peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,546 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

320,042 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-1933 EXP Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to overwrite arbitrary files via the… Patch early 4.3 medium 13.9% 2008-04-25
CVE-2008-2666 EXP Multiple directory traversal vulnerabilities in PHP 5.2.6 and earlier allow context-dependent attackers to bypass safe_mode restrictions by creating a… Patch early 5.0 medium 13.9% 2008-06-20
CVE-2005-1275 EXP Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of servic… Patch early 5.0 medium 13.9% 2005-04-25
CVE-2010-2028 EXP Buffer overflow in k23productions TFTPUtil GUI (aka TFTPGUI) 1.4.5 allows remote attackers to cause a denial of service (crash) and possibly execute a… Patch early 10.0 high 13.9% 2010-05-24
CVE-2024-28999 EXP The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console. Patch early 6.4 medium 13.9% 2024-06-04
CVE-2005-1598 EXP SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted co… Patch early 7.5 high 13.9% 2005-05-16
CVE-2006-1985 EXP Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to exe… Patch early 5.1 medium 13.9% 2006-04-21
CVE-2019-1149 EXP A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who succes… Patch early 8.8 high 13.9% 2019-08-14
CVE-2019-3810 EXP A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did n… Patch early 6.1 medium 13.9% 2019-03-25
CVE-2001-0129 EXP Buffer overflow in Tinyproxy HTTP proxy 1.3.3 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands… Patch early 10.0 high 13.9% 2001-03-12
CVE-2002-0187 EXP Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root pa… Patch early 7.5 high 13.9% 2002-07-03
CVE-2000-0260 EXP Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the "Link Vi… Patch early 7.5 high 13.9% 2000-04-14
CVE-2004-1364 EXP Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bi… Patch early 8.5 high 13.9% 2004-08-04
CVE-2012-4330 EXP The Samsung D6000 TV and possibly other products allows remote attackers to cause a denial of service (crash) via a long string in certain fields, as… Patch early 7.8 high 13.9% 2012-08-14
CVE-2009-1257 EXP Heap-based buffer overflow in Magic ISO Maker 5.5 build 0274 allows remote attackers to cause a denial of service (crash) or execute arbitrary code vi… Patch early 9.0 high 13.9% 2009-04-07
CVE-2000-0002 EXP Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request. Patch early 10.0 high 13.9% 1999-12-22
CVE-2005-3077 EXP Microsoft Internet Explorer 5.2.3 for Mac OS allows remote attackers to cause a denial of service (crash) via a web page with malformed attributes in… Patch early 5.0 medium 13.9% 2005-09-27
CVE-2019-6545 EXP AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update.… Patch early 7.5 high 13.9% 2019-02-13
CVE-2006-5536 EXP Directory traversal vulnerability in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to read arbitrary fil… Patch early 5.0 medium 13.9% 2006-10-26
CVE-2013-6127 EXP The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict Rep… Patch early 5.8 medium 13.9% 2013-10-25
CVE-2010-3127 EXP Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5 allows local users, and possibly remote attackers, to execute arbitrary code an… Patch early 9.3 high 13.9% 2010-08-26
CVE-2010-3426 EXP Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and ex… Patch early 7.5 high 13.9% 2010-09-16
CVE-2007-1562 EXP The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to ot… Patch early 6.8 medium 13.8% 2007-03-21
CVE-2011-4875 EXP Stack-based buffer overflow in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP,… Patch early 9.3 high 13.8% 2012-02-03
CVE-2002-1076 EXP Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET reque… Patch early 7.5 high 13.8% 2002-10-04
CVE-2017-9347 EXP In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/asn1/ros/packet-ros-… Patch early 7.5 high 13.8% 2017-06-02
CVE-2007-1492 EXP winmm.dll in Microsoft Windows XP allows user-assisted remote attackers to cause a denial of service (infinite loop) via a large cch argument value to… Patch early 7.1 high 13.8% 2007-03-16
CVE-2007-3997 EXP The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir res… Patch early 7.5 high 13.8% 2007-09-04
CVE-2004-0189 EXP The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") charact… Patch early 7.5 high 13.8% 2004-03-15
CVE-2006-1510 EXP Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 a… Patch early 4.0 medium 13.8% 2006-03-30
← previous page 172 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt