peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,092 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-5399 EXP The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of serv… Patch early 7.8 high 9.8% 2017-04-21
CVE-2019-16294 EXP SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file… Patch early 7.8 high 9.8% 2019-09-14
CVE-2010-0071 EXP Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to… Patch early 10.0 high 9.8% 2010-01-13
CVE-2006-1781 EXP PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 9.8% 2006-04-13
CVE-2016-8526 EXP Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to… Patch early 8.8 high 9.8% 2018-08-06
CVE-2019-1674 EXP A vulnerability in the update service of Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools for Windows could allow an authenticated,… Patch early 7.8 high 9.8% 2019-02-28
CVE-2009-3705 EXP PHP remote file inclusion vulnerability in debugger.php in Achievo before 1.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 9.8% 2009-10-16
CVE-1999-0935 EXP classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form. Patch early 10.0 high 9.8% 1999-12-15
CVE-2006-3955 EXP Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a allow remote attackers to execute arbitrary PHP code via a URL in the absolute… Patch early 7.5 high 9.8% 2006-08-01
CVE-2009-0304 EXP The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial of service (system crash) via… Patch early 7.8 high 9.8% 2009-01-27
CVE-2022-38840 EXP cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local file… Patch early 7.5 high 9.8% 2023-04-16
CVE-1999-0404 EXP Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution. Patch early 7.5 high 9.8% 1999-02-14
CVE-2019-7181 EXP Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the program. Patch early 7.5 high 9.8% 2019-05-09
CVE-2006-5768 EXP Multiple PHP remote file inclusion vulnerabilities in Cyberfolio 2.0 RC1 and earlier, when register_globals is enabled, allow remote attackers to exec… Patch early 7.5 high 9.8% 2006-11-06
CVE-2006-0515 EXP Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3.x before 2.3(4) and 3.x before 3.1(7), when used… Patch early 7.5 high 9.8% 2006-05-09
CVE-2017-9872 EXP The III_dequantize_sample function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cau… Patch early 7.8 high 9.8% 2017-06-25
CVE-2014-1905 EXP Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows… Patch early 10.0 high 9.8% 2014-12-29
CVE-2018-20580 EXP The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request param… Patch early 8.8 high 9.8% 2019-05-03
CVE-2016-1240 EXP The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and l… Patch early 7.8 high 9.8% 2016-10-03
CVE-2010-2752 EXP Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.… Patch early 9.3 high 9.8% 2010-07-30
CVE-2005-1523 EXP Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitr… Patch early 7.5 high 9.8% 2005-05-26
CVE-2004-2513 EXP Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via a long SELECT command. Patch early 10.0 high 9.8% 2004-12-31
CVE-2000-0074 EXP PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions. Patch early 7.5 high 9.8% 2000-01-11
CVE-2001-1196 EXP Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argument… Patch early 10.0 high 9.8% 2001-12-17
CVE-2014-5086 EXP A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let… Patch early 8.8 high 9.8% 2020-02-10
CVE-2011-3498 EXP Heap-based buffer overflow in Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (crash) and possibl… Patch early 10.0 high 9.8% 2011-09-16
CVE-2012-2227 EXP Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local files via… Patch early 7.5 high 9.8% 2012-08-26
CVE-2001-0702 EXP Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long (1) username, (2) p… Patch early 7.5 high 9.8% 2001-09-20
CVE-2004-0069 EXP Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifie… Patch early 7.5 high 9.8% 2004-02-17
CVE-2002-0313 EXP Buffer overflow in Essentia Web Server 2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long URL. Patch early 7.5 high 9.8% 2002-06-25
← previous page 131 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt