peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,069 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-43579 EXP A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linkin… Patch early 7.8 high 7.3% 2022-01-10
CVE-2004-0030 EXP PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remot… Patch early 9.8 critical 7.3% 2004-01-20
CVE-2016-1839 EXP The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2… Patch early 5.5 medium 7.3% 2016-05-20
CVE-2019-13237 EXP In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resource… Patch early 4.3 medium 7.3% 2019-08-27
CVE-2004-1554 EXP PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by modifying the… Patch early 7.5 high 7.3% 2004-12-31
CVE-2010-2809 EXP The default configuration of the <Button2> binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assist… Patch early 6.8 medium 7.3% 2010-08-19
CVE-2008-1278 EXP The RemotelyAnywhere.exe service in the Remotely Anywhere Server and Workstation 8.0.668 and earlier allows remote attackers to cause a denial of serv… Patch early 5.0 medium 7.3% 2008-03-10
CVE-2008-5280 EXP The Local ZIM Server in Zilab Chat and Instant Messaging (ZIM) Server 2.0 and 2.1 allows remote attackers to cause a denial of service (NULL pointer d… Patch early 5.0 medium 7.3% 2008-11-29
CVE-2000-0766 EXP Buffer overflow in vqSoft vqServer 1.4.49 allows remote attackers to cause a denial of service or possibly gain privileges via a long HTTP GET request… Patch early 7.5 high 7.3% 2000-10-20
CVE-2000-0400 EXP The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to do… Patch early 7.5 high 7.3% 2000-05-13
CVE-2008-1218 EXP Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to byp… Patch early 6.8 medium 7.3% 2008-03-10
CVE-2011-4800 EXP Directory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and write arbitrary files, and list a… Patch early 9.0 high 7.3% 2011-12-14
CVE-2001-1195 EXP Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager, which allows remote attackers… Patch early 7.5 high 7.3% 2001-12-15
CVE-2007-3151 EXP rpttop.htm in the web management interface in Packeteer PacketShaper 7.3.0g2 and 7.5.0g1 allows remote attackers to cause a denial of service (device… Patch early 5.0 medium 7.3% 2007-06-11
CVE-2004-0605 EXP Non-registered IRC users using (1) ircd-hybrid 7.0.1 and earlier, (2) ircd-ratbox 1.5.1 and earlier, or (3) ircd-ratbox 2.0rc6 and earlier do not have… Patch early 5.0 medium 7.3% 2004-12-06
CVE-2013-1594 EXP An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wireless keys and 3rd party creden… Patch early 7.5 high 7.3% 2020-01-24
CVE-2002-0300 EXP gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly re… Patch early 5.0 medium 7.3% 2002-05-31
CVE-2005-3811 EXP Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to overwrite arb… Patch early 5.0 medium 7.3% 2005-11-25
CVE-2009-1627 EXP Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbitrary code via a long .asf URL… Patch early 9.3 high 7.3% 2009-05-12
CVE-2020-6170 EXP An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the H… Patch early 9.8 critical 7.3% 2020-01-08
CVE-2005-4086 EXP Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier all… Patch early 5.0 medium 7.3% 2005-12-08
CVE-2004-1161 EXP rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access res… Patch early 7.5 high 7.3% 2005-01-10
CVE-2007-4105 EXP A certain ActiveX control in BaiduBar.dll in Baidu Soba Search Bar 5.4 allows remote attackers to execute arbitrary code via a request containing "a l… Patch early 9.3 high 7.3% 2007-07-31
CVE-2017-6104 EXP Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0. Patch early 7.5 high 7.3% 2017-03-02
CVE-2004-0287 EXP Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a lar… Patch early 5.0 medium 7.3% 2004-11-23
CVE-2004-1385 EXP phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID such as shel… Patch early 5.0 medium 7.3% 2004-12-31
CVE-2006-4422 EXP PHP remote file inclusion vulnerability in includes/phpdig/libs/search_function.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 7.3% 2006-08-29
CVE-2011-4640 EXP Directory traversal vulnerability in logs-x.php in SpamTitan WebTitan before 3.60 allows remote authenticated users to read arbitrary files via a .. (… Patch early 4.0 medium 7.3% 2012-10-08
CVE-2014-3865 EXP Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files outside of the intended directori… Patch early 6.4 medium 7.3% 2014-05-30
CVE-2014-2588 EXP Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via… Patch early 4.0 medium 7.3% 2014-03-24
← previous page 275 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt