peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,593 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-3574 EXP Tuniac 090517c allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long File1 argument in a .pls pla… Patch early 9.3 high 4.8% 2009-10-06
CVE-2007-4754 EXP Format string vulnerability in the safe_bprintf function in acesrc/acebot_cmds.c in Alien Arena 2007 6.10 and earlier allows remote attackers to cause… Patch early 7.5 high 4.8% 2007-09-08
CVE-2008-1319 EXP Untrusted search path and argument injection vulnerability in the VersantD service in Versant Object Database 7.0.1.3 and earlier, as used in Borland… Patch early 9.3 high 4.8% 2008-03-13
CVE-2018-16071 EXP A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted video… Patch early 8.8 high 4.8% 2019-01-09
CVE-2016-1819 EXP Use-after-free vulnerability in the IOAccelContext2::clientMemoryForType method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and… Patch early 7.8 high 4.8% 2016-05-20
CVE-2005-0979 EXP Multiple buffer overflows in RUMBA 7.3 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted… Patch early 7.5 high 4.8% 2005-05-02
CVE-2013-7187 EXP SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL comma… Patch early 7.5 high 4.8% 2013-12-20
CVE-2008-4486 EXP Directory traversal vulnerability in index.php in SAC.php (SACphp), as used in Yerba 6.3 and earlier, allows remote attackers to include and execute a… Patch early 10.0 high 4.8% 2008-10-08
CVE-1999-0705 EXP Buffer overflow in INN inews program. Patch early 7.5 high 4.8% 1999-09-01
CVE-2006-4584 EXP Tr Forum 2.0 allows remote attackers to bypass authentication and add an administrative account via the login and password parameters to admin/insert_… Patch early 7.5 high 4.8% 2006-09-06
CVE-2008-2574 EXP Unrestricted file upload vulnerability in admin/Editor/imgupload.php in FlashBlog 0.31 beta allows remote attackers to execute arbitrary code by uploa… Patch early 7.5 high 4.8% 2008-06-06
CVE-2015-3315 EXP Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a sym… Patch early 7.8 high 4.8% 2017-06-26
CVE-2009-3254 EXP Multiple stack-based buffer overflows in Ultimate Player 1.56 beta allow remote attackers to execute arbitrary code via a long string in a (1) .m3u or… Patch early 9.3 high 4.8% 2009-09-18
CVE-2004-0261 EXP oj.cgi in OpenJournal 2.0 through 2.0.5 allows remote attackers to bypass authentication and access the control panel via a 0 in the uid parameter. Patch early 10.0 high 4.8% 2004-11-23
CVE-2026-5027 EXP The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbi… Patch early 8.8 high 4.8% 2026-03-27
CVE-2017-2474 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchO… Patch early 7.8 high 4.8% 2017-04-02
CVE-2017-2478 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchO… Patch early 7.0 high 4.7% 2017-04-02
CVE-2007-0261 EXP snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administ… Patch early 10.0 high 4.7% 2007-01-16
CVE-2007-1640 EXP Multiple PHP remote file inclusion vulnerabilities in ClassWeb 2.03 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 10.0 high 4.7% 2007-03-23
CVE-2006-5552 EXP Multiple heap-based buffer overflows in RevilloC MailServer 1.21 and earlier allow remote attackers to cause a denial of service (CPU consumption or a… Patch early 7.5 high 4.7% 2006-10-26
CVE-2016-1821 EXP IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL point… Patch early 7.8 high 4.7% 2016-05-20
CVE-2007-0338 EXP Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with a large number of format stri… Patch early 7.5 high 4.7% 2007-01-18
CVE-2015-2090 EXP SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for Wordpress allows remote atta… Patch early 7.5 high 4.7% 2015-02-26
CVE-2015-2216 EXP SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme 4.x for WordPress allows remote attackers to execute arbitrary SQL commands via… Patch early 7.5 high 4.7% 2015-03-05
CVE-2015-3325 EXP SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to execute arbitrary SQL command… Patch early 7.5 high 4.7% 2015-05-15
CVE-2002-2170 EXP Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but… Patch early 7.5 high 4.7% 2002-12-31
CVE-2018-9128 EXP DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068. Patch early 7.8 high 4.7% 2018-04-01
CVE-2015-7767 EXP Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) v… Patch early 7.5 high 4.7% 2015-10-09
CVE-2006-0671 EXP Buffer overflow in Sony Ericsson K600i, V600i, W800i, and T68i cell phone allows remote attackers to cause a denial of service (reboot or shutdown) th… Patch early 7.8 high 4.7% 2006-02-13
CVE-2007-2853 EXP The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitrary commands via a command line… Patch early 10.0 high 4.7% 2007-05-24
← previous page 197 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt