peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,371 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2013-6040 EXP MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls before version 4.0 vulnerable to arbitrary code via a crafted HTML document. Latest versions (4.0… Patch early 8.1 high 7.4% 2014-01-21
CVE-2017-10688 EXP In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A crafted input will lead to a… Patch early 7.5 high 7.4% 2017-06-29
CVE-2017-5359 EXP EasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI. Patch early 7.5 high 7.4% 2017-03-15
CVE-2006-2531 EXP Ipswitch WhatsUp Professional 2006 only verifies the user's identity via HTTP headers, which allows remote attackers to spoof being a trusted console… Patch early 7.5 high 7.4% 2006-05-22
CVE-2006-5495 EXP Multiple PHP remote file inclusion vulnerabilities in Trawler Web CMS 1.8.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 7.4% 2006-10-25
CVE-2003-0510 EXP Format string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command. Patch early 7.5 high 7.4% 2003-08-07
CVE-2014-9619 EXP Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x befo… Patch early 7.2 high 7.4% 2017-09-19
CVE-2012-4357 EXP Array index error in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 might allow remote attackers to execute arbit… Patch early 9.3 high 7.4% 2012-08-19
CVE-2008-5904 EXP The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via inpu… Patch early 7.5 high 7.4% 2009-01-15
CVE-2021-43579 EXP A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linkin… Patch early 7.8 high 7.3% 2022-01-10
CVE-2004-1554 EXP PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by modifying the… Patch early 7.5 high 7.3% 2004-12-31
CVE-2000-0766 EXP Buffer overflow in vqSoft vqServer 1.4.49 allows remote attackers to cause a denial of service or possibly gain privileges via a long HTTP GET request… Patch early 7.5 high 7.3% 2000-10-20
CVE-2000-0400 EXP The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to do… Patch early 7.5 high 7.3% 2000-05-13
CVE-2011-4800 EXP Directory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and write arbitrary files, and list a… Patch early 9.0 high 7.3% 2011-12-14
CVE-2001-1195 EXP Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager, which allows remote attackers… Patch early 7.5 high 7.3% 2001-12-15
CVE-2013-1594 EXP An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wireless keys and 3rd party creden… Patch early 7.5 high 7.3% 2020-01-24
CVE-2009-1627 EXP Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbitrary code via a long .asf URL… Patch early 9.3 high 7.3% 2009-05-12
CVE-2004-1161 EXP rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access res… Patch early 7.5 high 7.3% 2005-01-10
CVE-2007-4105 EXP A certain ActiveX control in BaiduBar.dll in Baidu Soba Search Bar 5.4 allows remote attackers to execute arbitrary code via a request containing "a l… Patch early 9.3 high 7.3% 2007-07-31
CVE-2017-6104 EXP Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0. Patch early 7.5 high 7.3% 2017-03-02
CVE-2006-4422 EXP PHP remote file inclusion vulnerability in includes/phpdig/libs/search_function.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 7.3% 2006-08-29
CVE-2006-0791 EXP PHP remote file inclusion vulnerability in index.php in DreamCost HostAdmin allows remote attackers to include arbitrary files via the $path variable,… Patch early 7.5 high 7.3% 2006-02-19
CVE-2007-3312 EXP Directory traversal vulnerability in admin/plugin_manager.php in Jasmine CMS 1.0 allows remote authenticated administrators to include and execute arb… Patch early 9.0 high 7.3% 2007-06-21
CVE-2006-1124 EXP Buffer overflow in RevilloC MailServer and Proxy 1.21 allows remote attackers to execute arbitrary code via a long USER command. Patch early 7.5 high 7.3% 2006-03-09
CVE-2008-5625 EXP PHP 5 before 5.2.7 does not enforce the error_log safe_mode restrictions when safe_mode is enabled through a php_admin_flag setting in httpd.conf, whi… Patch early 7.5 high 7.3% 2008-12-17
CVE-2018-10258 EXP A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be… Patch early 8.8 high 7.3% 2018-05-01
CVE-2026-42167 EXP mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER request… Patch early 8.1 high 7.3% 2026-04-28
CVE-2006-2439 EXP Stack-based buffer overflow in ZipCentral 4.01 allows remote user-assisted attackers to execute arbitrary code via a ZIP archive containing a long fil… Patch early 7.6 high 7.3% 2006-06-01
CVE-2007-1569 EXP Stack-based buffer overflow in NewsBin Pro 4.32 allows remote attackers to cause a denial of service or execute arbitrary code via a yEnc (yEncode) en… Patch early 10.0 high 7.3% 2007-03-21
CVE-2008-0647 EXP Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.2… Patch early 10.0 high 7.3% 2008-02-07
← previous page 159 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt