peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,295 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

186,519 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2001-0050 EXP Buffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary commands via an IP address th… Patch early 10.0 high 14.6% 2001-02-16
CVE-2008-0296 EXP Heap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC Media Player 0.8.6d and earlier on Windows might allow remote RTSP servers… Patch early 10.0 high 14.6% 2008-01-16
CVE-2013-2567 EXP An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.co… Patch early 7.5 high 14.6% 2020-01-29
CVE-2006-3890 EXP Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, al… Patch early 9.3 high 14.6% 2006-11-21
CVE-2005-2878 EXP Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via form… Patch early 7.5 high 14.6% 2005-09-13
CVE-2017-11152 EXP Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write… Patch early 7.5 high 14.6% 2017-08-08
CVE-2010-2743 EXP The kernel-mode drivers in Microsoft Windows XP SP3 do not properly perform indexing of a function-pointer table during the loading of keyboard layout… Patch early 7.2 high 14.6% 2011-01-20
CVE-2024-46987 EXP Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. A path traversal vulnerability accessible via MediaController… Patch early 7.7 high 14.6% 2024-09-18
CVE-2001-0233 EXP Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a… Patch early 10.0 high 14.6% 2001-03-26
CVE-2018-20219 EXP An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an authentication c… Patch early 8.1 high 14.6% 2019-03-21
CVE-2004-1627 EXP Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long APPE com… Patch early 7.5 high 14.5% 2004-10-22
CVE-2006-5567 EXP Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via a crafted (… Patch early 9.3 high 14.5% 2006-10-27
CVE-2008-0339 EXP Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack v… Patch early 10.0 high 14.5% 2008-01-17
CVE-2017-2641 EXP In Moodle 2.x and 3.x, SQL injection can occur via user preferences. Patch early 9.8 critical 14.5% 2017-03-26
CVE-2006-2667 EXP Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriag… Patch early 7.5 high 14.5% 2006-05-30
CVE-2005-1306 EXP The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containi… Patch early 7.5 high 14.5% 2005-06-15
CVE-2017-16352 EXP GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the Describ… Patch early 8.8 high 14.5% 2017-11-01
CVE-2018-19585 EXP GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when usi… Patch early 7.5 high 14.5% 2019-05-17
CVE-2003-0865 EXP Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a long request. Patch early 7.5 high 14.5% 2003-11-17
CVE-2023-33440 EXP Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user. Patch early 7.2 high 14.5% 2023-05-26
CVE-2008-4762 EXP Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service crash) and potentially execute a… Patch early 9.0 high 14.5% 2008-10-28
CVE-2006-2362 EXP Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-depen… Patch early 7.3 high 14.5% 2006-05-15
CVE-2007-1561 EXP The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE mess… Patch early 7.8 high 14.5% 2007-03-21
CVE-2014-4170 EXP A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script,… Patch early 9.8 critical 14.5% 2020-02-13
CVE-2005-0245 EXP Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcurso… Patch early 7.5 high 14.5% 2005-02-01
CVE-2018-9248 EXP FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header. Patch early 9.8 critical 14.5% 2018-04-04
CVE-2019-8044 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 9.8 critical 14.5% 2019-08-20
CVE-2004-1284 EXP Buffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafted MP3 play… Patch early 10.0 high 14.5% 2005-01-10
CVE-2019-3025 EXP Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Food and Beverage Applications. The supported version that is affected is 5.7. Di… Patch early 9.0 critical 14.5% 2019-10-16
CVE-2001-0815 EXP Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitrary code via an HTTP request fo… Patch early 7.5 high 14.4% 2001-12-06
← previous page 167 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt