peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,573 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2003-0755 EXP Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory names and list… Patch early 10.0 high 6.5% 2003-10-20
CVE-2002-0968 EXP Buffer overflow in AnalogX SimpleServer:WWW 1.16 and earlier allows remote attackers to cause a denial of service (crash) and execute code via a long… Patch early 7.5 high 6.5% 2002-10-04
CVE-2007-2791 EXP Unspecified vulnerability in the Secure Shell (SSH) in HP Tru64 UNIX 5.1B-4 and 5.1B-3 allows remote attackers to identify valid users via unspecified… Patch early 10.0 high 6.5% 2007-05-22
CVE-2008-3167 EXP Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbitr… Patch early 9.3 high 6.5% 2008-07-14
CVE-2006-4848 EXP Multiple PHP remote file inclusion vulnerabilities in Brian Fraval Hitweb 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the RE… Patch early 7.5 high 6.5% 2006-09-19
CVE-2009-3318 EXP Directory traversal vulnerability in the Roland Breedveld Album (com_album) component 1.14 for Joomla! allows remote attackers to access arbitrary dir… Patch early 7.5 high 6.5% 2009-09-23
CVE-2006-3015 EXP Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double… Patch early 7.1 high 6.5% 2006-06-14
CVE-2019-12137 EXP Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note. Patch early 7.8 high 6.5% 2019-05-16
CVE-2018-4366 EXP A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1. Patch early 7.5 high 6.4% 2019-04-03
CVE-2018-9106 EXP CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via… Patch early 8.8 high 6.4% 2018-03-28
CVE-2017-5227 EXP QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format… Patch early 7.5 high 6.4% 2017-03-23
CVE-2020-27423 EXP Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legiti… Patch early 7.5 high 6.4% 2020-11-16
CVE-2014-2921 EXP The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 does not properly handle an objec… Patch early 7.5 high 6.4% 2014-04-21
CVE-2009-4987 EXP admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative access by setting… Patch early 7.5 high 6.4% 2010-08-25
CVE-2011-4042 EXP An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute ar… Patch early 9.3 high 6.4% 2012-04-03
CVE-2009-3717 EXP Heap-based buffer overflow in LucVil PatPlayer 3.9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long U… Patch early 9.3 high 6.4% 2009-10-16
CVE-2007-2827 EXP Heap-based buffer overflow in LEAD Technologies LEADTOOLS ISIS ActiveX Control (ltisi14E.ocx) 14.5.0.44 and earlier allows remote attackers to execute… Patch early 9.3 high 6.4% 2007-05-22
CVE-2007-2981 EXP Buffer overflow in a certain ActiveX control in LEAD Technologies LEADTOOLS Raster OCR Document Object Library (ltrdc14e.dll) 14.5.0.44 allows remote… Patch early 9.3 high 6.4% 2007-06-01
CVE-2018-4089 EXP An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safari before 11.0.3 is affected.… Patch early 8.8 high 6.4% 2018-04-03
CVE-2000-0848 EXP Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header. Patch early 10.0 high 6.4% 2000-11-14
CVE-2018-13110 EXP All ADB broadband gateways / routers based on the Epicentro platform are affected by a privilege escalation vulnerability where attackers can gain acc… Patch early 7.5 high 6.4% 2018-07-06
CVE-2008-7161 EXP Fortinet FortiGuard Fortinet FortiGate-1000 3.00 build 040075,070111 allows remote attackers to bypass URL filtering via fragmented GET or POST reques… Patch early 7.5 high 6.4% 2009-09-04
CVE-2003-0371 EXP Buffer overflow in Prishtina FTP client 1.x allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a l… Patch early 7.5 high 6.4% 2003-06-16
CVE-2008-5281 EXP Heap-based buffer overflow in Titan FTP Server 6.05 build 550 allows remote attackers to execute arbitrary code via a long DELE command. Patch early 10.0 high 6.4% 2008-11-29
CVE-2008-5071 EXP Multiple eval injection vulnerabilities in itpm_estimate.php in Yoxel 1.23beta and earlier allow remote authenticated users to execute arbitrary PHP c… Patch early 9.0 high 6.4% 2008-11-14
CVE-2014-0997 EXP WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used in the Samsung SM-T310, Android… Patch early 7.5 high 6.4% 2017-09-26
CVE-2001-0198 EXP Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBE… Patch early 7.6 high 6.4% 2001-05-03
CVE-2006-4234 EXP PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP co… Patch early 7.5 high 6.4% 2006-08-18
CVE-2009-3586 EXP Off-by-one error in src/http.c in CoreHTTP 0.5.3.1 and earlier allows remote attackers to cause a denial of service or possibly execute arbitrary code… Patch early 7.5 high 6.4% 2009-12-08
CVE-2002-2219 EXP chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow file via a long user (userid) f… Patch early 7.5 high 6.4% 2002-12-31
← previous page 172 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt