peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,084 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2011-3981 EXP PHP remote file inclusion vulnerability in actions.php in the Allwebmenus plugin 1.1.3 for WordPress allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 10.1% 2011-10-04
CVE-2014-10011 EXP Stack-based buffer overflow in UltraCamLib in the UltraCam ActiveX Control (UltraCamX.ocx) for the TRENDnet SecurView camera TV-IP422WN allows remote… Patch early 7.5 high 10.1% 2015-01-13
CVE-2000-0272 EXP RealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at port 7070. Patch early 7.8 high 10.1% 2000-04-20
CVE-2009-0103 EXP Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) apps_pat… Patch early 7.5 high 10.1% 2009-01-09
CVE-1999-0192 EXP Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable. Patch early 10.0 high 10% 1997-10-18
CVE-2005-2772 EXP Multiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to execute arbitrary code via (1)… Patch early 7.5 high 10% 2005-09-02
CVE-2005-0439 EXP Buffer overflow in the decode_post function in ELOG before 2.5.7 allows remote attackers to execute arbitrary code via attachments with long file name… Patch early 7.5 high 10% 2005-05-02
CVE-2000-0443 EXP The web interface server in HP Web JetAdmin 5.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack. Patch early 7.5 high 10% 2000-05-24
CVE-2007-1376 EXP The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which… Patch early 7.5 high 10% 2007-03-10
CVE-2014-2223 EXP Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to execute arbit… Patch early 7.5 high 10% 2014-09-11
CVE-2004-1892 EXP Stack-based buffer overflow in DecodeBase16 function, as used in the (1) IRC module and (2) web server in eMule 0.42d, allows remote attackers to exec… Patch early 7.5 high 10% 2004-12-31
CVE-2008-7126 EXP Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of service (cra… Patch early 10.0 high 10% 2009-08-31
CVE-2018-20782 EXP The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages. Patch early 7.5 high 10% 2019-02-17
CVE-2013-2474 EXP Directory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' parameter. Patch early 7.5 high 10% 2020-01-27
CVE-2008-2511 EXP Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEventCli.dll in CA Internet Secu… Patch early 9.3 high 10% 2008-06-02
CVE-2009-4427 EXP Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbitrary local files via a .. (do… Patch early 7.5 high 10% 2009-12-28
CVE-2006-1777 EXP Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execute arbitra… Patch early 7.5 high 10% 2006-04-13
CVE-1999-0951 EXP Buffer overflow in OmniHTTPd CGI program imagemap.exe allows remote attackers to execute commands. Patch early 10.0 high 10% 1999-10-22
CVE-2006-1149 EXP PHP remote file inclusion vulnerability in lib/OWL_API.php in OWL Intranet Engine 0.82, when register_globals is enabled, allows remote attackers to i… Patch early 7.5 high 10% 2006-03-10
CVE-2008-1322 EXP The File Check Utility (fcheck.exe) in ASG-Sentry Network Manager 7.0.0 and earlier allows remote attackers to cause a denial of service (CPU consumpt… Patch early 7.8 high 10% 2008-03-13
CVE-2006-0899 EXP Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot… Patch early 7.5 high 10% 2006-02-27
CVE-2016-1464 EXP Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code via a crafted file, aka Bug ID… Patch early 7.8 high 10% 2016-09-03
CVE-2018-17961 EXP Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this is… Patch early 8.6 high 10% 2018-10-15
CVE-2013-6283 EXP VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a lon… Patch early 7.5 high 10% 2013-10-25
CVE-2020-25538 EXP An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web pa… Patch early 8.8 high 10% 2020-11-13
CVE-2020-25557 EXP In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs… Patch early 8.8 high 10% 2020-11-13
CVE-2005-1666 EXP Multiple buffer overflows in Orenosv HTTP/FTP Server 0.8.1 allow remote authenticated users to cause a denial of service (server crash) and possibly e… Patch early 7.5 high 10% 2005-05-18
CVE-2007-4582 EXP Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ACTi Network Video Recorder (NVR) SP2 2.… Patch early 7.5 high 10% 2007-08-29
CVE-2003-1247 EXP Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile,… Patch early 7.5 high 10% 2003-12-31
CVE-2008-7170 EXP GSC build 2067 and earlier relies on the client to enforce administrator privileges, which allows remote attackers to execute arbitrary administrator… Patch early 10.0 high 9.9% 2009-09-08
← previous page 129 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt