peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,941 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-3859 EXP Buffer overflow in eEye Retina WiFi Scanner 1.0.8.68, as used in Retina Network Security Scanner 5.10.14, allows user-assisted remote attackers to cau… Patch early 9.3 high 11.6% 2009-11-04
CVE-2002-0591 EXP Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute co… Patch early 5.0 medium 11.6% 2002-06-18
CVE-2009-1574 EXP racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a… Patch early 5.0 medium 11.6% 2009-05-06
CVE-2016-6566 EXP The valueAsString parameter inside the JSON payload contained by the ucLogin_txtLoginId_ClientStat POST parameter of the Sungard eTRAKiT3 software ver… Patch early 9.8 critical 11.6% 2018-07-13
CVE-2008-4116 EXP Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbit… Patch early 9.3 high 11.6% 2008-09-18
CVE-2019-19731 EXP Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE acti… Patch early 7.5 high 11.6% 2019-12-16
CVE-2003-0129 EXP Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that i… Patch early 5.0 medium 11.6% 2003-03-24
CVE-2011-4189 EXP The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corrup… Patch early 7.5 high 11.6% 2012-03-02
CVE-2019-8925 EXP An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerability in the Administration zon… Patch early 4.3 medium 11.6% 2019-05-17
CVE-1999-0710 EXP The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attacker… Patch early 7.5 high 11.6% 1999-07-25
CVE-2002-1456 EXP Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value. Patch early 7.5 high 11.6% 2003-06-09
CVE-2004-1147 EXP phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands vi… Patch early 10.0 high 11.6% 2005-01-10
CVE-2007-2209 EXP Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.20 and possibly other products… Patch early 6.8 medium 11.6% 2007-04-24
CVE-2007-0233 EXP wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matchi… Patch early 7.5 high 11.6% 2007-01-13
CVE-2014-9014 EXP Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allo… Patch early 4.3 medium 11.6% 2019-11-06
CVE-2022-22833 EXP An issue was discovered in Servisnet Tessa 0.0.2. An attacker can obtain sensitive information via a /js/app.js request. Patch early 7.5 high 11.6% 2022-02-06
CVE-2015-4181 EXP Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 7.5 high 11.6% 2017-08-25
CVE-2018-18957 EXP An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_publisher.c. Patch early 9.8 critical 11.6% 2018-11-05
CVE-2012-1125 EXP Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 for WordPress allows remote atta… Patch early 6.8 medium 11.6% 2012-10-08
CVE-2008-7257 EXP CRLF injection vulnerability in +webvpn+/index.html in WebVPN on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1… Patch early 4.3 medium 11.6% 2010-06-29
CVE-2003-0263 EXP Multiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitrary code via long (1) MAIL FRO… Patch early 7.5 high 11.6% 2003-05-27
CVE-2016-9683 EXP The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative i… Patch early 9.8 critical 11.6% 2017-02-22
CVE-2013-7186 EXP Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long string in a .m3u file. Patch early 9.3 high 11.6% 2013-12-20
CVE-2013-2261 EXP Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure Patch early 7.5 high 11.6% 2019-11-04
CVE-2007-4254 EXP Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Designer 7.0 for Microsoft Visual St… Patch early 6.8 medium 11.5% 2007-08-08
CVE-2018-10517 EXP In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploit… Patch early 7.2 high 11.5% 2018-04-27
CVE-2008-0944 EXP Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote attackers to cause a denial of service (NULL dereference and application crash) via… Patch early 5.0 medium 11.5% 2008-02-25
CVE-2018-5724 EXP MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore.cgi. Patch early 9.8 critical 11.5% 2018-01-16
CVE-2019-10709 EXP AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP device, leading to a DoS or potenti… Patch early 9.8 critical 11.5% 2019-09-04
CVE-2019-6273 EXP download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files. Patch early 6.5 medium 11.5% 2019-03-21
← previous page 196 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt