peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,553 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

320,595 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2003-1090 EXP Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title. Patch early 10.0 high 11.6% 2003-02-06
CVE-2009-3859 EXP Buffer overflow in eEye Retina WiFi Scanner 1.0.8.68, as used in Retina Network Security Scanner 5.10.14, allows user-assisted remote attackers to cau… Patch early 9.3 high 11.6% 2009-11-04
CVE-2002-0591 EXP Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute co… Patch early 5.0 medium 11.6% 2002-06-18
CVE-2009-1574 EXP racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a… Patch early 5.0 medium 11.6% 2009-05-06
CVE-2008-4116 EXP Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbit… Patch early 9.3 high 11.6% 2008-09-18
CVE-2019-19731 EXP Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE acti… Patch early 7.5 high 11.6% 2019-12-16
CVE-2003-0129 EXP Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that i… Patch early 5.0 medium 11.6% 2003-03-24
CVE-2011-4189 EXP The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corrup… Patch early 7.5 high 11.6% 2012-03-02
CVE-2019-8925 EXP An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerability in the Administration zon… Patch early 4.3 medium 11.6% 2019-05-17
CVE-1999-0710 EXP The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attacker… Patch early 7.5 high 11.6% 1999-07-25
CVE-2002-1456 EXP Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value. Patch early 7.5 high 11.6% 2003-06-09
CVE-2004-1147 EXP phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands vi… Patch early 10.0 high 11.6% 2005-01-10
CVE-2007-2209 EXP Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.20 and possibly other products… Patch early 6.8 medium 11.6% 2007-04-24
CVE-2007-0233 EXP wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matchi… Patch early 7.5 high 11.6% 2007-01-13
CVE-2014-9014 EXP Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allo… Patch early 4.3 medium 11.6% 2019-11-06
CVE-2022-22833 EXP An issue was discovered in Servisnet Tessa 0.0.2. An attacker can obtain sensitive information via a /js/app.js request. Patch early 7.5 high 11.6% 2022-02-06
CVE-2015-4181 EXP Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 7.5 high 11.6% 2017-08-25
CVE-2012-1125 EXP Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 for WordPress allows remote atta… Patch early 6.8 medium 11.6% 2012-10-08
CVE-2008-7257 EXP CRLF injection vulnerability in +webvpn+/index.html in WebVPN on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1… Patch early 4.3 medium 11.6% 2010-06-29
CVE-2003-0263 EXP Multiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitrary code via long (1) MAIL FRO… Patch early 7.5 high 11.6% 2003-05-27
CVE-2013-7186 EXP Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long string in a .m3u file. Patch early 9.3 high 11.6% 2013-12-20
CVE-2013-2261 EXP Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure Patch early 7.5 high 11.6% 2019-11-04
CVE-2007-4254 EXP Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Designer 7.0 for Microsoft Visual St… Patch early 6.8 medium 11.5% 2007-08-08
CVE-2018-10517 EXP In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploit… Patch early 7.2 high 11.5% 2018-04-27
CVE-2008-0944 EXP Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote attackers to cause a denial of service (NULL dereference and application crash) via… Patch early 5.0 medium 11.5% 2008-02-25
CVE-2019-6273 EXP download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files. Patch early 6.5 medium 11.5% 2019-03-21
CVE-1999-0284 EXP Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. Patch early 7.5 high 11.5% 1998-01-01
CVE-2010-0397 EXP The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, w… Patch early 5.0 medium 11.5% 2010-03-16
CVE-2009-0544 EXP Buffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large… Patch early 10.0 high 11.5% 2009-02-12
CVE-2008-1289 EXP Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x b… Patch early 7.5 high 11.5% 2008-03-24
← previous page 191 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt