peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,359 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

12,661 results

CVESummaryPriorityCVSSEPSSPublished
CVE-1999-0146 EXP The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in… Patch early 7.5 high 14.9% 1997-07-15
CVE-2014-5210 EXP The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2… Patch early 10.0 high 14.9% 2014-08-21
CVE-2004-2262 EXP ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uplo… Patch early 7.5 high 14.9% 2004-12-31
CVE-2004-0934 EXP Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, whic… Patch early 7.5 high 14.9% 2005-01-27
CVE-2004-0936 EXP RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does… Patch early 7.5 high 14.9% 2005-01-27
CVE-2004-0937 EXP Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protectio… Patch early 7.5 high 14.9% 2005-02-09
CVE-2007-4476 EXP Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack." Patch early 7.5 high 14.9% 2007-09-05
CVE-2010-0838 EXP Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to… Patch early 7.5 high 14.9% 2010-04-01
CVE-2017-13861 EXP An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issu… Patch early 7.8 high 14.9% 2017-12-25
CVE-2013-6987 EXP Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before 4.3-3810 Update 3 allow remote… Patch early 7.5 high 14.9% 2013-12-31
CVE-2008-5722 EXP Buffer overflow in SAWStudio 3.9i allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrar… Patch early 10.0 high 14.9% 2008-12-26
CVE-2008-2040 EXP Stack-based buffer overflow in the HTTP::getAuthUserPass function (core/common/http.cpp) in Peercast 0.1218 and gnome-peercast allows remote attackers… Patch early 7.5 high 14.9% 2008-04-30
CVE-2010-1957 EXP Directory traversal vulnerability in the Love Factory (com_lovefactory) component 1.3.4 for Joomla! allows remote attackers to read arbitrary files vi… Patch early 7.5 high 14.8% 2010-05-19
CVE-2017-17020 EXP On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware… Patch early 8.8 high 14.8% 2018-05-01
CVE-2013-3881 EXP win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to gain privileges via a crafted ap… Patch early 7.2 high 14.8% 2013-10-09
CVE-2019-7666 EXP Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may a… Patch early 8.8 high 14.8% 2019-07-01
CVE-1999-1046 EXP Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long str… Patch early 10.0 high 14.8% 1999-03-01
CVE-2018-0491 EXP A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because th… Patch early 7.5 high 14.8% 2018-03-05
CVE-2014-2013 EXP Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote attackers to execute arbitrary… Patch early 7.5 high 14.8% 2014-03-03
CVE-2014-9463 EXP functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to… Patch early 8.8 high 14.8% 2017-09-15
CVE-2017-3807 EXP A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could… Patch early 8.8 high 14.8% 2017-02-09
CVE-2008-0477 EXP Stack-based buffer overflow in the QMPUpgrade.Upgrade.1 ActiveX control in QMPUpgrade.dll 1.0.0.1 in Move Networks Upgrade Manager allows remote attac… Patch early 10.0 high 14.8% 2008-01-29
CVE-2003-0280 EXP Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL… Patch early 10.0 high 14.7% 2003-06-16
CVE-2017-12500 EXP A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in… Patch early 8.8 high 14.7% 2018-02-15
CVE-2006-4197 EXP Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote at… Patch early 7.5 high 14.7% 2006-08-17
CVE-2010-1939 EXP Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup… Patch early 7.6 high 14.7% 2010-05-13
CVE-2006-5517 EXP Multiple PHP remote file inclusion vulnerabilities in Rhode Island Open Meetings Filing Application (OMFA) allow remote attackers to execute arbitrary… Patch early 7.5 high 14.7% 2006-10-26
CVE-2004-0691 EXP Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (… Patch early 7.5 high 14.7% 2004-09-28
CVE-2004-1289 EXP Multiple buffer overflows in (1) the getline function in pcalutil.c and (2) the get_holiday function in readfile.c for pcal 4.7.1 allow remote attacke… Patch early 10.0 high 14.7% 2005-01-10
CVE-2007-4584 EXP Stack-based buffer overflow in BitchX 1.1 Final allows remote IRC servers to execute arbitrary code via a long string in a MODE command, related to th… Patch early 10.0 high 14.7% 2007-08-29
← previous page 100 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt