peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,590 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-0262 EXP Stack-based buffer overflow in Triologic Media Player 7 and 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string… Patch early 9.3 high 6.2% 2009-01-23
CVE-2018-10018 EXP The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a long IsBlackListed argument. Patch early 8.8 high 6.2% 2018-07-13
CVE-2006-7032 EXP PHP remote file inclusion vulnerability in phpbb/getmsg.php in FlashBB 1.1.5 and earlier allows remote attackers to execute arbitrary code via a URL i… Patch early 10.0 high 6.2% 2007-02-23
CVE-2009-2568 EXP Stack-based buffer overflow in Sorinara Streaming Audio Player (SAP) 0.9 allows remote attackers to execute arbitrary code via a long string in a play… Patch early 9.3 high 6.2% 2009-07-22
CVE-2022-47076 EXP An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via DisplayParallelLogData.aspx. Patch early 7.5 high 6.2% 2023-02-28
CVE-2009-1743 EXP Directory traversal vulnerability in InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows… Patch early 9.3 high 6.2% 2009-05-21
CVE-2000-0828 EXP Buffer overflow in ddicgi.exe in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long User-Agen… Patch early 10.0 high 6.2% 2000-11-14
CVE-1999-0287 EXP Vulnerability in the Wguest CGI program. Patch early 7.5 high 6.2% 1999-04-09
CVE-2004-1301 EXP Buffer overflow in the book_format_sql function in format.c for xlreader 0.9.0 allows remote attackers to execute arbitrary code via a crafted Excel (… Patch early 10.0 high 6.2% 2005-01-10
CVE-2006-3491 EXP Stack-based buffer overflow in Kaillera Server 0.86 and earlier allows remote attackers to execute arbitrary code via a long nickname. Patch early 7.5 high 6.2% 2006-07-10
CVE-2007-2474 EXP Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code… Patch early 7.5 high 6.2% 2007-05-02
CVE-2009-1368 EXP Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parame… Patch early 7.5 high 6.2% 2009-04-22
CVE-2004-0290 EXP Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that contains large (1… Patch early 10.0 high 6.1% 2004-11-23
CVE-2005-2367 EXP Format string vulnerability in the proto_item_set_text function in Ethereal 0.9.4 through 0.10.11, as used in multiple dissectors, allows remote attac… Patch early 7.5 high 6.1% 2005-08-10
CVE-2016-3219 EXP The kernel-mode driver in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of… Patch early 7.8 high 6.1% 2016-06-16
CVE-2018-7466 EXP install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES dat… Patch early 7.5 high 6.1% 2018-02-25
CVE-2007-3167 EXP Stack-based buffer overflow in the Vivotek Motion Jpeg ActiveX control (aka MjpegControl) in MjpegDecoder.dll 2.0.0.13 allows remote attackers to exec… Patch early 7.6 high 6.1% 2007-06-11
CVE-2007-2761 EXP Stack-based buffer overflow in MagicISO 5.4 build 239 and earlier allows remote attackers to execute arbitrary code via a long filename in a .cue file… Patch early 7.5 high 6.1% 2007-05-18
CVE-2008-6143 EXP OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account name in the username cookie. Patch early 7.5 high 6.1% 2009-02-16
CVE-2009-3306 EXP PHP remote file inclusion vulnerability in include/header.php in ClearSite 4.50 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 6.1% 2009-09-23
CVE-1999-0238 EXP php.cgi allows attackers to read any file on the system. Patch early 10.0 high 6.1% 1997-08-01
CVE-2009-1610 EXP admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator password and gain administrator priv… Patch early 7.5 high 6.1% 2009-05-11
CVE-2009-0457 EXP Multiple directory traversal vulnerabilities in AJA Portal 1.2 allow remote attackers to include and execute arbitrary local files via directory trave… Patch early 7.5 high 6.1% 2009-02-10
CVE-2002-0855 EXP Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscript… Patch early 7.5 high 6.1% 2002-09-05
CVE-2000-1046 EXP Multiple buffer overflows in the ESMTP service of Lotus Domino 5.0.2c and earlier allow remote attackers to cause a denial of service and possibly exe… Patch early 10.0 high 6.1% 2000-12-11
CVE-2009-2363 EXP Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls playlist file with a playlist… Patch early 9.3 high 6.1% 2009-07-08
CVE-2009-1652 EXP admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and add… Patch early 7.5 high 6.1% 2009-05-16
CVE-2006-7068 EXP PHP remote file inclusion vulnerability in CliServ Web Community 0.65 and earlier allows remote attackers to execute arbitrary PHP code via a URL in t… Patch early 7.5 high 6.1% 2007-03-02
CVE-2001-0029 EXP Buffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrary commands via a long host or… Patch early 10.0 high 6.1% 2001-02-12
CVE-2018-6221 EXP An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle attacker to tamper with an up… Patch early 8.1 high 6.1% 2018-03-15
← previous page 176 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt