peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,085 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-2420 EXP flsearch.pl in FtpLocate 2.02 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP GET request. Patch early 10.0 high 5.6% 2005-08-03
CVE-2008-3207 EXP PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabled, allows remote attackers to… Patch early 9.3 high 5.6% 2008-07-18
CVE-2009-4761 EXP Stack-based buffer overflow in Mini-stream RM Downloader allows remote attackers to execute arbitrary code via a long string in a .smi file. Patch early 9.3 high 5.6% 2010-03-29
CVE-2010-2348 EXP Stack-based buffer overflow in Batch Audio Converter Lite Edition 1.0.0.0 and earlier allows remote attackers to execute arbitrary code via a long lin… Patch early 9.3 high 5.6% 2010-06-21
CVE-2007-1037 EXP Stack-based buffer overflow in News File Grabber 4.1.0.1 and earlier allows remote attackers to execute arbitrary code via a .nzb file with a long sub… Patch early 9.3 high 5.6% 2007-02-21
CVE-2010-5096 EXP Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the key… Patch early 7.5 high 5.6% 2012-08-13
CVE-1999-0360 EXP MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotel… Patch early 7.2 high 5.6% 1999-01-30
CVE-2000-0971 EXP Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO" or "MAIL FROM… Patch early 10.0 high 5.6% 2000-12-19
CVE-2015-2679 EXP Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) page p… Patch early 7.5 high 5.6% 2015-03-23
CVE-2001-0471 EXP SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise a… Patch early 7.5 high 5.6% 2001-06-27
CVE-2014-6235 EXP Unspecified vulnerability in the ke DomPDF extension before 0.0.5 for TYPO3 allows remote attackers to execute arbitrary code via unknown vectors. Patch early 7.5 high 5.6% 2014-09-11
CVE-2008-5839 EXP Buffer overflow in Foxmail 6.5 allows remote attackers to execute arbitrary code via a long mailto URI in the HREF attribute of an A element. Patch early 9.3 high 5.6% 2009-01-05
CVE-2008-3300 EXP AlphAdmin CMS 1.0.5/03 allows remote attackers to bypass authentication and gain administrative access by setting the aa_login cookie value to 1. NOT… Patch early 7.5 high 5.6% 2008-07-25
CVE-2017-11319 EXP Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and consequently gain privileges by… Patch early 8.8 high 5.6% 2017-12-11
CVE-2000-0670 EXP The cvsweb CGI script in CVSWeb 1.80 allows remote attackers with write access to a CVS repository to execute arbitrary commands via shell metacharact… Patch early 7.2 high 5.6% 2000-07-12
CVE-2012-6307 EXP A vulnerability exists in JPEGsnoop 1.5.2 due to an unspecified issue in JPEG file handling, which could let a malicious user execute arbitrary code Patch early 8.8 high 5.6% 2020-02-06
CVE-2010-4230 EXP Stack-based buffer overflow in a certain ActiveX control for the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmw… Patch early 9.3 high 5.6% 2010-11-17
CVE-2009-0175 EXP Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (application crash) and possibl… Patch early 9.3 high 5.6% 2009-01-20
CVE-2009-1351 EXP Heap-based buffer overflow in Apollo 37zz allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code… Patch early 9.3 high 5.6% 2009-04-21
CVE-2009-1352 EXP Stack-based buffer overflow in Dawningsoft PowerCHM 5.7 allows remote attackers to cause a denial of service (application crash) and possibly execute… Patch early 9.3 high 5.6% 2009-04-21
CVE-2009-1817 EXP Multiple buffer overflows in DigiMode Maya 1.0.2 allow remote attackers to execute arbitrary code via a long string in a malformed (1) .m3u or (2) .m3… Patch early 9.3 high 5.6% 2009-05-29
CVE-2009-4758 EXP Stack-based buffer overflow in dicas Mpegable Player 2.12 allows remote attackers to cause a denial of service (application crash) or possibly execute… Patch early 9.3 high 5.6% 2010-03-29
CVE-2007-6654 EXP Buffer overflow in a certain ActiveX control in Macrovision InstallShield Update Service Web Agent 5.1.100.47363 allows remote attackers to execute ar… Patch early 9.3 high 5.6% 2008-01-04
CVE-2008-3430 EXP Buffer overflow in the CoVideoWindow.ocx ActiveX control 5.0.907.1 in Eyeball MessengerSDK, as used in products such as SiOL Komunikator 1.3, allows r… Patch early 9.3 high 5.6% 2008-07-31
CVE-2008-4750 EXP Stack-based buffer overflow in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allows remote at… Patch early 9.3 high 5.6% 2008-10-27
CVE-2008-3116 EXP Format string vulnerability in dx8render.dll in Snail Game (aka Suzhou Snail Electronic Company) 5th street (aka Hot Step or High Street 5) allows rem… Patch early 10.0 high 5.6% 2008-07-10
CVE-2008-0491 EXP SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via th… Patch early 7.5 high 5.5% 2008-01-30
CVE-2000-0057 EXP Cold Fusion CFCACHE tag places temporary cache files within the web document root, allowing remote attackers to obtain sensitive system information. Patch early 7.5 high 5.5% 2000-01-04
CVE-2000-0125 EXP wwwthreads does not properly cleanse numeric data or table names that are passed to SQL queries, which allows remote attackers to gain privileges for… Patch early 7.5 high 5.5% 2000-02-03
CVE-2000-0916 EXP FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (I… Patch early 7.5 high 5.5% 2000-12-19
← previous page 186 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt