peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,371 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

149,835 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-1179 EXP Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… Patch early 9.3 high 8.9% 2010-03-29
CVE-2006-4160 EXP Multiple PHP remote file inclusion vulnerabilities in Tony Bibbs and Vincent Furia MVCnPHP 3.0 allow remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 8.9% 2006-08-16
CVE-2001-0899 EXP Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variable. Patch early 7.5 high 8.9% 2001-11-16
CVE-2016-8377 EXP An issue was discovered in Fatek Automation PLC WinProladder Version 3.11 Build 14701. A stack-based buffer overflow vulnerability exists when the sof… Patch early 8.0 high 8.9% 2017-02-13
CVE-2022-2591 EXP A vulnerability classified as critical has been found in TEM FLEX-1085 1.6.0. Affected is an unknown function of the file /sistema/flash/reboot. The m… Patch early 7.5 high 8.9% 2022-08-01
CVE-2009-3658 EXP Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory… Patch early 8.8 high 8.9% 2009-10-09
CVE-2012-1563 EXP Joomla! before 2.5.3 allows Admin Account Creation. Patch early 7.5 high 8.9% 2020-01-15
CVE-2006-4131 EXP Multiple buffer overflows in ArcSoft MMS Composer 1.5.5.6, and possibly earlier, and 2.0.0.13, and possibly earlier, allow remote attackers to cause a… Patch early 7.5 high 8.9% 2006-08-14
CVE-2006-5472 EXP PHP remote file inclusion vulnerability in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 8.9% 2006-10-24
CVE-2017-7042 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 8.8 high 8.9% 2017-07-20
CVE-2008-0485 EXP Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV… Patch early 9.3 high 8.9% 2008-02-05
CVE-2007-0976 EXP Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary code via a long DVD_TOOLS.OpenDVD… Patch early 10.0 high 8.9% 2007-02-16
CVE-2009-0134 EXP Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers t… Patch early 9.3 high 8.9% 2009-01-16
CVE-1999-0283 EXP The Java Web Server would allow remote users to obtain the source code for CGI programs. Patch early 10.0 high 8.9% 1999-01-01
CVE-2015-7894 EXP The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allows remote attackers to cause a… Patch early 8.8 high 8.9% 2017-08-09
CVE-2022-1631 EXP Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, the… Patch early 8.8 high 8.9% 2022-05-09
CVE-2004-2443 EXP Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null pa… Patch early 7.5 high 8.8% 2004-12-31
CVE-2001-0507 EXP IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka th… Patch early 7.2 high 8.8% 2001-09-20
CVE-1999-0204 EXP Sendmail 8.6.9 allows remote attackers to execute root commands, using ident. Patch early 10.0 high 8.8% 1997-01-01
CVE-2008-2214 EXP Stack-based buffer overflow in the Network Manager in Castle Rock Computing SNMPc 7.1 and earlier allows remote attackers to cause a denial of service… Patch early 10.0 high 8.8% 2008-05-14
CVE-2017-8311 EXP Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to e… Patch early 7.8 high 8.8% 2017-05-23
CVE-2013-2267 EXP PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system. Patch early 7.2 high 8.8% 2020-01-27
CVE-2014-2846 EXP Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remot… Patch early 7.5 high 8.8% 2014-04-28
CVE-2004-1259 EXP Multiple buffer overflows in the handle_directive function in abcpp.c for abcpp 1.3.0 allow remote attackers to execute arbitrary code via crafted ABC… Patch early 10.0 high 8.8% 2005-01-10
CVE-2004-1261 EXP Multiple buffer overflows in the preparse function in asp2php 0.76.23 allow remote attackers to execute arbitrary code via crafted ASP scripts. Patch early 10.0 high 8.8% 2005-01-10
CVE-2004-1298 EXP Buffer overflow in the parse function in vb2c.c for vb2c 0.02 allows remote attackers to execute arbitrary code via a crafted FRM file. Patch early 10.0 high 8.8% 2005-01-10
CVE-2026-27483 EXP MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability in… Patch early 8.8 high 8.8% 2026-02-24
CVE-2007-5610 EXP The DeleteSingleFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows re… Patch early 10.0 high 8.8% 2008-06-04
CVE-2008-0953 EXP The StartApp function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote att… Patch early 10.0 high 8.8% 2008-06-04
CVE-2015-7112 EXP The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code i… Patch early 9.3 high 8.8% 2015-12-11
← previous page 163 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt