peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,295 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-6750 EXP Buffer overflow in Ricoh DL FTP Server 1.1.0.6 and earlier allows remote attackers to execute arbitrary code via a long USER command. Patch early 7.5 high 7.7% 2015-08-31
CVE-2003-1341 EXP The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.e… Patch early 7.5 high 7.7% 2003-12-31
CVE-2015-3693 EXP Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates for DDR3 RAM, which might make i… Patch early 9.3 high 7.7% 2015-07-03
CVE-2008-4134 EXP PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other versions before 0.05, allows remo… Patch early 7.5 high 7.7% 2008-09-19
CVE-2008-4509 EXP Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows remote attackers to execute a… Patch early 10.0 high 7.7% 2008-10-09
CVE-2017-6984 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. iTunes before 12.6.1 on Windows is… Patch early 8.8 high 7.7% 2017-05-22
CVE-2013-3615 EXP Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent attackers to discover clearte… Patch early 7.8 high 7.7% 2013-09-17
CVE-2000-0207 EXP SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters. Patch early 7.5 high 7.7% 2000-03-01
CVE-2000-0424 EXP The CGI counter 4.0.7 by George Burgyan allows remote attackers to execute arbitrary commands via shell metacharacters. Patch early 7.5 high 7.7% 2000-05-15
CVE-2000-0432 EXP The calender.pl and the calendar_admin.pl calendar scripts by Matt Kruse allow remote attackers to execute arbitrary commands via shell metacharacters… Patch early 7.5 high 7.7% 2000-05-16
CVE-2012-1830 EXP Stack-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 555. Patch early 10.0 high 7.7% 2012-07-05
CVE-2014-7910 EXP Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service or possibly have other impact v… Patch early 7.5 high 7.7% 2014-11-19
CVE-2002-2145 EXP Savant Web Server 3.1 and earlier allows remote attackers to bypass authentication for password protected user folders via a URL with a hex encoded sp… Patch early 7.5 high 7.7% 2002-12-31
CVE-2006-0881 EXP Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attac… Patch early 7.5 high 7.7% 2006-02-24
CVE-2002-2400 EXP Buffer overflow in the httpdProcessRequest function in LibHTTPD 1.2 allows remote attackers to cause a denial of service (crash) and possibly execute… Patch early 10.0 high 7.7% 2002-12-31
CVE-2014-3085 EXP systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute arb… Patch early 7.1 high 7.6% 2014-08-17
CVE-2011-4162 EXP The (1) AddUser, (2) AddUserEx, (3) RemoveUser, (4) RemoveUserByGuide, (5) RemoveUserEx, and (6) RemoveUserRegardless methods in HP Protect Tools Devi… Patch early 7.5 high 7.6% 2011-12-05
CVE-2007-3606 EXP Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCII versions, allows remote atta… Patch early 7.6 high 7.6% 2007-07-06
CVE-2002-0948 EXP Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute server-side includes (SSI) as t… Patch early 7.5 high 7.6% 2002-10-04
CVE-2015-6401 EXP Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication requirement and execute unspecif… Patch early 7.5 high 7.6% 2015-12-14
CVE-2004-0292 EXP Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code v… Patch early 10.0 high 7.6% 2004-11-23
CVE-2004-1208 EXP Buffer overflow in Orbz 2.10 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code… Patch early 10.0 high 7.6% 2005-01-10
CVE-2011-2963 EXP TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to… Patch early 10.0 high 7.6% 2011-07-29
CVE-2003-1251 EXP The (1) menu.inc.php, (2) datasets.php and (3) mass_operations.inc.php (mistakenly referred to as mass_opeations.inc.php) scripts in N/X 2002 allow re… Patch early 7.5 high 7.6% 2003-12-31
CVE-2008-1231 EXP Directory traversal vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to include and execute arbitrary local .jsp files… Patch early 9.3 high 7.6% 2008-03-10
CVE-2018-18955 EXP In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nest… Patch early 7.0 high 7.6% 2018-11-16
CVE-2006-2877 EXP PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and earlier allows remote attackers to include arbitrary PHP files via the include_prefix… Patch early 7.5 high 7.6% 2006-06-07
CVE-2020-35488 EXP The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a… Patch early 7.5 high 7.6% 2021-01-05
CVE-2008-1762 EXP Opera before 9.27 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted scaled image pattern… Patch early 9.3 high 7.6% 2008-04-12
CVE-2006-4532 EXP PHP remote file inclusion vulnerability in articles/article.php in Yet Another Community System (YACS) CMS 6.6.1 and earlier allows remote attackers t… Patch early 7.5 high 7.6% 2006-09-01
← previous page 155 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt