peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,887 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-8671 EXP Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safa… Patch early 8.8 high 7.7% 2019-12-18
CVE-2008-3396 EXP Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via… Patch early 5.0 medium 7.7% 2008-07-31
CVE-2008-0767 EXP ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain "number of URLs" field is consistent with the… Patch early 5.0 medium 7.7% 2008-02-13
CVE-2003-1386 EXP AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displ… Patch early 6.4 medium 7.7% 2003-12-31
CVE-1999-0996 EXP Buffer overflow in Infoseek Ultraseek search engine allows remote attackers to execute commands via a long GET request. Patch early 7.5 high 7.7% 1999-12-15
CVE-2006-5558 EXP Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via format… Patch early 10.0 high 7.7% 2006-10-27
CVE-2008-0702 EXP Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of service (daemon crash or hang)… Patch early 9.3 high 7.7% 2008-02-12
CVE-2009-5134 EXP Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions before 1.8.3 (Build 16010), al… Patch early 6.8 medium 7.7% 2013-01-18
CVE-2008-3155 EXP Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to cause a denial of serv… Patch early 9.3 high 7.7% 2008-07-11
CVE-2017-0245 EXP The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1 and Windows Server 2012 Gold allow a local authenticated attacker to exec… Patch early 4.7 medium 7.7% 2017-05-12
CVE-2007-3446 EXP BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers to obtain login access. Patch early 7.5 high 7.7% 2007-06-27
CVE-2000-0452 EXP Buffer overflow in the ESMTP service of Lotus Domino Server 5.0.1 allows remote attackers to cause a denial of service via a long MAIL FROM command. Patch early 5.0 medium 7.7% 2000-05-18
CVE-2001-1471 EXP prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the… Patch early 8.8 high 7.7% 2001-07-31
CVE-2008-0222 EXP Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and exe… Patch early 7.5 high 7.7% 2008-01-10
CVE-1999-1016 EXP Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows… Patch early 5.0 medium 7.7% 1999-08-27
CVE-2002-0230 EXP Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cm… Patch early 5.0 medium 7.7% 2002-05-16
CVE-2010-0387 EXP Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to cau… Patch early 7.5 high 7.7% 2010-01-25
CVE-2020-14946 EXP downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and earlier allows users to downloa… Patch early 4.3 medium 7.7% 2020-06-22
CVE-2007-2988 EXP A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administrative credentials are missing,… Patch early 7.5 high 7.7% 2007-06-01
CVE-2013-6674 EXP Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 a… Patch early 4.3 medium 7.7% 2014-02-17
CVE-2011-5129 EXP Heap-based buffer overflow in XChat 2.8.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code… Patch early 5.0 medium 7.7% 2012-08-30
CVE-2020-12351 EXP Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. Patch early 8.8 high 7.7% 2020-11-23
CVE-2007-3725 EXP The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) before 0.91 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted… Patch early 4.3 medium 7.7% 2007-07-12
CVE-2023-25289 EXP Directory Traversal vulnerability in virtualreception Digital Receptie version win7sp1_rtm.101119-1850 6.1.7601.1.0.65792 in embedded web server, allo… Patch early 7.5 high 7.7% 2023-05-04
CVE-2000-0329 EXP A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka… Patch early 5.1 medium 7.7% 1999-11-11
CVE-2017-0569 EXP An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the c… Patch early 7.0 high 7.7% 2017-04-07
CVE-2015-2169 EXP Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attackers to inject arbitrary web scri… Patch early 4.3 medium 7.7% 2015-06-24
CVE-2021-44665 EXP A Directory Traversal vulnerability exists in the Xerte Project Xerte through 3.10.3 when downloading a project file via download.php. Patch early 6.5 medium 7.7% 2022-02-24
CVE-2017-3131 EXP A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or comma… Patch early 5.4 medium 7.7% 2017-09-12
CVE-2017-15990 EXP Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/. Patch early 9.8 critical 7.7% 2017-10-31
← previous page 264 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt