peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,573 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

186,640 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2011-4620 EXP Buffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products, allows user-assisted remote a… Patch early 9.3 high 12.6% 2011-12-31
CVE-2017-14459 EXP An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a… Patch early 10.0 critical 12.6% 2018-04-11
CVE-1999-0977 EXP Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request. Patch early 10.0 high 12.6% 1999-12-10
CVE-2000-0743 EXP Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a DES key generation request (G… Patch early 10.0 high 12.6% 2000-10-20
CVE-2013-0804 EXP The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of ser… Patch early 10.0 high 12.6% 2013-02-24
CVE-2015-2844 EXP The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arbitrary commands via the $actio… Patch early 10.0 high 12.6% 2015-05-12
CVE-2001-0700 EXP Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MIME header. Patch early 7.5 high 12.6% 2001-09-20
CVE-2013-6881 EXP CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell metacharacters in the… Patch early 10.0 high 12.6% 2014-01-07
CVE-2007-6638 EXP March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user… Patch early 10.0 high 12.6% 2008-01-04
CVE-2019-11444 EXP An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be ex… Patch early 7.2 high 12.6% 2019-04-22
CVE-2018-11509 EXP ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from t… Patch early 9.8 critical 12.6% 2018-08-16
CVE-2001-0022 EXP simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the guestbook parameter… Patch early 10.0 high 12.6% 2001-02-12
CVE-2014-6435 EXP cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remote attackers… Patch early 7.5 high 12.6% 2018-01-12
CVE-1999-1063 EXP CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter. Patch early 10.0 high 12.6% 1999-06-01
CVE-2018-19861 EXP Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request. NOTE: this product is… Patch early 9.8 critical 12.6% 2019-01-03
CVE-2018-19862 EXP Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST request. NOTE: this product is… Patch early 9.8 critical 12.6% 2019-01-03
CVE-2011-0489 EXP The server components in Objectivity/DB 10.0 do not require authentication for administrative commands, which allows remote attackers to modify data,… Patch early 7.5 high 12.6% 2011-01-18
CVE-2018-8898 EXP A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer=… Patch early 9.8 critical 12.5% 2018-05-23
CVE-2018-10285 EXP The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attack… Patch early 9.8 critical 12.5% 2018-04-22
CVE-2019-6272 EXP Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code. Patch early 8.8 high 12.5% 2019-03-21
CVE-2019-6275 EXP Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code… Patch early 8.8 high 12.5% 2019-03-21
CVE-2001-0561 EXP Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack… Patch early 7.5 high 12.5% 2001-08-14
CVE-2014-8675 EXP Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which allows remote attackers to obtain… Patch early 7.5 high 12.5% 2017-08-31
CVE-2007-0981 EXP Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the sam… Patch early 7.5 high 12.5% 2007-02-16
CVE-2019-19774 EXP An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /e… Patch early 8.8 high 12.5% 2019-12-13
CVE-2017-5630 EXP PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which all… Patch early 7.5 high 12.5% 2017-02-01
CVE-2017-17976 EXP In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution. Patch early 9.8 critical 12.5% 2018-01-26
CVE-2010-3124 EXP Untrusted search path vulnerability in bin/winvlc.c in VLC Media Player 1.1.3 and earlier allows local users, and possibly remote attackers, to execut… Patch early 9.3 high 12.5% 2010-08-26
CVE-2018-10070 EXP A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU and all available RAM by sendin… Patch early 7.5 high 12.5% 2018-04-16
CVE-2008-1193 EXP Unspecified vulnerability in Java Runtime Environment Image Parsing Library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier,… Patch early 9.3 high 12.5% 2008-03-06
← previous page 179 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt