peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

149,742 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-9463 EXP functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to… Patch early 8.8 high 14.8% 2017-09-15
CVE-2017-3807 EXP A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could… Patch early 8.8 high 14.8% 2017-02-09
CVE-2008-0477 EXP Stack-based buffer overflow in the QMPUpgrade.Upgrade.1 ActiveX control in QMPUpgrade.dll 1.0.0.1 in Move Networks Upgrade Manager allows remote attac… Patch early 10.0 high 14.8% 2008-01-29
CVE-2003-0280 EXP Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL… Patch early 10.0 high 14.7% 2003-06-16
CVE-2017-12500 EXP A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in… Patch early 8.8 high 14.7% 2018-02-15
CVE-2006-4197 EXP Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote at… Patch early 7.5 high 14.7% 2006-08-17
CVE-2010-1939 EXP Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup… Patch early 7.6 high 14.7% 2010-05-13
CVE-2006-5517 EXP Multiple PHP remote file inclusion vulnerabilities in Rhode Island Open Meetings Filing Application (OMFA) allow remote attackers to execute arbitrary… Patch early 7.5 high 14.7% 2006-10-26
CVE-2004-0691 EXP Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (… Patch early 7.5 high 14.7% 2004-09-28
CVE-2004-1289 EXP Multiple buffer overflows in (1) the getline function in pcalutil.c and (2) the get_holiday function in readfile.c for pcal 4.7.1 allow remote attacke… Patch early 10.0 high 14.7% 2005-01-10
CVE-2007-4584 EXP Stack-based buffer overflow in BitchX 1.1 Final allows remote IRC servers to execute arbitrary code via a long string in a MODE command, related to th… Patch early 10.0 high 14.7% 2007-08-29
CVE-2007-5381 EXP Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to exe… Patch early 9.3 high 14.7% 2007-10-12
CVE-2003-1387 EXP Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username. Patch early 7.5 high 14.7% 2003-12-31
CVE-2006-2022 EXP Buffer overflow in the parse_url function in the RTSP module (rtsp/parse_url.c) in Fenice 1.10 and earlier allows remote attackers to execute arbitrar… Patch early 7.5 high 14.7% 2006-04-25
CVE-2022-24715 EXP Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration,… Patch early 8.5 high 14.7% 2022-03-08
CVE-2020-10963 EXP FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/fi… Patch early 7.2 high 14.7% 2020-03-25
CVE-2001-0836 EXP Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request. Patch early 7.5 high 14.7% 2001-12-06
CVE-2010-4228 EXP Stack-based buffer overflow in NWFTPD.NLM before 5.10.02 in the FTP server in Novell NetWare allows remote authenticated users to execute arbitrary co… Patch early 9.0 high 14.7% 2011-03-22
CVE-2022-3142 EXP The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injecti… Patch early 8.8 high 14.7% 2022-09-19
CVE-2004-1120 EXP Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and earlier al… Patch early 10.0 high 14.6% 2005-01-10
CVE-2009-2692 EXP The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops stru… Patch early 7.8 high 14.6% 2009-08-14
CVE-2009-3663 EXP Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of service (cra… Patch early 10.0 high 14.6% 2009-10-11
CVE-2004-1127 EXP Buffer overflow in Open Dc Hub 0.7.14 allows remote attackers, with administrator privileges, to execute arbitrary code via a long RedirectAll command… Patch early 10.0 high 14.6% 2005-01-10
CVE-2006-6125 EXP Heap-based buffer overflow in the wireless driver (WG311ND5.SYS) 2.3.1.10 for NetGear WG311v1 wireless adapter allows remote attackers to execute arbi… Patch early 7.5 high 14.6% 2006-11-27
CVE-2001-0050 EXP Buffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary commands via an IP address th… Patch early 10.0 high 14.6% 2001-02-16
CVE-2008-0296 EXP Heap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC Media Player 0.8.6d and earlier on Windows might allow remote RTSP servers… Patch early 10.0 high 14.6% 2008-01-16
CVE-2013-2567 EXP An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.co… Patch early 7.5 high 14.6% 2020-01-29
CVE-2006-3890 EXP Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, al… Patch early 9.3 high 14.6% 2006-11-21
CVE-2005-2878 EXP Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via form… Patch early 7.5 high 14.6% 2005-09-13
CVE-2017-11152 EXP Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write… Patch early 7.5 high 14.6% 2017-08-08
← previous page 123 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt