peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,893 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-5740 EXP The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code… Patch early 7.5 high 12.4% 2007-10-31
CVE-2013-3690 EXP Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and pos… Patch early 6.8 medium 12.4% 2013-10-01
CVE-2009-1209 EXP Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script tag with a long defer attribu… Patch early 9.3 high 12.4% 2009-04-01
CVE-2007-0017 EXP Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and t… Patch early 6.8 medium 12.4% 2007-01-03
CVE-2018-5319 EXP RAVPower FileHub 2.000.056 allows remote users to steal sensitive information via a crafted HTTP request. Patch early 7.5 high 12.4% 2018-01-24
CVE-2004-1675 EXP Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DO… Patch early 5.0 medium 12.4% 2004-09-11
CVE-2016-4314 EXP Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary fil… Patch early 4.9 medium 12.4% 2017-02-17
CVE-2006-1834 EXP Integer signedness error in Opera before 8.54 allows remote attackers to execute arbitrary code via long values in a stylesheet attribute, which pass… Patch early 5.1 medium 12.4% 2006-04-19
CVE-2005-1787 EXP setup.php in phpStat 1.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the $check variable. Patch early 7.5 high 12.3% 2005-05-27
CVE-2016-10401 EXP ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account passwor… Patch early 8.8 high 12.3% 2017-07-25
CVE-2007-3148 EXP Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute ar… Patch early 9.3 high 12.3% 2007-06-11
CVE-2020-10386 EXP admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by uploading a .php fil… Patch early 7.2 high 12.3% 2020-03-12
CVE-2017-1002003 EXP Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://… Patch early 9.8 critical 12.3% 2017-09-14
CVE-1999-0066 EXP AnyForm CGI remote execution. Patch early 9.8 critical 12.3% 1995-07-31
CVE-2013-4975 EXP Hikvision DS-2CD7153-E IP Camera has Privilege Escalation Patch early 8.8 high 12.3% 2019-12-27
CVE-2010-0437 EXP The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving a… Patch early 7.8 high 12.3% 2010-03-24
CVE-2018-15767 EXP The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerability caused by a misconfigura… Patch early 8.8 high 12.3% 2018-11-30
CVE-2023-22629 EXP An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the newPath parameter. An authenti… Patch early 8.8 high 12.3% 2023-02-14
CVE-2019-15029 EXP FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will ins… Patch early 8.8 high 12.3% 2019-09-05
CVE-2018-4192 EXP An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affe… Patch early 7.5 high 12.3% 2018-06-08
CVE-2018-7264 EXP The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign error… Patch early 9.8 critical 12.3% 2018-02-28
CVE-2016-6599 EXP BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service co… Patch early 9.8 critical 12.3% 2018-01-30
CVE-2007-6533 EXP Buffer overflow in Zoom Player 6.00 beta 2 and earlier allows user-assisted remote attackers to execute arbitrary code via an HTTP link to a PLS file… Patch early 7.5 high 12.3% 2007-12-27
CVE-2016-6174 EXP applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) befo… Patch early 8.1 high 12.3% 2016-07-12
CVE-2008-6172 EXP Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!, when magic_quotes_gpc is dis… Patch early 6.8 medium 12.3% 2009-02-19
CVE-2003-0478 EXP Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0… Patch early 10.0 high 12.3% 2003-08-07
CVE-2007-3655 EXP Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and earlier, allows remote attacker… Patch early 6.8 medium 12.3% 2007-07-10
CVE-2001-0025 EXP ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter. Patch early 10.0 high 12.3% 2001-02-12
CVE-2009-0192 EXP Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute… Patch early 5.0 medium 12.3% 2009-07-14
CVE-1999-0025 EXP root privileges via buffer overflow in df command on SGI IRIX systems. Patch early 7.2 high 12.3% 1997-07-16
← previous page 189 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt