peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,964 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2000-0425 EXP Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands. Patch early 10.0 high 5.8% 2000-05-03
CVE-2021-3394 EXP Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder permissions allowing a malicious… Patch early 8.8 high 5.8% 2021-02-09
CVE-2005-1413 EXP Multiple SQL injection vulnerabilities in enVivo!CMS allow remote attackers to execute arbitrary SQL commands and gain privileges via the (1) username… Patch early 7.5 high 5.8% 2005-05-03
CVE-2013-5692 EXP Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files… Patch early 8.5 high 5.8% 2013-09-30
CVE-2008-6897 EXP Multiple buffer overflows in Getleft.exe in Andres Garcia Getleft 1.2 allow remote attackers to cause a denial of service (crash) and possibly execute… Patch early 9.3 high 5.8% 2009-08-05
CVE-2009-3338 EXP Stack-based buffer overflow in EffectMatrix (E.M.) Magic Morph 1.95b allows remote attackers to execute arbitrary code via a long string in a .mor fil… Patch early 9.3 high 5.8% 2009-09-24
CVE-2009-3670 EXP Stack-based buffer overflow in KSP Sound Player 2009 R2 and R2.1 allows remote attackers to execute arbitrary code via a long string in a .m3u playlis… Patch early 9.3 high 5.8% 2009-10-11
CVE-2009-4964 EXP Stack-based buffer overflow in KSP 2006 FINAL allows remote attackers to execute arbitrary code via a long string in a .M3U playlist file. Patch early 9.3 high 5.8% 2010-07-28
CVE-2017-13784 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 5.8% 2017-11-13
CVE-2017-13785 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 5.8% 2017-11-13
CVE-2017-13792 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 5.8% 2017-11-13
CVE-2017-13795 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 5.8% 2017-11-13
CVE-2017-13802 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 5.8% 2017-11-13
CVE-2005-3558 EXP PHP file inclusion vulnerability in index.php in OSTE 1.0 allows remote attackers to execute arbitrary code via the (1) page and (2) site parameters. Patch early 7.5 high 5.8% 2005-11-16
CVE-2008-6983 EXP modules/tool/hitcounter.php in devalcms 1.4a allows remote attackers to execute arbitrary PHP code via the HTTP Referer header with a target file spec… Patch early 7.5 high 5.8% 2009-08-19
CVE-2008-0148 EXP TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a… Patch early 10.0 high 5.8% 2008-01-09
CVE-2008-4321 EXP Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long response to the PWD command. Patch early 9.3 high 5.8% 2008-09-29
CVE-2003-1142 EXP Help in NIPrint LPD-LPR Print Server 4.10 and earlier executes Windows Explorer with SYSTEM privileges, which allows local users to gain privileges. Patch early 10.0 high 5.8% 2003-11-03
CVE-2016-1828 EXP The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a… Patch early 7.8 high 5.8% 2016-05-20
CVE-2021-28142 EXP CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete." Patch early 8.8 high 5.8% 2021-04-06
CVE-2017-17738 EXP The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools.html. Patch early 7.5 high 5.8% 2017-12-18
CVE-2008-7079 EXP Buffer overflow in Nero ShowTime 5.0.15.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long… Patch early 9.3 high 5.8% 2009-08-25
CVE-2009-1040 EXP Buffer overflow in WinAsm Studio 5.1.5.0 allows user-assisted remote attackers to execute arbitrary code via a crafted project (.wap) file. Patch early 9.3 high 5.8% 2009-03-20
CVE-2009-3811 EXP Stack-based buffer overflow in Music Tag Editor 1.61 build 212 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag.… Patch early 9.3 high 5.8% 2009-10-27
CVE-2009-4097 EXP Stack-based buffer overflow in the MplayInputFile function in Serenity Audio Player 3.2.3 and earlier allows remote attackers to execute arbitrary cod… Patch early 9.3 high 5.8% 2009-11-29
CVE-2009-4863 EXP Stack-based buffer overflow in UltraPlayer Media Player 2.112 allows remote attackers to execute arbitrary code via a long string in a .usk file. Patch early 9.3 high 5.8% 2010-05-11
CVE-2010-2311 EXP Stack-based buffer overflow in Power Tab Editor 1.7 build 80 allows user-assisted remote attackers to execute arbitrary code via a .ptb file with a lo… Patch early 9.3 high 5.8% 2010-06-16
CVE-2007-2062 EXP Stack-based buffer overflow in VCDGear 3.55 and 3.56 BETA allows user-assisted remote attackers to execute arbitrary code via a long FILE argument in… Patch early 9.3 high 5.8% 2007-04-18
CVE-2007-5487 EXP Stack-based buffer overflow in COWON America jetAudio Basic 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a long URL in an… Patch early 9.3 high 5.8% 2007-10-16
CVE-2008-1973 EXP Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (crash) or execute arbitrary cod… Patch early 9.3 high 5.8% 2008-04-27
← previous page 182 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt