peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,585 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-3491 EXP Multiple buffer overflows in the receiver function in loop.c in FlatFrag 0.3 and earlier allow remote attackers to execute arbitrary code via the (1)… Patch early 7.5 high 4.9% 2005-11-04
CVE-2006-7156 EXP PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a module for miniBB, allows remo… Patch early 10.0 high 4.9% 2007-03-07
CVE-2018-4206 EXP An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2018-001 is affected. tvOS befo… Patch early 7.8 high 4.9% 2018-06-08
CVE-2006-6396 EXP Stack-based buffer overflow in BlazeVideo HDTV Player 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via a long filename… Patch early 7.5 high 4.9% 2006-12-08
CVE-2013-3574 EXP Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote attackers… Patch early 7.8 high 4.9% 2013-06-14
CVE-2019-1089 EXP An elevation of privilege vulnerability exists in rpcss.dll when the RPC service Activation Kernel improperly handles an RPC request. To exploit this… Patch early 7.8 high 4.9% 2019-07-15
CVE-2012-5864 EXP These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. By directly visiting the pages within th… Patch early 9.4 high 4.9% 2012-11-23
CVE-2009-1674 EXP Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathname in a… Patch early 9.3 high 4.9% 2009-05-18
CVE-2009-3253 EXP Stack-based buffer overflow in TriceraSoft Swift Ultralite 1.032 allows remote attackers to cause a denial of service (crash) or execute arbitrary cod… Patch early 9.3 high 4.9% 2009-09-18
CVE-2007-5450 EXP Unspecified vulnerability in Safari on the Apple iPod touch (aka iTouch) and iPhone 1.1.1 allows user-assisted remote attackers to cause a denial of s… Patch early 9.3 high 4.9% 2007-10-14
CVE-2013-5578 EXP Buffer overflow in the ToDot method in the WINGRAPHVIZLib.NEATO ActiveX control in WinGraphviz.dll in StarUML allows remote attackers to execute arbit… Patch early 9.3 high 4.9% 2013-08-25
CVE-2023-31874 EXP Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_process'). Patch early 8.8 high 4.9% 2023-05-29
CVE-2005-4287 EXP PHP remote file include vulnerability in MarmaraWeb E-commerce allows remote attackers to execute arbitrary code via the page parameter to index.php. Patch early 7.5 high 4.9% 2005-12-16
CVE-1999-0822 EXP Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command. Patch early 10.0 high 4.9% 1999-11-30
CVE-2008-1244 EXP cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows remote attackers to perform a… Patch early 10.0 high 4.9% 2008-03-10
CVE-2008-7074 EXP Format string vulnerability in MemeCode Software i.Scribe 1.88 through 2.00 before Beta9 allows remote SMTP servers to cause a denial of service (cras… Patch early 9.3 high 4.9% 2009-08-25
CVE-2005-2305 EXP DG Remote Control Server 1.6.2 allows remote attackers to cause a denial of service (crash or CPU consumption) and possibly execute arbitrary code via… Patch early 7.5 high 4.9% 2005-07-19
CVE-2006-0072 EXP Buffer overflow in termsh on SCO OpenServer 5.0.7 allows remote attackers to execute arbitrary code via a long -o command line argument. NOTE: this i… Patch early 7.5 high 4.9% 2006-01-04
CVE-2009-3547 EXP Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference a… Patch early 7.0 high 4.9% 2009-11-04
CVE-2016-9566 EXP base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink atta… Patch early 7.8 high 4.9% 2016-12-15
CVE-2020-8819 EXP An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in the IPN callback processing f… Patch early 8.1 high 4.9% 2020-02-25
CVE-2000-0295 EXP Buffer overflow in LCDproc allows remote attackers to gain root privileges via the screen_add command. Patch early 10.0 high 4.9% 2000-04-21
CVE-2009-3213 EXP Stack-based buffer overflow in broid 1.0 Beta 3a allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrar… Patch early 9.3 high 4.9% 2009-09-16
CVE-2015-3314 EXP SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5. Patch early 8.1 high 4.9% 2017-09-07
CVE-1999-1531 EXP Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SR… Patch early 7.5 high 4.9% 1999-11-02
CVE-2008-0986 EXP Integer overflow in the BMP::readFromStream method in the libsgl.so library in Google Android SDK m3-rc37a and earlier, and m5-rc14, allows remote att… Patch early 7.5 high 4.9% 2008-03-06
CVE-2010-2099 EXP bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows rem… Patch early 7.5 high 4.9% 2010-05-27
CVE-2016-1247 EXP The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04… Patch early 7.8 high 4.9% 2016-11-29
CVE-2007-1393 EXP PHP remote file inclusion vulnerability in mysave.php in Magic CMS 4.2.747 allows remote attackers to execute arbitrary PHP code via a URL in the file… Patch early 10.0 high 4.9% 2007-03-10
CVE-2007-1787 EXP Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier, when register_globals is ena… Patch early 9.3 high 4.9% 2007-03-31
← previous page 195 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt