peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,095 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2011-5167 EXP Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strateg… Patch early 9.3 high 9.8% 2012-09-15
CVE-2018-11479 EXP The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that establishes… Patch early 7.8 high 9.8% 2018-05-25
CVE-2019-6215 EXP A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for W… Patch early 8.8 high 9.8% 2019-03-05
CVE-2008-4694 EXP Unspecified vulnerability in Opera before 9.60 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via… Patch early 9.3 high 9.8% 2008-10-23
CVE-2013-3934 EXP Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allows remote attackers to execute… Patch early 9.3 high 9.8% 2013-09-10
CVE-2008-7103 EXP Stack-based buffer overflow in an ActiveX control in najdisitoolbar.dll in Najdi.si Toolbar 2.0.4.1 allows remote attackers to cause a denial of servi… Patch early 9.3 high 9.8% 2009-08-27
CVE-2016-4535 EXP Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to cause a denial of service (memo… Patch early 7.5 high 9.8% 2016-05-05
CVE-2006-1243 EXP Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitra… Patch early 7.5 high 9.7% 2006-03-15
CVE-2007-2584 EXP Buffer overflow in the IsOldAppInstalled function in the McSubMgr.McSubMgr Subscription Manager ActiveX control (MCSUBMGR.DLL) in McAfee SecurityCente… Patch early 10.0 high 9.7% 2007-05-10
CVE-2019-9832 EXP The AirDrop application through 2.0 for Android allows remote attackers to cause a denial of service via a client that makes many socket connections t… Patch early 7.5 high 9.7% 2019-03-15
CVE-1999-0879 EXP Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file. Patch early 10.0 high 9.7% 1999-10-01
CVE-2008-3702 EXP Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used in products such as SpeedBit… Patch early 9.3 high 9.7% 2008-08-15
CVE-2008-5406 EXP Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denial of service (application cras… Patch early 9.3 high 9.7% 2008-12-10
CVE-2008-5691 EXP Heap-based buffer overflow in the Phoenician Casino FlashAX ActiveX control 1.0.0.7 allows remote attackers to execute arbitrary code via a long argum… Patch early 9.3 high 9.7% 2008-12-19
CVE-2006-4968 EXP PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execute arbitrary PHP code via a UR… Patch early 7.5 high 9.7% 2006-09-25
CVE-2006-4913 EXP Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary local files an… Patch early 7.5 high 9.7% 2006-09-21
CVE-2019-11706 EXP A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages… Patch early 7.5 high 9.7% 2019-07-23
CVE-2019-16902 EXP In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying t… Patch early 7.5 high 9.7% 2019-09-27
CVE-2001-1246 EXP PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote… Patch early 7.5 high 9.7% 2001-06-30
CVE-2018-7254 EXP The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-r… Patch early 7.8 high 9.7% 2018-02-19
CVE-2023-37979 EXP Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions. Patch early 7.1 high 9.7% 2023-07-27
CVE-2017-11662 EXP The _WM_ParseNewMidi function in f_midi.c in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mi… Patch early 7.5 high 9.7% 2017-08-17
CVE-2009-3241 EXP Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers to cause a… Patch early 7.8 high 9.7% 2009-09-18
CVE-2018-9010 EXP Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via the /cgi-bin/cgiServer.exx page… Patch early 7.2 high 9.7% 2018-03-25
CVE-2014-5074 EXP Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device restart and STOP transition)… Patch early 7.1 high 9.7% 2014-08-17
CVE-1999-0182 EXP Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password. Patch early 10.0 high 9.7% 1997-09-30
CVE-2000-0775 EXP Buffer overflow in RobTex Viking server earlier than 1.06-370 allows remote attackers to cause a denial of service or execute arbitrary commands via a… Patch early 7.5 high 9.7% 2000-10-20
CVE-2000-0991 EXP Buffer overflow in Hilgraeve, Inc. HyperTerminal client on Windows 98, ME, and 2000 allows remote attackers to execute arbitrary commands via a long t… Patch early 7.5 high 9.7% 2000-12-19
CVE-2007-2079 EXP The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the database server hostname, whic… Patch early 9.3 high 9.7% 2007-04-18
CVE-2003-0436 EXP Buffer overflow in search.cgi for mnoGoSearch 3.1.20 allows remote attackers to execute arbitrary code via a long ul parameter. Patch early 7.5 high 9.7% 2003-07-24
← previous page 132 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt