peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,567 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-1945 EXP Buffer overflow in Kinesphere eXchange POP3 allows remote attackers to execute arbitrary code via a long MAIL FROM field. Patch early 7.5 high 6.5% 2004-04-20
CVE-2008-7053 EXP LogMeIn Remote Access Utility ActiveX control (RACtrl.dll) allows remote attackers to cause a denial of service (crash) by setting the fgcolor and bgc… Patch early 9.3 high 6.5% 2009-08-24
CVE-2007-2585 EXP Stack-based buffer overflow in the Verify function in the BarCodeWiz ActiveX control 2.0 and 2.52 (BarcodeWiz.dll) allows remote attackers to execute… Patch early 9.3 high 6.5% 2007-05-10
CVE-2014-8770 EXP Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a and earlier for Magento Communit… Patch early 9.0 high 6.5% 2014-11-13
CVE-2017-7005 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. Th… Patch early 8.8 high 6.5% 2018-04-03
CVE-2013-5673 EXP SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attackers to execute arbitrary SQL c… Patch early 7.5 high 6.5% 2013-09-10
CVE-2006-4828 EXP PHP remote file inclusion vulnerability in zipndownload.php in PhotoPost 4.0 through 4.6 allows remote attackers to execute arbitrary PHP code via a U… Patch early 7.5 high 6.5% 2006-09-15
CVE-2009-4186 EXP Stack consumption vulnerability in Apple Safari 4.0.3 on Windows allows remote attackers to cause a denial of service (application crash) via a long U… Patch early 9.3 high 6.5% 2009-12-03
CVE-2001-1009 EXP Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibl… Patch early 10.0 high 6.5% 2001-08-31
CVE-2008-6763 EXP login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged… Patch early 7.5 high 6.5% 2009-04-28
CVE-2006-3355 EXP Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not pro… Patch early 7.5 high 6.5% 2006-07-06
CVE-2018-8718 EXP Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mai… Patch early 8.0 high 6.5% 2018-03-27
CVE-2008-3320 EXP admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbit… Patch early 7.5 high 6.5% 2008-07-25
CVE-2013-7136 EXP The UPC Ireland Cisco EPC 2425 router (aka Horizon Box) does not have a sufficiently large number of possible WPA-PSK passphrases, which makes it easi… Patch early 9.3 high 6.5% 2013-12-19
CVE-2006-0586 EXP Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arbitrary SQL commands via multip… Patch early 7.5 high 6.5% 2006-02-08
CVE-2009-2015 EXP Directory traversal vulnerability in includes/file_includer.php in the Ideal MooFAQ (com_moofaq) component 1.0 for Joomla! allows remote attackers to… Patch early 7.5 high 6.5% 2009-06-09
CVE-2006-5758 EXP The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memo… Patch early 7.2 high 6.5% 2006-11-06
CVE-2007-1251 EXP Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0, when EVENTLOG is enabled, allows remote… Patch early 9.3 high 6.5% 2007-03-03
CVE-2006-0304 EXP Buffer overflow in Dual DHCP DNS Server 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary co… Patch early 7.5 high 6.5% 2006-01-19
CVE-2002-1001 EXP Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long… Patch early 7.5 high 6.5% 2002-10-04
CVE-2002-0206 EXP index.php in Francisco Burzi PHP-Nuke 5.3.1 and earlier, and possibly other versions before 5.5, allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 6.5% 2002-05-16
CVE-2016-10079 EXP SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP port 515. Patch early 7.5 high 6.5% 2017-02-01
CVE-2012-6653 EXP Unspecified vulnerability in the All Video Gallery (all-video-gallery) plugin before 1.2.0 for WordPress has unspecified impact and attack vectors. Patch early 7.5 high 6.5% 2014-08-06
CVE-2018-10577 EXP An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10.… Patch early 8.8 high 6.5% 2018-05-02
CVE-2018-4386 EXP Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1… Patch early 8.8 high 6.5% 2019-04-03
CVE-2011-3336 EXP regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion. Patch early 7.5 high 6.5% 2020-02-12
CVE-2004-2677 EXP Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format… Patch early 7.5 high 6.5% 2004-12-31
CVE-2011-5166 EXP Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string to the (1) USER, (2) PASS, (3)… Patch early 7.5 high 6.5% 2012-09-15
CVE-2017-2476 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… Patch early 8.8 high 6.5% 2017-04-02
CVE-2015-0569 EXP Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka Wi-Fi) driver for the Linux ker… Patch early 7.8 high 6.5% 2016-05-09
← previous page 171 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt