peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,121 CVEs 1,733 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

149,763 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-0050 EXP Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (ap… Patch early 8.8 high 11.6% 2010-03-15
CVE-2003-1090 EXP Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title. Patch early 10.0 high 11.6% 2003-02-06
CVE-2009-3859 EXP Buffer overflow in eEye Retina WiFi Scanner 1.0.8.68, as used in Retina Network Security Scanner 5.10.14, allows user-assisted remote attackers to cau… Patch early 9.3 high 11.6% 2009-11-04
CVE-2008-4116 EXP Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbit… Patch early 9.3 high 11.6% 2008-09-18
CVE-2019-19731 EXP Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE acti… Patch early 7.5 high 11.6% 2019-12-16
CVE-2011-4189 EXP The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corrup… Patch early 7.5 high 11.6% 2012-03-02
CVE-1999-0710 EXP The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attacker… Patch early 7.5 high 11.6% 1999-07-25
CVE-2002-1456 EXP Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value. Patch early 7.5 high 11.6% 2003-06-09
CVE-2004-1147 EXP phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands vi… Patch early 10.0 high 11.6% 2005-01-10
CVE-2007-0233 EXP wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matchi… Patch early 7.5 high 11.6% 2007-01-13
CVE-2022-22833 EXP An issue was discovered in Servisnet Tessa 0.0.2. An attacker can obtain sensitive information via a /js/app.js request. Patch early 7.5 high 11.6% 2022-02-06
CVE-2015-4181 EXP Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 7.5 high 11.6% 2017-08-25
CVE-2003-0263 EXP Multiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitrary code via long (1) MAIL FRO… Patch early 7.5 high 11.6% 2003-05-27
CVE-2013-7186 EXP Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long string in a .m3u file. Patch early 9.3 high 11.6% 2013-12-20
CVE-2013-2261 EXP Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure Patch early 7.5 high 11.6% 2019-11-04
CVE-1999-0284 EXP Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. Patch early 7.5 high 11.5% 1998-01-01
CVE-2009-0544 EXP Buffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large… Patch early 10.0 high 11.5% 2009-02-12
CVE-2008-1289 EXP Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x b… Patch early 7.5 high 11.5% 2008-03-24
CVE-2002-0599 EXP Blahz-DNS 0.2 and earlier allows remote attackers to bypass authentication and modify configuration by directly requesting CGI programs such as dostuf… Patch early 10.0 high 11.5% 2002-06-18
CVE-2000-1014 EXP Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute arbitrary command… Patch early 7.5 high 11.5% 2000-12-11
CVE-2004-0816 EXP Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service (application c… Patch early 7.5 high 11.5% 2004-12-23
CVE-2000-0909 EXP Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long Fro… Patch early 7.5 high 11.5% 2000-12-19
CVE-2011-2543 EXP Buffer overflow in the cuil component in Cisco Telepresence System Integrator C Series 4.x before TC4.2.0 allows remote authenticated users to cause a… Patch early 9.0 high 11.5% 2011-09-23
CVE-2016-1610 EXP Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows re… Patch early 7.5 high 11.5% 2016-08-01
CVE-2006-2849 EXP PHP remote file inclusion vulnerability in includes/webdav/server.php in Bytehoard 2.1 Epsilon/Delta allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 11.5% 2006-06-06
CVE-2003-1425 EXP guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter. Patch early 10.0 high 11.5% 2003-12-31
CVE-2005-3486 EXP Multiple format string vulnerabilities in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole… Patch early 7.5 high 11.5% 2005-11-03
CVE-2009-4112 EXP Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memor… Patch early 9.0 high 11.5% 2009-11-30
CVE-2018-18428 EXP TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg URI. Patch early 7.5 high 11.5% 2018-10-19
CVE-2021-3337 EXP The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on repl… Patch early 7.5 high 11.5% 2021-01-28
← previous page 140 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt