peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,556 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

320,600 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-0599 EXP Blahz-DNS 0.2 and earlier allows remote attackers to bypass authentication and modify configuration by directly requesting CGI programs such as dostuf… Patch early 10.0 high 11.5% 2002-06-18
CVE-2000-1014 EXP Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute arbitrary command… Patch early 7.5 high 11.5% 2000-12-11
CVE-2004-0816 EXP Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service (application c… Patch early 7.5 high 11.5% 2004-12-23
CVE-2000-0909 EXP Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long Fro… Patch early 7.5 high 11.5% 2000-12-19
CVE-2011-2543 EXP Buffer overflow in the cuil component in Cisco Telepresence System Integrator C Series 4.x before TC4.2.0 allows remote authenticated users to cause a… Patch early 9.0 high 11.5% 2011-09-23
CVE-2016-1610 EXP Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows re… Patch early 7.5 high 11.5% 2016-08-01
CVE-2018-15120 EXP libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application cras… Patch early 6.5 medium 11.5% 2018-08-24
CVE-2008-6222 EXP Directory traversal vulnerability in the Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 for Joomla! allows remote attackers to read arbi… Patch early 5.0 medium 11.5% 2009-02-20
CVE-2016-0070 EXP The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT… Patch early 5.5 medium 11.5% 2016-10-14
CVE-2006-2849 EXP PHP remote file inclusion vulnerability in includes/webdav/server.php in Bytehoard 2.1 Epsilon/Delta allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 11.5% 2006-06-06
CVE-2003-1425 EXP guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter. Patch early 10.0 high 11.5% 2003-12-31
CVE-2005-3486 EXP Multiple format string vulnerabilities in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole… Patch early 7.5 high 11.5% 2005-11-03
CVE-2009-4112 EXP Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memor… Patch early 9.0 high 11.5% 2009-11-30
CVE-2018-18428 EXP TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg URI. Patch early 7.5 high 11.5% 2018-10-19
CVE-2021-3337 EXP The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on repl… Patch early 7.5 high 11.5% 2021-01-28
CVE-2019-2697 EXP Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Diffic… Patch early 8.1 high 11.5% 2019-04-23
CVE-2000-0165 EXP The Delegate application proxy has several buffer overflows which allow a remote attacker to execute commands. Patch early 7.5 high 11.5% 1999-11-13
CVE-2007-1912 EXP Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file. Patch early 6.8 medium 11.5% 2007-04-10
CVE-2005-2616 EXP Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.ph… Patch early 7.5 high 11.5% 2005-08-17
CVE-2010-3682 EXP Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXP… Patch early 4.0 medium 11.4% 2011-01-11
CVE-2006-4832 EXP Buffer overflow in the telnet service in Verso NetPerformer FRAD ACT SDM-95xx 7.xx (R1) and earlier, SDM-93xx 10.x.x (R2) and earlier, and SDM-92xx 9.… Patch early 7.5 high 11.4% 2006-09-15
CVE-2012-3574 EXP Unrestricted file upload vulnerability in includes/doajaxfileupload.php in the MM Forms Community plugin 2.2.5 and 2.2.6 for WordPress allows remote a… Patch early 7.5 high 11.4% 2012-06-16
CVE-2001-1022 EXP Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option… Patch early 7.5 high 11.4% 2001-07-26
CVE-2015-3221 EXP OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated use… Patch early 4.0 medium 11.4% 2015-08-26
CVE-2014-9147 EXP Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/. Patch early 7.5 high 11.4% 2017-10-16
CVE-2010-1878 EXP Directory traversal vulnerability in the OrgChart (com_orgchart) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a ..… Patch early 7.5 high 11.4% 2010-05-12
CVE-2013-4788 EXP The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the ra… Patch early 5.1 medium 11.4% 2013-10-04
CVE-2019-9189 EXP Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central c… Patch early 8.8 high 11.4% 2019-06-05
CVE-2007-0107 EXP WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers… Patch early 6.8 medium 11.4% 2007-01-09
CVE-2002-0644 EXP Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members… Patch early 7.5 high 11.4% 2002-08-12
← previous page 192 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt