peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,941 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-02

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2000-0260 EXP Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the "Link Vi… Patch early 7.5 high 13.9% 2000-04-14
CVE-2002-0187 EXP Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root pa… Patch early 7.5 high 13.9% 2002-07-03
CVE-2004-1364 EXP Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bi… Patch early 8.5 high 13.9% 2004-08-04
CVE-2012-4330 EXP The Samsung D6000 TV and possibly other products allows remote attackers to cause a denial of service (crash) via a long string in certain fields, as… Patch early 7.8 high 13.9% 2012-08-14
CVE-2009-1257 EXP Heap-based buffer overflow in Magic ISO Maker 5.5 build 0274 allows remote attackers to cause a denial of service (crash) or execute arbitrary code vi… Patch early 9.0 high 13.9% 2009-04-07
CVE-2000-0002 EXP Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request. Patch early 10.0 high 13.9% 1999-12-22
CVE-2019-6545 EXP AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update.… Patch early 7.5 high 13.9% 2019-02-13
CVE-2010-3127 EXP Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5 allows local users, and possibly remote attackers, to execute arbitrary code an… Patch early 9.3 high 13.9% 2010-08-26
CVE-2010-3426 EXP Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and ex… Patch early 7.5 high 13.9% 2010-09-16
CVE-2011-4875 EXP Stack-based buffer overflow in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP,… Patch early 9.3 high 13.8% 2012-02-03
CVE-2002-1076 EXP Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET reque… Patch early 7.5 high 13.8% 2002-10-04
CVE-2007-1492 EXP winmm.dll in Microsoft Windows XP allows user-assisted remote attackers to cause a denial of service (infinite loop) via a large cch argument value to… Patch early 7.1 high 13.8% 2007-03-16
CVE-2007-3997 EXP The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir res… Patch early 7.5 high 13.8% 2007-09-04
CVE-2004-0189 EXP The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") charact… Patch early 7.5 high 13.8% 2004-03-15
CVE-2015-0002 EXP The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, W… Patch early 7.2 high 13.8% 2015-01-13
CVE-2009-1675 EXP Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 227 reply to a PASV comma… Patch early 9.3 high 13.8% 2009-05-18
CVE-2017-7478 EXP OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue… Patch early 7.5 high 13.8% 2017-05-15
CVE-2010-4300 EXP Heap-based buffer overflow in the dissect_ldss_transfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector in Wireshark 1.2.0 through 1.2.… Patch early 7.5 high 13.8% 2010-11-26
CVE-2019-6973 EXP Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is conf… Patch early 7.5 high 13.8% 2019-03-21
CVE-2014-9473 EXP Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arb… Patch early 7.5 high 13.8% 2015-01-08
CVE-2007-4498 EXP The Grandstream SIP Phone GXV-3000 with firmware 1.0.1.7, Loader 1.0.0.6, and Boot 1.0.0.18 allows remote attackers to force silent call completion, e… Patch early 7.8 high 13.8% 2007-08-23
CVE-2018-4237 EXP An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchO… Patch early 7.8 high 13.7% 2018-06-08
CVE-2019-11415 EXP An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. A malformed login request allows remote attackers to cause a denial of service (reboot),… Patch early 7.5 high 13.7% 2019-04-22
CVE-2001-0522 EXP Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in th… Patch early 7.5 high 13.7% 2001-08-14
CVE-2005-3684 EXP Multiple buffer overflows in freeFTPd 1.0.8, without logging enabled, allow remote authenticated attackers to cause a denial of service (application c… Patch early 7.5 high 13.7% 2005-11-19
CVE-2010-3146 EXP Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 allow local users to gain privileges via a Trojan horse (1) mso.dll or (2)… Patch early 9.3 high 13.7% 2010-08-27
CVE-2011-0614 EXP Buffer overflow in Adobe Audition 3.0.1 and earlier allows remote attackers to cause a denial of service (memory corruption and application crash) or… Patch early 9.3 high 13.7% 2011-05-16
CVE-2004-1293 EXP Buffer overflow in the ReadFontTbl function in reader.c for rtf2latex2e 1.0fc2 allows remote attackers to execute arbitrary code via a crafted RTF fil… Patch early 10.0 high 13.7% 2005-01-10
CVE-2010-2918 EXP PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites (com_joomla-visites) component 1.1 RC2 for Joomla! allows re… Patch early 7.5 high 13.7% 2010-07-30
CVE-2002-0814 EXP Buffer overflow in VMware Authorization Service for VMware GSX Server 2.0.0 build-2050 allows remote authenticated users to execute arbitrary code via… Patch early 7.5 high 13.7% 2002-08-12
← previous page 105 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt