peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,218 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

12,661 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-0566 EXP Buffer overflow in Golden FTP Server Pro (goldenftpd) 2.x allows remote attackers to execute arbitrary code via a long RNTO command. Patch early 7.5 high 15.7% 2005-01-22
CVE-2010-1759 EXP Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows r… Patch early 9.3 high 15.7% 2010-06-11
CVE-2011-1206 EXP Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before… Patch early 10.0 high 15.7% 2011-04-21
CVE-2010-1306 EXP Directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote attackers to read arbitrary loca… Patch early 7.5 high 15.7% 2010-04-08
CVE-2010-1875 EXP Directory traversal vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to read arbitra… Patch early 7.5 high 15.7% 2010-05-12
CVE-2018-1218 EXP In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the 'nsrd' daemon causes a buffer o… Patch early 7.5 high 15.7% 2018-03-19
CVE-2010-2351 EXP Stack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remote attackers to execute arbitr… Patch early 10.0 high 15.7% 2010-06-21
CVE-2006-4489 EXP Multiple PHP remote file inclusion vulnerabilities in MiniBill 2006-07-14 (1.2.2) allow remote attackers to execute arbitrary PHP code via (1) a URL i… Patch early 7.5 high 15.7% 2006-08-31
CVE-2019-3924 EXP MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The software will execute user defin… Patch early 7.5 high 15.7% 2019-02-20
CVE-2010-1602 EXP Directory traversal vulnerability in the ZiMB Comment (com_zimbcomment) component 0.8.1 for Joomla! allows remote attackers to read arbitrary files an… Patch early 7.5 high 15.7% 2010-04-29
CVE-2005-2856 EXP Stack-based buffer overflow in the WinACE UNACEV2.DLL third-party compression utility before 2.6.0.0, as used in multiple products including (1) ALZip… Patch early 7.5 high 15.7% 2005-09-08
CVE-2008-0220 EXP Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunc… Patch early 7.5 high 15.7% 2008-01-10
CVE-2004-0659 EXP Buffer overflow in TranslateFilename for common.c in MPlayer 1.0pre4 allows remote attackers to execute arbitrary code via a long file name. Patch early 10.0 high 15.7% 2004-08-06
CVE-2008-3242 EXP Heap-based buffer overflow in the PPMedia Class ActiveX control in PPMPlayer.dll in PPMate 2.3.1.93 allows remote attackers to execute arbitrary code… Patch early 10.0 high 15.7% 2008-07-21
CVE-2006-3172 EXP Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary PHP code via a URL with a trai… Patch early 7.5 high 15.6% 2006-06-23
CVE-2004-0354 EXP Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code via forma… Patch early 10.0 high 15.6% 2004-11-23
CVE-2010-4931 EXP Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .. (dot dot… Patch early 10.0 high 15.6% 2011-10-09
CVE-2000-0844 EXP Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to exec… Patch early 10.0 high 15.6% 2000-11-14
CVE-2006-4046 EXP Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for Windows, and 0.1.10_rc5 and earlier on Linux/BSD, allow remote at… Patch early 7.5 high 15.6% 2006-08-09
CVE-2024-9054 EXP Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor… Patch early 8.8 high 15.6% 2024-10-04
CVE-2013-0291 EXP NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability Patch early 7.5 high 15.6% 2020-01-30
CVE-2013-7051 EXP D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters Patch early 8.8 high 15.6% 2020-02-04
CVE-2006-4236 EXP Multiple PHP remote file inclusion vulnerabilities in POWERGAP allow remote attackers to execute arbitrary PHP code via a URL in the (1) shopid parame… Patch early 7.5 high 15.6% 2006-08-21
CVE-2001-0100 EXP bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address. Patch early 10.0 high 15.6% 2001-02-12
CVE-2006-5302 EXP Multiple PHP remote file inclusion vulnerabilities in Redaction System 1.0000 allow remote attackers to execute arbitrary PHP code via a URL in the (1… Patch early 7.5 high 15.6% 2006-10-17
CVE-2003-1378 EXP Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via… Patch early 8.8 high 15.6% 2003-12-31
CVE-2020-25790 EXP Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes… Patch early 7.2 high 15.6% 2020-09-19
CVE-2016-0793 EXP Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on W… Patch early 7.5 high 15.6% 2016-04-01
CVE-2008-0912 EXP Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10.0.1.3415… Patch early 10.0 high 15.6% 2008-02-22
CVE-2008-0671 EXP Stack-based buffer overflow in the add_line_buffer function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attackers to execute arbitrary code v… Patch early 10.0 high 15.6% 2008-02-12
← previous page 96 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt