peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,488 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

149,881 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-2961 EXP Buffer overflow in the get_string_ahref function for ProZilla 1.3.7.4 and possibly earlier, with the -ftpsearch option enabled, allows remote servers… Patch early 7.5 high 8.6% 2005-10-05
CVE-2007-2776 EXP AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, whi… Patch early 10.0 high 8.6% 2007-05-21
CVE-2020-9372 EXP The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to b… Patch early 7.8 high 8.6% 2020-03-04
CVE-2007-4737 EXP Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code… Patch early 7.5 high 8.6% 2007-09-06
CVE-2017-6367 EXP In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology involves a long Host header and an… Patch early 7.5 high 8.6% 2017-03-14
CVE-2005-0879 EXP PHP remote file include vulnerability in (1) content.php and (2) index.php for Vortex Portal allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 8.6% 2005-05-02
CVE-2020-5752 EXP Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands w… Patch early 7.8 high 8.6% 2020-05-21
CVE-2008-7124 EXP zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain ad… Patch early 7.5 high 8.6% 2009-08-31
CVE-2009-1549 EXP AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto." Patch early 7.5 high 8.6% 2009-05-06
CVE-1999-0953 EXP WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers. Patch early 10.0 high 8.6% 1999-09-16
CVE-2003-0143 EXP The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authentic… Patch early 10.0 high 8.6% 2003-03-18
CVE-2003-1148 EXP Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and po… Patch early 7.5 high 8.6% 2003-10-25
CVE-2007-0614 EXP The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a… Patch early 7.8 high 8.6% 2007-01-31
CVE-2008-6953 EXP Buffer overflow in oovoo.exe in ooVoo 1.7.1.35, and possibly other versions before 1.7.1.59, allows remote attackers to cause a denial of service (cra… Patch early 9.3 high 8.6% 2009-08-12
CVE-2002-0962 EXP Cross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via (1) the url variable in the L… Patch early 7.5 high 8.6% 2002-10-04
CVE-2003-0651 EXP Buffer overflow in the mylo_log logging function for mod_mylo 0.2.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET… Patch early 7.5 high 8.6% 2003-08-27
CVE-2018-4200 EXP An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud before 7.5 on Windows is affe… Patch early 8.8 high 8.6% 2018-06-08
CVE-2009-1830 EXP Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long search query. Patch early 10.0 high 8.6% 2009-05-29
CVE-2010-1176 EXP Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… Patch early 9.3 high 8.6% 2010-03-29
CVE-2019-3999 EXP Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to exe… Patch early 7.8 high 8.6% 2020-02-25
CVE-2008-0127 EXP The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute ar… Patch early 8.8 high 8.6% 2008-01-10
CVE-2014-6389 EXP backup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the d parameter. Patch early 7.5 high 8.6% 2014-10-06
CVE-2014-9144 EXP Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metacharacters in the ping field (s… Patch early 7.5 high 8.6% 2014-12-05
CVE-2010-1685 EXP Stack-based buffer overflow in CursorArts ZipWrangler 1.20 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing a… Patch early 9.3 high 8.6% 2010-05-04
CVE-2008-0379 EXP Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to c… Patch early 9.3 high 8.6% 2008-01-22
CVE-2008-6833 EXP Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and execute arbitrary local files… Patch early 10.0 high 8.6% 2009-06-22
CVE-2012-0406 EXP The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a deni… Patch early 7.8 high 8.6% 2012-04-20
CVE-2002-0955 EXP Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execute arbitra… Patch early 7.5 high 8.6% 2002-10-04
CVE-2010-1132 EXP The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute… Patch early 9.3 high 8.5% 2010-03-27
CVE-2007-2536 EXP PicoZip allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous fil… Patch early 7.8 high 8.5% 2007-05-09
← previous page 166 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt