peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-0644 EXP Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members… Patch early 7.5 high 11.4% 2002-08-12
CVE-2010-1199 EXP Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and… Patch early 9.3 high 11.4% 2010-06-24
CVE-2007-2714 EXP Unspecified vulnerability in akismet.php in Matt Mullenweg Akismet before 2.0.2, a WordPress plugin, has unknown impact and attack vectors. Patch early 10.0 high 11.4% 2007-05-16
CVE-2020-24365 EXP An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenti… Patch early 8.8 high 11.4% 2020-09-24
CVE-2007-0134 EXP Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is su… Patch early 7.5 high 11.4% 2007-01-09
CVE-2005-0859 EXP PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlin… Patch early 7.5 high 11.4% 2005-05-02
CVE-2020-14945 EXP A privilege escalation vulnerability exists within Global RADAR BSA Radar 1.6.7234.24750 and earlier that allows an authenticated, low-privileged user… Patch early 8.8 high 11.4% 2020-06-22
CVE-2000-0506 EXP The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to pr… Patch early 10.0 high 11.4% 2000-06-09
CVE-2004-1304 EXP Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file. Patch early 10.0 high 11.4% 2005-01-10
CVE-2019-16112 EXP TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceManag… Patch early 8.8 high 11.4% 2020-05-13
CVE-2018-11492 EXP ASUS HG100 devices allow denial of service via an IPv4 packet flood. Patch early 7.5 high 11.4% 2018-08-10
CVE-2007-6327 EXP Buffer overflow in a certain ActiveX control in Online Media Technologies AVSMJPEGFILE.DLL 1.1.1.102 allows remote attackers to execute arbitrary code… Patch early 7.5 high 11.4% 2007-12-13
CVE-2019-6989 EXP TP-Link TL-WR940N is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the ipAddrDispose function. By sending special… Patch early 8.8 high 11.4% 2019-06-06
CVE-2008-2745 EXP Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows remote attackers to execute ar… Patch early 9.3 high 11.4% 2008-06-17
CVE-2016-2210 EXP Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (… Patch early 7.3 high 11.4% 2016-06-30
CVE-2003-0487 EXP Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code… Patch early 7.5 high 11.4% 2003-08-07
CVE-2008-2044 EXP includes/library.php in netOffice Dwins 1.3 p2 compares the demoSession variable to the 'true' string literal instead of the true boolean literal, whi… Patch early 7.5 high 11.4% 2008-05-01
CVE-2013-6877 EXP Heap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allows remote attackers to e… Patch early 9.3 high 11.3% 2013-12-19
CVE-2016-1608 EXP vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated users to execute arbitrary comm… Patch early 8.8 high 11.3% 2016-08-01
CVE-2010-4278 EXP operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters… Patch early 9.0 high 11.3% 2010-12-02
CVE-2009-4018 EXP The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and… Patch early 7.5 high 11.3% 2009-11-29
CVE-2007-1421 EXP Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root… Patch early 10.0 high 11.3% 2007-03-13
CVE-2010-3154 EXP Untrusted search path vulnerability in Adobe Extension Manager CS5 5.0.298 allows local users, and possibly remote attackers, to execute arbitrary cod… Patch early 9.3 high 11.3% 2010-08-27
CVE-2010-0416 EXP Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix Player 1.0.6 and RealPlayer al… Patch early 7.5 high 11.3% 2010-02-18
CVE-2008-1461 EXP Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the command line. NO… Patch early 7.6 high 11.3% 2008-03-24
CVE-2006-4920 EXP Multiple PHP remote file inclusion vulnerabilities in Site@School (S@S) 2.4.02 and earlier allow remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 11.3% 2006-09-21
CVE-2017-2370 EXP An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. wa… Patch early 7.8 high 11.3% 2017-02-20
CVE-2008-4547 EXP Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows remote attackers to execute a… Patch early 9.3 high 11.3% 2008-10-14
CVE-2017-9812 EXP The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Ma… Patch early 7.5 high 11.3% 2017-07-17
CVE-2017-16953 EXP connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration o… Patch early 7.5 high 11.3% 2017-12-01
← previous page 119 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt