peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,585 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2001-0296 EXP Buffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command. Patch early 10.0 high 5% 2001-05-03
CVE-2003-0805 EXP Multiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x before 3.0.6 allows attackers to execute arbitrary code via (1) a long filename a… Patch early 7.5 high 5% 2003-10-06
CVE-2019-6498 EXP GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused. Patch early 8.8 high 5% 2019-01-21
CVE-2002-0276 EXP Buffer overflow in various decoders in Ettercap 0.6.3.1 and earlier, when running on networks with an MTU greater than 2000, allows remote attackers t… Patch early 7.5 high 5% 2002-05-31
CVE-2003-0835 EXP Multiple buffer overflows in asf_http_request of MPlayer before 0.92 allows remote attackers to execute arbitrary code via an ASX header with a long h… Patch early 7.5 high 5% 2003-11-17
CVE-2021-28242 EXP SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting… Patch early 8.8 high 5% 2021-04-15
CVE-2019-13623 EXP In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with an execut… Patch early 7.8 high 5% 2019-07-17
CVE-2005-0671 EXP Format string vulnerability in Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary code via form… Patch early 7.5 high 5% 2005-03-03
CVE-2017-0100 EXP A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Window… Patch early 7.8 high 5% 2017-03-17
CVE-2007-1024 EXP PHP remote file inclusion vulnerability in include.php in Meganoide's news 1.1.1 allows remote attackers to execute arbitrary PHP code via a URL in th… Patch early 10.0 high 5% 2007-02-21
CVE-2004-1619 EXP Buffer overflow in Privateer's Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickname. Patch early 7.5 high 5% 2004-10-20
CVE-2005-2844 EXP Buffer overflow in MMClient.exe in Indiatimes Messenger 6.0 allows remote attackers to cause a denial of service (application crash) and possibly exec… Patch early 7.5 high 5% 2005-09-08
CVE-2005-3992 EXP Multiple buffer overflows in WinEggDropShell remote access trojan (RAT) 1.7 allow remote attackers to execute arbitrary code via (1) a long GET reques… Patch early 7.5 high 5% 2005-12-04
CVE-2009-0820 EXP Multiple eval injection vulnerabilities in phpScheduleIt before 1.2.11 allow remote attackers to execute arbitrary code via (1) the end_date parameter… Patch early 7.5 high 4.9% 2009-03-05
CVE-2002-0329 EXP Cross-site scripting vulnerability in Snitz Forums 2000 3.3.03 and earlier allows remote attackers to execute arbitrary script as other Forums 2000 us… Patch early 7.5 high 4.9% 2002-06-25
CVE-2007-1416 EXP PHP remote file inclusion vulnerability in createurl.php in JCcorp (aka James Coyle) URLshrink allows remote attackers to execute arbitrary PHP code v… Patch early 10.0 high 4.9% 2007-03-12
CVE-2004-0249 EXP PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another userID. Patch early 10.0 high 4.9% 2004-11-23
CVE-2012-6625 EXP SQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allows remote attackers to ex… Patch early 7.5 high 4.9% 2014-01-16
CVE-2004-1835 EXP Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat… Patch early 7.5 high 4.9% 2004-12-31
CVE-2017-11469 EXP get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter. Patch early 7.5 high 4.9% 2017-07-20
CVE-2008-4873 EXP board.cgi in Sepal SPBOARD 4.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter during a down_file… Patch early 10.0 high 4.9% 2008-11-01
CVE-2017-9603 EXP SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid… Patch early 8.8 high 4.9% 2017-06-13
CVE-2007-3186 EXP Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, a… Patch early 9.3 high 4.9% 2007-06-12
CVE-2016-1813 EXP The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 all… Patch early 7.8 high 4.9% 2016-05-20
CVE-2016-1823 EXP The IOHIDDevice::handleReportWithTime function in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows atta… Patch early 7.8 high 4.9% 2016-05-20
CVE-2009-3307 EXP Multiple PHP remote file inclusion vulnerabilities in FSphp 0.2.1 allow remote attackers to execute arbitrary PHP code via a URL in the FSPHP_LIB para… Patch early 7.5 high 4.9% 2009-09-23
CVE-2008-0755 EXP Format string vulnerability in the ReportSysLogEvent function in the LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy… Patch early 7.5 high 4.9% 2008-02-13
CVE-2007-3612 EXP Stack-based buffer overflow in Visual IRC (ViRC) 2.0 allows remote IRC servers to execute arbitrary code via a long response to a JOIN command. Patch early 7.5 high 4.9% 2007-07-06
CVE-2004-1904 EXP Buffer overflow in ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to execute arbitrary code via the Internacional property followed by… Patch early 7.5 high 4.9% 2004-12-31
CVE-2005-0906 EXP Buffer overflow in a player logging function in the Tincat network library 2.x before 2.0.28, as used in games such as Sacred and The Settlers: Herita… Patch early 7.5 high 4.9% 2005-05-02
← previous page 194 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt