peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,267 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

149,794 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2000-0074 EXP PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions. Patch early 7.5 high 9.8% 2000-01-11
CVE-2001-1196 EXP Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argument… Patch early 10.0 high 9.8% 2001-12-17
CVE-2014-5086 EXP A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let… Patch early 8.8 high 9.8% 2020-02-10
CVE-2011-3498 EXP Heap-based buffer overflow in Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (crash) and possibl… Patch early 10.0 high 9.8% 2011-09-16
CVE-2012-2227 EXP Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local files via… Patch early 7.5 high 9.8% 2012-08-26
CVE-2001-0702 EXP Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long (1) username, (2) p… Patch early 7.5 high 9.8% 2001-09-20
CVE-2004-0069 EXP Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifie… Patch early 7.5 high 9.8% 2004-02-17
CVE-2002-0313 EXP Buffer overflow in Essentia Web Server 2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long URL. Patch early 7.5 high 9.8% 2002-06-25
CVE-2011-5167 EXP Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strateg… Patch early 9.3 high 9.8% 2012-09-15
CVE-2018-11479 EXP The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that establishes… Patch early 7.8 high 9.8% 2018-05-25
CVE-2019-6215 EXP A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for W… Patch early 8.8 high 9.8% 2019-03-05
CVE-2008-4694 EXP Unspecified vulnerability in Opera before 9.60 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via… Patch early 9.3 high 9.8% 2008-10-23
CVE-2013-3934 EXP Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allows remote attackers to execute… Patch early 9.3 high 9.8% 2013-09-10
CVE-2008-7103 EXP Stack-based buffer overflow in an ActiveX control in najdisitoolbar.dll in Najdi.si Toolbar 2.0.4.1 allows remote attackers to cause a denial of servi… Patch early 9.3 high 9.8% 2009-08-27
CVE-2016-4535 EXP Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to cause a denial of service (memo… Patch early 7.5 high 9.8% 2016-05-05
CVE-2006-1243 EXP Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitra… Patch early 7.5 high 9.7% 2006-03-15
CVE-2007-2584 EXP Buffer overflow in the IsOldAppInstalled function in the McSubMgr.McSubMgr Subscription Manager ActiveX control (MCSUBMGR.DLL) in McAfee SecurityCente… Patch early 10.0 high 9.7% 2007-05-10
CVE-2019-9832 EXP The AirDrop application through 2.0 for Android allows remote attackers to cause a denial of service via a client that makes many socket connections t… Patch early 7.5 high 9.7% 2019-03-15
CVE-1999-0879 EXP Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file. Patch early 10.0 high 9.7% 1999-10-01
CVE-2008-3702 EXP Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used in products such as SpeedBit… Patch early 9.3 high 9.7% 2008-08-15
CVE-2008-5406 EXP Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denial of service (application cras… Patch early 9.3 high 9.7% 2008-12-10
CVE-2008-5691 EXP Heap-based buffer overflow in the Phoenician Casino FlashAX ActiveX control 1.0.0.7 allows remote attackers to execute arbitrary code via a long argum… Patch early 9.3 high 9.7% 2008-12-19
CVE-2006-4968 EXP PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execute arbitrary PHP code via a UR… Patch early 7.5 high 9.7% 2006-09-25
CVE-2006-4913 EXP Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary local files an… Patch early 7.5 high 9.7% 2006-09-21
CVE-2019-11706 EXP A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages… Patch early 7.5 high 9.7% 2019-07-23
CVE-2019-16902 EXP In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying t… Patch early 7.5 high 9.7% 2019-09-27
CVE-2001-1246 EXP PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote… Patch early 7.5 high 9.7% 2001-06-30
CVE-2018-7254 EXP The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-r… Patch early 7.8 high 9.7% 2018-02-19
CVE-2023-37979 EXP Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions. Patch early 7.1 high 9.7% 2023-07-27
CVE-2017-11662 EXP The _WM_ParseNewMidi function in f_midi.c in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mi… Patch early 7.5 high 9.7% 2017-08-17
← previous page 154 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt