← previous page 282 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt