peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,964 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-4442 EXP A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, S… Patch early 8.8 high 5.8% 2019-04-03
CVE-2018-4443 EXP A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, S… Patch early 8.8 high 5.8% 2019-04-03
CVE-2004-1793 EXP Stack-based buffer overflow in swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote authenticated users to execute arbitrary code via a long m… Patch early 7.5 high 5.8% 2004-12-31
CVE-2007-1501 EXP Stack-based buffer overflow in Avant Browser 11.0 build 26 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary… Patch early 9.3 high 5.8% 2007-03-19
CVE-2009-1660 EXP Stack-based buffer overflow in URUWorks ViPlay3 3.0 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbi… Patch early 9.3 high 5.8% 2009-05-18
CVE-2000-1174 EXP Multiple buffer overflows in AFS ACL parser for Ethereal 0.8.13 and earlier allows remote attackers to execute arbitrary commands via a packet with a… Patch early 7.5 high 5.8% 2001-01-09
CVE-2005-2639 EXP Buffer overflow in Chris Moneymaker's World Poker Championship 1.0 allows remote attackers to cause a denial of service (application crash) and possib… Patch early 7.5 high 5.8% 2005-08-23
CVE-2005-3485 EXP Buffer overflow in Glider Collect'n kill 1.0.0.0 allows remote attackers to execute arbitrary code via a gl_playerEnter command with a long player nam… Patch early 7.5 high 5.8% 2005-11-03
CVE-2010-2315 EXP PHP remote file inclusion vulnerability in picturelib.php in SmartISoft phpBazar 2.1.1 allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 5.8% 2010-06-17
CVE-2017-13783 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 5.8% 2017-11-13
CVE-2017-13791 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 5.8% 2017-11-13
CVE-2017-13796 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 5.8% 2017-11-13
CVE-2008-6447 EXP Buffer overflow in emmailstore.dll 6.5.0.3 in the QuikSoft EasyMail MailStore ActiveX control allows remote attackers to execute arbitrary code via a… Patch early 9.3 high 5.8% 2009-03-09
CVE-2009-1643 EXP Stack-based buffer overflow in Sorinara Soritong MP3 Player 1.0 allows remote attackers to execute arbitrary code via a crafted .m3u file. Patch early 9.3 high 5.8% 2009-05-15
CVE-2009-1644 EXP Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via a crafted .pla file. Patch early 9.3 high 5.8% 2009-05-15
CVE-2010-2439 EXP Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list (.maf file). Patch early 9.3 high 5.8% 2010-06-24
CVE-2015-3673 EXP Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allows local users to obtain root p… Patch early 7.2 high 5.8% 2015-07-03
CVE-2009-3221 EXP Stack-based buffer overflow in Audio Lib Player (ALP) allows remote attackers to execute arbitrary code via a long URL in a .m3u playlist file. Patch early 9.3 high 5.8% 2009-09-16
CVE-2006-6261 EXP Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbit… Patch early 9.3 high 5.8% 2006-12-04
CVE-2010-3125 EXP Untrusted search path vulnerability in TeamMate Audit Management Software Suite 8.0 patch 2 allows local users, and possibly remote attackers, to exec… Patch early 9.3 high 5.8% 2010-08-26
CVE-2020-5509 EXP PHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile image. Patch early 7.2 high 5.8% 2020-01-14
CVE-2007-6402 EXP Stack-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote attackers… Patch early 9.3 high 5.8% 2007-12-17
CVE-2014-5083 EXP A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a remote mali… Patch early 8.8 high 5.8% 2020-02-10
CVE-2014-5085 EXP A Command Execution vulnerability exists in Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote maliciou… Patch early 8.8 high 5.8% 2020-02-10
CVE-2003-0380 EXP Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of service (crash)… Patch early 7.5 high 5.8% 2003-07-02
CVE-2008-1920 EXP Heap-based buffer overflow in the boxelyRenderer module in the Personal Status Manager feature in ICQ 6.0 build 6043 allows remote attackers to cause… Patch early 7.5 high 5.8% 2008-04-23
CVE-2007-2820 EXP Multiple stack-based buffer overflows in the KSign KSignSWAT ActiveX Control (AxKSignSWAT.dll) 2.0.3.3 allow remote attackers to execute arbitrary cod… Patch early 7.5 high 5.8% 2007-05-22
CVE-2002-0900 EXP Buffer overflow in pks PGP public key web server before 0.9.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitr… Patch early 7.5 high 5.8% 2002-10-04
CVE-2007-1141 EXP PHP remote file inclusion vulnerability in preview.php in Magic News Plus 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 5.8% 2007-03-02
CVE-2000-0166 EXP Buffer overflow in the InterAccess telnet server TelnetD allows remote attackers to execute commands via a long login name. Patch early 10.0 high 5.8% 2000-02-21
← previous page 181 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt