peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,322 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-6561 EXP Multiple stack-based buffer overflows in PDFLib allow user-assisted remote attackers to execute arbitrary code via a long filename argument to the PDF… Patch early 5.7 medium 6.7% 2007-12-28
CVE-2004-1907 EXP The Web Filtering functionality in Kerio Personal Firewall (KPF) 4.0.13 allows remote attackers to cause a denial of service (crash) by sending hex-en… Patch early 2.6 low 6.7% 2004-12-31
CVE-2016-10081 EXP /usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishan… Patch early 7.8 high 6.7% 2016-12-29
CVE-2001-1202 EXP Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page, which allows rem… Patch early 7.5 high 6.7% 2001-12-28
CVE-2005-1520 EXP Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attac… Patch early 7.5 high 6.7% 2005-05-26
CVE-2002-1147 EXP The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration enabled, does… Patch early 7.1 high 6.7% 2002-10-11
CVE-2011-3187 EXP The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in reque… Patch early 4.3 medium 6.7% 2011-08-29
CVE-2004-0164 EXP KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message t… Patch early 5.0 medium 6.7% 2004-03-03
CVE-2021-46398 EXP A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get… Patch early 8.8 high 6.7% 2022-02-04
CVE-2003-1227 EXP PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remot… Patch early 7.5 high 6.7% 2003-12-31
CVE-2013-3613 EXP Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a repla… Patch early 7.8 high 6.7% 2013-09-17
CVE-2002-1885 EXP PHP remote file inclusion vulnerability in showhits.php3 for PowerPhlogger (PPhlogger) 2.0.9 through 2.2.2 allows remote attackers to execute arbitrar… Patch early 7.5 high 6.7% 2002-12-31
CVE-2008-1886 EXP The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for a KeyCode that blocks unautho… Patch early 7.5 high 6.7% 2008-04-18
CVE-2009-4665 EXP Directory traversal vulnerability in CuteSoft_Client/CuteEditor/Load.ashx in CuteSoft Components Cute Editor for ASP.NET allows remote attackers to re… Patch early 5.0 medium 6.7% 2010-03-05
CVE-2006-6661 EXP Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execut… Patch early 7.5 high 6.7% 2006-12-20
CVE-2017-2364 EXP An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. The issue involves the "WebKit" co… Patch early 6.5 medium 6.7% 2017-02-20
CVE-2009-0744 EXP Apple Safari 4 Beta build 528.16 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a feeds: UR… Patch early 5.0 medium 6.7% 2009-02-27
CVE-2006-2284 EXP Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarol… Patch early 6.8 medium 6.7% 2006-05-10
CVE-2007-0462 EXP The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote att… Patch early 10.0 high 6.7% 2007-01-26
CVE-2014-6607 EXP M/Monit 3.3.2 and earlier does not verify the original password before changing passwords, which allows remote attackers to change the password of oth… Patch early 7.5 high 6.6% 2014-10-06
CVE-2007-2486 EXP Directory traversal vulnerability in download.asp in Motobit 1.3 and 1.5 (aka PStruh-CZ) allows remote attackers to read arbitrary files via a .. (dot… Patch early 5.0 medium 6.6% 2007-05-03
CVE-2017-17098 EXP The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary P… Patch early 9.8 critical 6.6% 2018-01-02
CVE-2006-4869 EXP PHP remote file inclusion vulnerability in phpunity-postcard.php in phpunity.postcard allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 6.6% 2006-09-19
CVE-2008-7086 EXP Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie cookie to a… Patch early 7.5 high 6.6% 2009-08-26
CVE-2004-2026 EXP Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format str… Patch early 7.5 high 6.6% 2004-12-31
CVE-2017-15013 EXP OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticat… Patch early 8.8 high 6.6% 2017-10-13
CVE-2007-0355 EXP Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly r… Patch early 7.2 high 6.6% 2007-01-19
CVE-2003-0802 EXP Nokia Electronic Documentation (NED) 5.0 allows remote attackers to obtain a directory listing of the WebLogic web root, and the physical path of the… Patch early 5.0 medium 6.6% 2003-10-06
CVE-2008-7006 EXP Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backup… Patch early 5.0 medium 6.6% 2009-08-19
CVE-1999-0431 EXP Linux 2.2.3 and earlier allow a remote attacker to perform an IP fragmentation attack, causing a denial of service. Patch early 5.0 medium 6.6% 1999-03-01
← previous page 297 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt