peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,146 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-1400 EXP The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unauthorized access via a direct re… Patch early 7.5 high 7.2% 2004-12-31
CVE-2017-15879 EXP CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before… Patch early 8.8 high 7.2% 2017-10-24
CVE-2009-1634 EXP The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, whic… Patch early 7.5 high 7.2% 2009-05-26
CVE-2013-4885 EXP The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily… Patch early 6.8 medium 7.2% 2013-10-26
CVE-1999-1018 EXP IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker t… Patch early 7.5 high 7.2% 1999-07-27
CVE-2006-3746 EXP Integer overflow in parse_comment in GnuPG (gpg) 1.4.4 allows remote attackers to cause a denial of service (segmentation fault) via a crafted message… Patch early 5.0 medium 7.2% 2006-07-28
CVE-2007-4748 EXP Buffer overflow in the PowerPlayer.dll ActiveX control in PPStream 2.0.1.3829 allows remote attackers to execute arbitrary code via a long Logo parame… Patch early 6.8 medium 7.2% 2007-09-06
CVE-2008-0539 EXP Cross-site scripting (XSS) vulnerability in dms/policy/rep_request.php in F5 BIG-IP Application Security Manager (ASM) 9.4.3 allows remote attackers t… Patch early 4.3 medium 7.2% 2008-02-01
CVE-2007-1649 EXP PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a serialized data input string beginnin… Patch early 7.8 high 7.2% 2007-03-24
CVE-2012-2396 EXP VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted MP4 fi… Patch early 4.3 medium 7.2% 2012-04-19
CVE-2017-7046 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 8.8 high 7.2% 2017-07-20
CVE-2005-2850 EXP SlimFTPd 3.17 allows remote attackers to cause a denial of service (crash) via certain (1) USER and (2) PASS commands, possibly due to a buffer overfl… Patch early 5.0 medium 7.2% 2005-09-08
CVE-2015-1578 EXP Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing atta… Patch early 5.8 medium 7.2% 2015-02-11
CVE-2018-5333 EXP In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an invalid address is… Patch early 5.5 medium 7.2% 2018-01-11
CVE-2010-1177 EXP Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… Patch early 9.3 high 7.2% 2010-03-29
CVE-2007-6314 EXP BarracudaDrive Web Server before 3.8 allows remote attackers to read the source code for web scripts by appending a (1) + (plus), (2) . (dot), or (3)… Patch early 5.0 medium 7.2% 2007-12-12
CVE-2000-0640 EXP Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, which provides different error… Patch early 7.5 high 7.2% 2000-07-08
CVE-2009-1227 EXP NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI Web Service allows remote atta… Patch early 10.0 high 7.2% 2009-04-02
CVE-2018-1120 EXP A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory containing command line argum… Patch early 2.8 low 7.2% 2018-06-20
CVE-2007-5110 EXP Absolute path traversal vulnerability in the EbCrypt.eb_c_PRNGenerator.1 ActiveX control in EBCRYPT.DLL 2.0.0.2087 and earlier in EB Design ebCrypt al… Patch early 7.5 high 7.2% 2007-09-26
CVE-2022-40319 EXP The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa… Patch early 7.5 high 7.2% 2023-01-17
CVE-2006-2481 EXP VMware ESX Server 2.0.x before 2.0.2 and 2.x before 2.5.2 patch 4 stores authentication credentials in base 64 encoded format in the vmware.mui.kid an… Patch early 5.0 medium 7.2% 2006-07-31
CVE-2007-2192 EXP Buffer overflow in Photofiltre Studio 8.1.1 allows user-assisted remote attackers to execute arbitrary code via a crafted .tif file. Patch early 9.3 high 7.2% 2007-04-24
CVE-2008-0071 EXP The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause a denial o… Patch early 4.3 medium 7.2% 2008-06-16
CVE-2009-1611 EXP Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 257 reply to a CWD comman… Patch early 10.0 high 7.2% 2009-05-11
CVE-2002-0319 EXP Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other… Patch early 7.5 high 7.2% 2002-06-25
CVE-2002-1481 EXP savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbi… Patch early 7.5 high 7.2% 2003-04-22
CVE-2010-0388 EXP Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a den… Patch early 7.5 high 7.2% 2010-01-25
CVE-2006-3074 EXP klif.sys in Kaspersky Internet Security 6.0 and 7.0, Kaspersky Anti-Virus (KAV) 6.0 and 7.0, KAV 6.0 for Windows Workstations, and KAV 6.0 for Windows… Patch early 5.0 medium 7.2% 2006-06-19
CVE-2009-1357 EXP CRLF injection vulnerability in da/DA/Login in Sun Java System Delegated Administrator 6.2 through 6.4 allows remote attackers to inject arbitrary HTT… Patch early 6.8 medium 7.2% 2009-04-23
← previous page 279 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt