peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,553 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-0002 EXP Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to exec… Patch early 7.5 high 5.3% 2002-01-31
CVE-2013-4695 EXP Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution Patch early 7.8 high 5.3% 2019-12-27
CVE-2020-10883 EXP This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. A… Patch early 7.8 high 5.3% 2020-03-25
CVE-2009-0351 EXP Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argument beginn… Patch early 9.0 high 5.3% 2009-01-29
CVE-2008-5073 EXP Heap-based buffer overflow in an ActiveX control in Novell ZENworks Desktop Management 6.5 allows remote attackers to execute arbitrary code via a lon… Patch early 9.3 high 5.3% 2008-11-14
CVE-2018-16083 EXP An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of… Patch early 8.8 high 5.3% 2019-01-09
CVE-2004-0648 EXP Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referen… Patch early 10.0 high 5.3% 2004-08-06
CVE-2017-13797 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 5.3% 2017-11-13
CVE-2008-4247 EXP ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple co… Patch early 7.5 high 5.3% 2008-09-25
CVE-2016-1767 EXP QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafte… Patch early 7.8 high 5.3% 2016-03-24
CVE-2016-1769 EXP QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafte… Patch early 7.8 high 5.3% 2016-03-24
CVE-2015-4614 EXP Multiple SQL injection vulnerabilities in includes/Function.php in the Easy2Map plugin before 1.2.5 for WordPress allow remote attackers to execute ar… Patch early 7.5 high 5.2% 2015-07-08
CVE-2003-1431 EXP Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via a long host string in th… Patch early 7.1 high 5.2% 2003-12-31
CVE-2006-0685 EXP The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allo… Patch early 10.0 high 5.2% 2006-02-15
CVE-2015-8664 EXP Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 47.0.2526.106 allows remote att… Patch early 8.8 high 5.2% 2015-12-24
CVE-2004-1466 EXP The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds after they have been uploaded… Patch early 7.5 high 5.2% 2004-12-31
CVE-2010-4879 EXP PHP remote file inclusion vulnerability in dompdf.php in dompdf 0.6.0 beta1 allows remote attackers to execute arbitrary PHP code via a URL in the inp… Patch early 7.5 high 5.2% 2011-10-07
CVE-2008-1866 EXP admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload… Patch early 9.0 high 5.2% 2008-04-17
CVE-2022-31325 EXP There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php. Patch early 7.2 high 5.2% 2022-06-08
CVE-1999-0765 EXP SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor. Patch early 10.0 high 5.2% 1999-05-19
CVE-2016-3962 EXP Stack-based buffer overflow in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME… Patch early 7.3 high 5.2% 2016-07-03
CVE-2017-6096 EXP A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/view-list.php (Requires auth… Patch early 7.2 high 5.2% 2017-02-21
CVE-2017-6097 EXP A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign/count_of_send.php (Requir… Patch early 7.2 high 5.2% 2017-02-21
CVE-2009-2361 EXP SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the st… Patch early 7.5 high 5.2% 2009-07-08
CVE-2019-19031 EXP Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS by consuming resources. The c… Patch early 8.1 high 5.2% 2019-12-30
CVE-2000-0741 EXP Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code vi… Patch early 7.5 high 5.2% 2000-10-20
CVE-2007-2821 EXP SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitrary SQL commands via the cooki… Patch early 7.5 high 5.2% 2007-05-22
CVE-2022-3141 EXP The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the sett… Patch early 8.8 high 5.2% 2022-09-19
CVE-2012-5879 EXP An ActiveX control in McHealthCheck.dll in McAfee Virtual Technician (MVT) and ePO-MVT 6.5.0.2101 and earlier allows remote attackers to modify or cre… Patch early 8.2 high 5.2% 2013-03-28
CVE-2008-0805 EXP Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitrary code by uploading a file w… Patch early 9.3 high 5.2% 2008-02-19
← previous page 190 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt