peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,590 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-6230 EXP Directory traversal vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote attackers to include and execute arb… Patch early 7.5 high 6.3% 2007-12-04
CVE-2016-3220 EXP atmfd.dll in the Adobe Type Manager Font Driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window… Patch early 7.8 high 6.3% 2016-06-16
CVE-2017-13798 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 6.3% 2017-11-13
CVE-2008-3299 EXP eSyndiCat 1.6 allows remote attackers to bypass authentication and gain administrative access by setting the admin_lng cookie value to 1. NOTE: the pr… Patch early 7.5 high 6.3% 2008-07-25
CVE-2014-4034 EXP SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the article_id param… Patch early 7.5 high 6.3% 2014-06-11
CVE-2015-7986 EXP The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a denial of service (memory corrupti… Patch early 7.5 high 6.2% 2015-10-27
CVE-2000-0490 EXP Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN request. Patch early 10.0 high 6.2% 2000-06-01
CVE-2008-3166 EXP PHP remote file inclusion vulnerability in modules/global/inc/content.inc.php in BoonEx Ray 3.5, when register_globals is enabled, allows remote attac… Patch early 9.3 high 6.2% 2008-07-14
CVE-2012-4250 EXP Stack-based buffer overflow in the RequestScreenOptimization function in the XProcessControl.ocx ActiveX control in msls31.dll in Samsung NET-i viewer… Patch early 9.3 high 6.2% 2012-08-13
CVE-2003-1140 EXP Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the configuration file. Patch early 10.0 high 6.2% 2003-10-27
CVE-2023-4278 EXP The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to regist… Patch early 7.5 high 6.2% 2023-09-11
CVE-2014-4968 EXP The WebView class and use of the WebView.addJavascriptInterface method in the Boat Browser application 8.0 and 8.0.1 for Android allow remote attacker… Patch early 8.8 high 6.2% 2020-02-12
CVE-2023-28288 EXP Microsoft SharePoint Server Spoofing Vulnerability Patch early 8.1 high 6.2% 2023-04-11
CVE-2018-0952 EXP An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hu… Patch early 7.8 high 6.2% 2018-08-15
CVE-2009-3969 EXP Stack-based buffer overflow in Faslo Player 7.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… Patch early 9.3 high 6.2% 2009-11-18
CVE-1999-0997 EXP wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program… Patch early 7.5 high 6.2% 1999-12-20
CVE-2003-1313 EXP Multiple PHP remote file inclusion vulnerabilities in EternalMart Mailing List Manager (EMLM) 1.32 allow remote attackers to execute arbitrary PHP cod… Patch early 7.5 high 6.2% 2003-12-31
CVE-2007-0504 EXP Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to execute arbitrary code via the… Patch early 10.0 high 6.2% 2007-01-26
CVE-1999-0210 EXP Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters. Patch early 10.0 high 6.2% 1997-11-26
CVE-2007-2568 EXP Multiple stack-based buffer overflows in VCDGear 3.55 allow user-assisted remote attackers to execute arbitrary code via a long (1) tag or (2) track t… Patch early 9.3 high 6.2% 2007-05-16
CVE-2017-7049 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 8.8 high 6.2% 2017-07-20
CVE-2015-2824 EXP Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL co… Patch early 7.5 high 6.2% 2015-04-06
CVE-2009-3838 EXP Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash)… Patch early 9.3 high 6.2% 2009-11-02
CVE-2020-20969 EXP File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file. Patch early 7.2 high 6.2% 2023-06-20
CVE-2004-1303 EXP Buffer overflow in the get function in get.c for Yanf 0.4 allows remote malicious web servers to execute arbitrary code via crafted HTTP responses. Patch early 10.0 high 6.2% 2005-01-10
CVE-2009-0422 EXP Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is disabled, allows remote attackers… Patch early 7.5 high 6.2% 2009-02-05
CVE-2007-6273 EXP Multiple format string vulnerabilities in the configuration file in SonicWALL GLobal VPN Client 3.1.556 and 4.0.0.810 allow user-assisted remote attac… Patch early 9.3 high 6.2% 2007-12-07
CVE-2002-0942 EXP Buffer overflows in Lugiment Log Explorer before 3.02 allow attackers with database permissions to execute arbitrary code via long arguments to the ex… Patch early 7.5 high 6.2% 2002-10-04
CVE-2007-0466 EXP Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 allows remote attackers to execute arbitrary code via a crafted ASF_File_Propertie… Patch early 10.0 high 6.2% 2007-01-31
CVE-2024-24409 EXP Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option. Patch early 8.8 high 6.2% 2024-11-08
← previous page 175 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt