peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,585 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-1044 EXP Stack-based buffer overflow in the Quantum Streaming Player (Quantum Streaming IE Player) ActiveX control (aka QSP2IE.QSP2IE) in qsp2ie07076007.dll 7.… Patch early 7.5 high 4.8% 2008-02-27
CVE-2016-1846 EXP The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary… Patch early 7.8 high 4.8% 2016-05-20
CVE-2007-0683 EXP PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 4.8% 2007-02-03
CVE-2006-2107 EXP Buffer overflow in BL4 SMTP Server 0.1.4 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long… Patch early 7.5 high 4.8% 2006-04-29
CVE-2006-3400 EXP Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remote attack… Patch early 7.5 high 4.8% 2006-07-06
CVE-2007-1013 EXP PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote attackers to execute arbitrary… Patch early 10.0 high 4.8% 2007-02-21
CVE-2007-2538 EXP SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via th… Patch early 7.5 high 4.8% 2007-05-09
CVE-2007-3539 EXP Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL comma… Patch early 7.5 high 4.8% 2007-07-03
CVE-2007-4419 EXP Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cook… Patch early 9.3 high 4.8% 2007-08-18
CVE-2004-0940 EXP Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary… Patch early 7.8 high 4.8% 2005-02-09
CVE-2009-1356 EXP Stack-based buffer overflow in Elecard AVC HD Player allows remote attackers to execute arbitrary code via a long MP3 filename in a playlist (.xpl) fi… Patch early 9.3 high 4.8% 2009-04-21
CVE-2009-4107 EXP Buffer overflow in Invisible Browsing 5.0.52 allows user-assisted remote attackers to execute arbitrary code via a crafted .ibkey file containing a lo… Patch early 9.3 high 4.8% 2009-11-29
CVE-2009-4757 EXP Stack-based buffer overflow in BrotherSoft EW-MusicPlayer 0.8 allows remote attackers to cause a denial of service (application crash) or possibly exe… Patch early 9.3 high 4.8% 2010-03-29
CVE-2006-2315 EXP PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 4.8% 2006-05-12
CVE-2008-5010 EXP in.dhcpd in the DHCP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows remote attackers to cause a denial of service… Patch early 10.0 high 4.8% 2008-11-10
CVE-2015-7235 EXP Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for WordPress allow remote attackers… Patch early 7.5 high 4.8% 2015-09-17
CVE-2000-0586 EXP Buffer overflow in Dalnet IRC server 4.6.5 allows remote attackers to cause a denial of service or execute arbitrary commands via the SUMMON command. Patch early 10.0 high 4.8% 2000-06-29
CVE-2007-5653 EXP The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restrictions, which allows context-depe… Patch early 9.3 high 4.8% 2007-10-23
CVE-2009-4372 EXP AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute a… Patch early 7.5 high 4.8% 2009-12-21
CVE-2008-7022 EXP Insecure method vulnerability in ChilkatMail_v7_9.dll in the Chilkat Software IMAP ActiveX control (ChilkatMail2.ChilkatMailMan2.1) allows remote atta… Patch early 9.3 high 4.8% 2009-08-21
CVE-2002-0280 EXP Buffer overflow in CodeBlue 4 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via a long string in an SMTP… Patch early 7.5 high 4.8% 2002-05-31
CVE-2005-1702 EXP Format string vulnerability in Warrior Kings: Battles 1.23 and earlier and Warrior Kings 1.3 and earlier allows remote attackers to execute arbitrary… Patch early 7.5 high 4.8% 2005-05-24
CVE-2015-6008 EXP install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands via the adminPassword paramete… Patch early 7.5 high 4.8% 2015-09-28
CVE-1999-0873 EXP Buffer overflow in Skyfull mail server via MAIL FROM command. Patch early 7.5 high 4.8% 1999-10-30
CVE-2009-1059 EXP Stack-based buffer overflow in Trident PowerZip 7.2 might allow remote attackers to execute arbitrary code via a crafted .zip file. NOTE: CVE has not… Patch early 9.3 high 4.8% 2009-03-24
CVE-2009-2961 EXP Stack-based buffer overflow in Thaddy de Konng KOL Player 1.0 allows remote attackers to cause a denial of service (crash) or execute arbitrary code v… Patch early 9.3 high 4.8% 2009-08-25
CVE-2009-3947 EXP Buffer overflow in the FTP service on the Tandberg MXP F7.0 allows remote attackers to cause a denial of service (process crash or device reboot) or p… Patch early 9.3 high 4.8% 2009-11-16
CVE-2009-4759 EXP Buffer overflow in BrotherSoft BMXPlay 0.4.4b allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary c… Patch early 9.3 high 4.8% 2010-03-29
CVE-2008-6932 EXP Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uploading a fi… Patch early 7.5 high 4.8% 2009-08-11
CVE-2008-2267 EXP Incomplete blacklist vulnerability in javaUpload.php in Postlet in the FileManager module in CMS Made Simple 1.2.4 and earlier allows remote attackers… Patch early 7.5 high 4.8% 2008-05-16
← previous page 196 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt