peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,813 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

187,634 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-3935 EXP PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary PHP code v… Patch early 9.3 high 4% 2007-07-21
CVE-2005-2210 EXP Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL. Patch early 7.5 high 4% 2005-07-11
CVE-2005-2644 EXP Buffer overflow in JaguarEditControl.dll in Isemarket JaguarControl allows remote attackers to cause a denial of service (crash) and possibly execute… Patch early 7.5 high 4% 2005-08-23
CVE-2017-6550 EXP Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitrary SQL commands via the (1) TA… Patch early 9.8 critical 4% 2017-03-20
CVE-2006-5014 EXP Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladm… Patch early 8.8 high 4% 2006-09-27
CVE-2007-0585 EXP include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain source code of files via the conff… Patch early 9.3 high 4% 2007-01-30
CVE-2007-2506 EXP WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attackers to cause a denial of service… Patch early 7.8 high 4% 2007-05-04
CVE-2017-5633 EXP Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) chang… Patch early 8.0 high 4% 2017-03-06
CVE-2007-4220 EXP Directory traversal vulnerability in Motorola Timbuktu Pro before 8.6.5 for Windows allows remote attackers to create or delete arbitrary files via a… Patch early 7.8 high 4% 2007-08-29
CVE-2009-3753 EXP Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension… Patch early 7.5 high 4% 2009-10-22
CVE-2016-1744 EXP The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or… Patch early 7.8 high 4% 2016-03-24
CVE-2006-4060 EXP PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 4% 2006-08-10
CVE-2007-2495 EXP Multiple stack-based buffer overflows in the ExcelOCX ActiveX control in ExcelViewer.ocx 3.1.0.6 allow remote attackers to cause a denial of service (… Patch early 7.5 high 4% 2007-05-04
CVE-2006-5895 EXP PHP remote file inclusion vulnerability in core/core.php in EncapsCMS 0.3.6 allows remote attackers to execute arbitrary PHP code via a URL in the roo… Patch early 7.5 high 4% 2006-11-14
CVE-2007-1590 EXP The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device cra… Patch early 7.8 high 4% 2007-03-21
CVE-2017-15957 EXP my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file. Patch early 8.8 high 3.9% 2017-10-29
CVE-2017-17590 EXP FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter. Patch early 9.8 critical 3.9% 2017-12-13
CVE-2008-2686 EXP webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overwriting a PHP file in webinc/bx… Patch early 7.5 high 3.9% 2008-06-13
CVE-2008-2092 EXP Linksys SPA-2102 Phone Adapter 3.3.6 allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE: the… Patch early 7.8 high 3.9% 2008-05-06
CVE-2000-0155 EXP Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when… Patch early 7.2 high 3.9% 2000-02-18
CVE-2014-9605 EXP WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a syste… Patch early 9.4 high 3.9% 2015-09-04
CVE-2006-7048 EXP Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarol… Patch early 7.5 high 3.9% 2007-02-24
CVE-2006-3930 EXP PHP remote file inclusion vulnerability in admin.a6mambohelpdesk.php in a6mambohelpdesk Mambo Component 18RC1 and earlier allows remote attackers to e… Patch early 7.5 high 3.9% 2006-07-31
CVE-2010-3888 EXP Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild… Patch early 7.2 high 3.9% 2010-10-08
CVE-2006-3884 EXP Multiple SQL injection vulnerabilities in links.php in Gonafish LinksCaffe 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) of… Patch early 7.5 high 3.9% 2006-07-27
CVE-2018-10900 EXP Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be… Patch early 7.8 high 3.9% 2018-07-26
CVE-2000-0624 EXP Buffer overflow in Winamp 2.64 and earlier allows remote attackers to execute arbitrary commands via a long #EXTINF: extension in the M3U playlist. Patch early 7.5 high 3.9% 2000-07-20
CVE-2005-3019 EXP Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request paramete… Patch early 7.5 high 3.9% 2005-09-21
CVE-2005-0419 EXP Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as demonstrate… Patch early 7.5 high 3.9% 2005-04-27
CVE-2005-2694 EXP Buffer overflow in WinAce 2.6.0.5, and possibly earlier versions, allows remote attackers to execute arbitrary code via a temporary (.tmp) file that c… Patch early 7.5 high 3.9% 2005-08-26
← previous page 287 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt