peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,891 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-6505 EXP epan/dissectors/packet-packetbb.c in the PacketBB dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a… Patch early 5.9 medium 7.7% 2016-08-06
CVE-2005-3294 EXP Typsoft FTP Server 1.11, with "Sub Directory Include" enabled, allows remote attackers to cause a denial of service (crash) by sending multiple RETR c… Patch early 5.0 medium 7.7% 2005-10-23
CVE-2006-2149 EXP PHP remote file inclusion vulnerability in sources/lostpw.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows rem… Patch early 6.4 medium 7.7% 2006-05-03
CVE-2006-2392 EXP PHP remote file inclusion vulnerability in public_includes/pub_popup/popup_finduser.php in PHP Blue Dragon Platinum 2.8.0 allows remote attackers to e… Patch early 6.4 medium 7.7% 2006-05-16
CVE-2014-1202 EXP The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a… Patch early 9.3 high 7.7% 2014-01-25
CVE-2017-7115 EXP An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It… Patch early 8.1 high 7.7% 2017-10-23
CVE-2004-0437 EXP Titan FTP Server version 3.01 build 163, and possibly other versions before build 169, allows remote authenticated users to cause a denial of service… Patch early 5.0 medium 7.7% 2004-07-07
CVE-2012-1670 EXP admin/index.php in PHP Grade Book before 1.9.5 BETA allows remote attackers to read the database via a SaveSQL action. Patch early 5.0 medium 7.7% 2012-03-31
CVE-2000-0521 EXP Savant web server allows remote attackers to read source code of CGI scripts via a GET request that does not include the HTTP version number. Patch early 5.0 medium 7.7% 2000-06-05
CVE-2006-4788 EXP PHP remote file inclusion vulnerability in includes/log.inc.php in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled… Patch early 5.1 medium 7.7% 2006-09-14
CVE-2005-0735 EXP newsscript.pl for NewsScript allows remote attackers to gain privileges by setting the mode parameter to admin. Patch early 10.0 high 7.7% 2005-05-02
CVE-2018-6126 EXP A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML… Patch early 8.8 high 7.7% 2019-01-09
CVE-2015-6750 EXP Buffer overflow in Ricoh DL FTP Server 1.1.0.6 and earlier allows remote attackers to execute arbitrary code via a long USER command. Patch early 7.5 high 7.7% 2015-08-31
CVE-2010-0642 EXP Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded characters in the filename extension… Patch early 5.0 medium 7.7% 2010-02-17
CVE-2017-16935 EXP Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to bypass intended access restri… Patch early 9.8 critical 7.7% 2017-11-24
CVE-2003-1341 EXP The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.e… Patch early 7.5 high 7.7% 2003-12-31
CVE-2008-2106 EXP Call of Duty 4 (CoD4) 1.5 and earlier allows remote authenticated users to cause a denial of service (crash) via a type 7 stats packet, which triggers… Patch early 6.8 medium 7.7% 2008-05-07
CVE-2012-6313 EXP simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information via a reque… Patch early 5.0 medium 7.7% 2012-12-11
CVE-2015-3693 EXP Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates for DDR3 RAM, which might make i… Patch early 9.3 high 7.7% 2015-07-03
CVE-2008-4134 EXP PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other versions before 0.05, allows remo… Patch early 7.5 high 7.7% 2008-09-19
CVE-2007-2519 EXP Directory traversal vulnerability in the installer in PEAR 1.0 through 1.5.3 allows user-assisted remote attackers to overwrite arbitrary files via a… Patch early 6.8 medium 7.7% 2007-05-22
CVE-2006-1610 EXP PHP remote file inclusion vulnerability in lib/armygame.php in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allows… Patch early 5.1 medium 7.7% 2006-04-04
CVE-2008-4509 EXP Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows remote attackers to execute a… Patch early 10.0 high 7.7% 2008-10-09
CVE-2017-6984 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. iTunes before 12.6.1 on Windows is… Patch early 8.8 high 7.7% 2017-05-22
CVE-2013-3615 EXP Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent attackers to discover clearte… Patch early 7.8 high 7.7% 2013-09-17
CVE-2000-0207 EXP SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters. Patch early 7.5 high 7.7% 2000-03-01
CVE-2000-0424 EXP The CGI counter 4.0.7 by George Burgyan allows remote attackers to execute arbitrary commands via shell metacharacters. Patch early 7.5 high 7.7% 2000-05-15
CVE-2000-0432 EXP The calender.pl and the calendar_admin.pl calendar scripts by Matt Kruse allow remote attackers to execute arbitrary commands via shell metacharacters… Patch early 7.5 high 7.7% 2000-05-16
CVE-2005-1686 EXP Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string spe… Patch early 2.6 low 7.7% 2005-05-20
CVE-2012-1830 EXP Stack-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 555. Patch early 10.0 high 7.7% 2012-07-05
← previous page 265 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt