peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,887 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

187,678 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2000-0325 EXP The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability. Patch early 7.2 high 3.7% 1999-08-20
CVE-2016-3694 EXP Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-module is not installed, allow remo… Patch early 9.8 critical 3.7% 2017-02-15
CVE-2005-4087 EXP PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier… Patch early 7.5 high 3.7% 2005-12-08
CVE-2007-2599 EXP Multiple SQL injection vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to execute arbitrary SQL comma… Patch early 7.5 high 3.7% 2007-05-11
CVE-2013-4862 EXP MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmware via t… Patch early 8.1 high 3.7% 2020-01-28
CVE-2012-4772 EXP SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL commands via the plan_id paramet… Patch early 7.5 high 3.7% 2012-10-22
CVE-2005-1894 EXP Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer heade… Patch early 7.5 high 3.7% 2005-06-09
CVE-2009-2784 EXP Multiple directory traversal vulnerabilities in dit.cms 1.3, when register_globals is enabled, allow remote attackers to include and execute arbitrary… Patch early 9.3 high 3.7% 2009-08-17
CVE-2006-2100 EXP Directory traversal vulnerability in Magic ISO 5.0 Build 0166 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an… Patch early 7.8 high 3.7% 2006-04-29
CVE-2006-2102 EXP Directory traversal vulnerability in PowerISO 2.9 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image. Patch early 7.8 high 3.7% 2006-04-29
CVE-2007-1303 EXP Directory traversal vulnerability in rb.cgi in RRDBrowse 1.6 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the fil… Patch early 7.8 high 3.7% 2007-03-07
CVE-2006-5092 EXP PHP remote file inclusion vulnerability in navigation/menu.php in A-Blog 2 allows remote attackers to execute arbitrary PHP code via a URL in the navi… Patch early 7.5 high 3.7% 2006-09-29
CVE-2006-7132 EXP Directory traversal vulnerability in pmd-config.php in PHPMyDesk 1.0beta allows remote attackers to include arbitrary local files via the pmdlang para… Patch early 10.0 high 3.7% 2007-03-06
CVE-2007-1080 EXP Multiple heap-based buffer overflows in TurboFTP 5.30 Build 572 allow remote servers to cause a denial of service via (1) long filename in a response… Patch early 7.8 high 3.7% 2007-02-22
CVE-2007-4740 EXP The HPRevolutionRegistryManager ActiveX control in Hp.Revolution.RegistryManager.dll 1 in Telecom Italy Alice Messenger allows remote attackers to cre… Patch early 9.3 high 3.7% 2007-09-06
CVE-2007-2642 EXP Directory traversal vulnerability in galeria.php in R2K Gallery 1.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang2 pa… Patch early 7.8 high 3.7% 2007-05-13
CVE-2017-5123 EXP Insufficient data validation in waitid allowed an user to escape sandboxes on Linux. Patch early 8.8 high 3.7% 2021-11-02
CVE-2017-8841 EXP Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350… Patch early 8.1 high 3.7% 2017-06-05
CVE-2009-4147 EXP The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear the (1) LD_LIBMAP, (2) LD_LIBRA… Patch early 7.2 high 3.7% 2009-12-02
CVE-2018-4083 EXP An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Touch Bar Support" component. It allows a… Patch early 7.8 high 3.7% 2018-04-03
CVE-2000-0641 EXP Savant web server allows remote attackers to execute arbitrary commands via a long GET request. Patch early 7.5 high 3.7% 2000-07-08
CVE-2017-6896 EXP Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to admin privi… Patch early 8.8 high 3.7% 2017-03-14
CVE-2007-2430 EXP shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by placing file contents and dir… Patch early 7.8 high 3.7% 2007-05-02
CVE-2014-9558 EXP Multiple SQL injection vulnerabilities in SmartCMS v.2. Patch early 9.8 critical 3.7% 2017-08-28
CVE-2015-7346 EXP SQL injection vulnerability in ZCMS 1.1. Patch early 9.8 critical 3.7% 2017-06-07
CVE-2019-7303 EXP A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64… Patch early 7.5 high 3.7% 2019-04-23
CVE-2008-4243 EXP Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote… Patch early 7.8 high 3.7% 2008-09-25
CVE-2008-7010 EXP Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a direct request to admin/regis… Patch early 10.0 high 3.7% 2009-08-19
CVE-2007-1100 EXP Directory traversal vulnerability in download.php in Ahmet Sacan Pickle before 20070301 allows remote attackers to read arbitrary files via a .. (dot… Patch early 7.8 high 3.7% 2007-02-26
CVE-2006-0418 EXP Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a crafted username. Patch early 7.5 high 3.7% 2006-01-25
← previous page 293 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt