peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,522 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

186,622 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2001-0280 EXP Buffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command. Patch early 10.0 high 13% 2001-05-03
CVE-2007-4034 EXP Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPC… Patch early 9.3 high 13% 2007-07-27
CVE-2009-2511 EXP Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, a… Patch early 7.5 high 13% 2009-10-14
CVE-2019-15039 EXP An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1. Patch early 9.8 critical 12.9% 2019-10-01
CVE-2010-2626 EXP index.pl in Miyabi CGI Tools SEO Links 1.02 allows remote attackers to execute arbitrary commands via shell metacharacters in the fn command. NOTE: so… Patch early 7.5 high 12.9% 2010-07-02
CVE-2024-27746 EXP SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email ad… Patch early 9.8 critical 12.9% 2024-03-01
CVE-2005-4466 EXP Heap-based buffer overflow in the SIPParser function in i3sipmsg.dll in Interaction SIP Proxy before 3.0.011 allows remote attackers to cause a denial… Patch early 7.5 high 12.9% 2005-12-22
CVE-2006-7079 EXP Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables a… Patch early 9.8 critical 12.9% 2007-03-02
CVE-2019-9491 EXP Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the… Patch early 7.8 high 12.9% 2019-10-21
CVE-2005-2277 EXP Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file… Patch early 10.0 high 12.9% 2005-07-15
CVE-2003-1177 EXP Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute a… Patch early 7.5 high 12.9% 2003-12-31
CVE-2009-4653 EXP Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to cause a denial of servic… Patch early 9.0 high 12.9% 2010-02-26
CVE-2015-7258 EXP ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by displaying u… Patch early 8.8 high 12.9% 2017-08-24
CVE-2017-16929 EXP The remote management interface on the Claymore Dual GPU miner 10.1 is vulnerable to an authenticated directory traversal vulnerability exploited by i… Patch early 8.1 high 12.9% 2017-12-05
CVE-2021-46354 EXP Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Ad… Patch early 7.5 high 12.9% 2022-02-09
CVE-2003-0720 EXP Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type. Patch early 7.5 high 12.9% 2003-09-17
CVE-1999-1576 EXP Buffer overflow in Adobe Acrobat ActiveX control (pdf.ocx, PDF.PdfCtrl.1) 1.3.188 for Acrobat Reader 4.0 allows remote attackers to execute arbitrary… Patch early 7.5 high 12.9% 1999-09-27
CVE-2000-0065 EXP Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request. Patch early 10.0 high 12.9% 2000-01-17
CVE-2000-0091 EXP Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password. Patch early 10.0 high 12.9% 2000-01-21
CVE-2012-2619 EXP The Broadcom BCM4325 and BCM4329 Wi-Fi chips, as used in certain Acer, Apple, Asus, Ford, HTC, Kyocera, LG, Malata, Motorola, Nokia, Pantech, Samsung,… Patch early 7.8 high 12.9% 2012-11-14
CVE-1999-0208 EXP rpc.ypupdated (NIS) allows remote users to execute arbitrary commands. Patch early 10.0 high 12.9% 1995-12-12
CVE-2022-2840 EXP The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via vario… Patch early 9.8 critical 12.9% 2022-09-19
CVE-2019-8689 EXP Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watc… Patch early 8.8 high 12.9% 2019-12-18
CVE-2013-1916 EXP In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server h… Patch early 8.8 high 12.8% 2022-06-24
CVE-2005-1349 EXP Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter to a read o… Patch early 7.5 high 12.8% 2005-05-02
CVE-2024-25832 EXP F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous typ… Patch early 8.8 high 12.8% 2024-02-29
CVE-2016-3376 EXP The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R… Patch early 7.8 high 12.8% 2016-10-14
CVE-2007-5607 EXP Buffer overflow in the RegistryString function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1… Patch early 7.5 high 12.8% 2008-06-04
CVE-2007-3697 EXP PHP remote file inclusion vulnerability in phpbb/sendmsg.php in FlashBB 1.1.8 and earlier allows remote attackers to execute arbitrary code via a URL… Patch early 7.5 high 12.8% 2007-07-11
CVE-1999-0896 EXP Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and passwo… Patch early 10.0 high 12.8% 1999-11-04
← previous page 177 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt