peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,999 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-9812 EXP The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Ma… Patch early 7.5 high 11.3% 2017-07-17
CVE-2017-16953 EXP connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration o… Patch early 7.5 high 11.3% 2017-12-01
CVE-2002-0613 EXP dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user_logged_in or… Patch early 10.0 high 11.3% 2002-06-18
CVE-2020-15261 EXP On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally authenticated users with administr… Patch early 8.0 high 11.3% 2020-10-19
CVE-2007-4005 EXP Stack-based buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 allows remote attackers to execute arbitrary code via a long string to the sh… Patch early 5.0 medium 11.2% 2007-07-26
CVE-2004-1789 EXP Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to inject arbitrary web script or H… Patch early 4.3 medium 11.2% 2004-12-31
CVE-2021-24488 EXP The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being out… Patch early 6.1 medium 11.2% 2021-08-02
CVE-2019-6274 EXP Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified impa… Patch early 8.8 high 11.2% 2019-03-21
CVE-2025-2126 EXP A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the fi… Patch early 6.3 medium 11.2% 2025-03-09
CVE-2004-1584 EXP CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HT… Patch early 5.0 medium 11.2% 2004-12-31
CVE-2009-4880 EXP Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attacker… Patch early 5.0 medium 11.2% 2010-06-01
CVE-1999-1453 EXP Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX o… Patch early 2.6 low 11.2% 1999-02-02
CVE-2013-5660 EXP Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file. Patch early 9.3 high 11.2% 2014-04-25
CVE-2013-7246 EXP Buffer overflow in the IconCreate method in an ActiveX control in the DaumGame ActiveX plugin 1.1.0.4 and 1.1.0.5 allows remote attackers to execute a… Patch early 9.3 high 11.2% 2014-01-30
CVE-2001-1163 EXP Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500. Patch early 10.0 high 11.2% 2001-06-16
CVE-2014-4927 EXP Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to c… Patch early 7.8 high 11.2% 2014-07-24
CVE-2004-2652 EXP The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attacke… Patch early 7.8 high 11.2% 2004-12-31
CVE-2004-1260 EXP Multiple buffer overflows in the (1) write_heading function in subs.cpp or (2) trim_title function in parse.cpp for abctab2ps 1.6.3 allow remote attac… Patch early 10.0 high 11.2% 2005-01-10
CVE-2009-1608 EXP Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrary code via… Patch early 9.3 high 11.2% 2009-05-11
CVE-2016-9651 EXP A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arb… Patch early 8.8 high 11.2% 2019-01-09
CVE-2015-2196 EXP SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id para… Patch early 7.5 high 11.2% 2015-03-03
CVE-2012-1008 EXP OfficeSIP Server 3.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted To header in a SIP INVITE message. Patch early 5.0 medium 11.2% 2012-02-08
CVE-2004-1992 EXP Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which trigge… Patch early 5.0 medium 11.2% 2004-04-20
CVE-2007-4061 EXP Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to create or overwrite ar… Patch early 9.3 high 11.2% 2007-07-30
CVE-2012-3450 EXP pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during pars… Patch early 2.6 low 11.2% 2012-08-06
CVE-2008-1996 EXP licq before 1.3.6 allows remote attackers to cause a denial of service (file-descriptor exhaustion and application crash) via a large number of connec… Patch early 5.0 medium 11.2% 2008-04-28
CVE-2009-3111 EXP The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Passwor… Patch early 5.0 medium 11.2% 2009-09-09
CVE-2008-4096 EXP libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server… Patch early 8.5 high 11.2% 2008-09-18
CVE-2002-1549 EXP Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request. Patch early 7.5 high 11.2% 2003-03-31
CVE-2012-1593 EXP epan/dissectors/packet-ansi_a.c in the ANSI A dissector in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a den… Patch early 3.3 low 11.2% 2012-04-11
← previous page 200 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt