peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,829 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

320,901 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-4018 EXP The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and… Patch early 7.5 high 11.3% 2009-11-29
CVE-2007-1421 EXP Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root… Patch early 10.0 high 11.3% 2007-03-13
CVE-2008-2595 EXP Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.4.2 has unknown impact a… Patch early 5.0 medium 11.3% 2008-07-15
CVE-2007-0243 EXP Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and… Patch early 6.8 medium 11.3% 2007-01-17
CVE-2007-0126 EXP Heap-based buffer overflow in Opera 9.02 allows remote attackers to execute arbitrary code via a JPEG file with an invalid number of index bytes in th… Patch early 9.3 high 11.3% 2007-01-09
CVE-2010-3154 EXP Untrusted search path vulnerability in Adobe Extension Manager CS5 5.0.298 allows local users, and possibly remote attackers, to execute arbitrary cod… Patch early 9.3 high 11.3% 2010-08-27
CVE-2010-0416 EXP Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix Player 1.0.6 and RealPlayer al… Patch early 7.5 high 11.3% 2010-02-18
CVE-2007-2583 EXP The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a deni… Patch early 4.0 medium 11.3% 2007-05-10
CVE-2022-2552 EXP The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server… Patch early 5.3 medium 11.3% 2022-08-22
CVE-2015-7039 EXP Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbit… Patch early 6.8 medium 11.3% 2015-12-11
CVE-2008-1461 EXP Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the command line. NO… Patch early 7.6 high 11.3% 2008-03-24
CVE-2006-4089 EXP Multiple buffer overflows in Andy Lo-A-Foe AlsaPlayer 0.99.76 and earlier allow remote attackers to cause a denial of service (application crash), or… Patch early 5.0 medium 11.3% 2006-08-11
CVE-2010-3870 EXP The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, whic… Patch early 6.8 medium 11.3% 2010-11-12
CVE-2006-2223 EXP RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authent… Patch early 5.0 medium 11.3% 2006-05-05
CVE-2006-4920 EXP Multiple PHP remote file inclusion vulnerabilities in Site@School (S@S) 2.4.02 and earlier allow remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 11.3% 2006-09-21
CVE-2017-2370 EXP An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. wa… Patch early 7.8 high 11.3% 2017-02-20
CVE-2019-10009 EXP A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to preview an uploa… Patch early 6.5 medium 11.3% 2019-06-03
CVE-2008-4547 EXP Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows remote attackers to execute a… Patch early 9.3 high 11.3% 2008-10-14
CVE-2017-9812 EXP The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Ma… Patch early 7.5 high 11.3% 2017-07-17
CVE-2017-16953 EXP connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration o… Patch early 7.5 high 11.3% 2017-12-01
CVE-2002-0613 EXP dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user_logged_in or… Patch early 10.0 high 11.3% 2002-06-18
CVE-2020-15261 EXP On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally authenticated users with administr… Patch early 8.0 high 11.3% 2020-10-19
CVE-2007-4005 EXP Stack-based buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 allows remote attackers to execute arbitrary code via a long string to the sh… Patch early 5.0 medium 11.2% 2007-07-26
CVE-2004-1789 EXP Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to inject arbitrary web script or H… Patch early 4.3 medium 11.2% 2004-12-31
CVE-2021-24488 EXP The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being out… Patch early 6.1 medium 11.2% 2021-08-02
CVE-2019-6274 EXP Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified impa… Patch early 8.8 high 11.2% 2019-03-21
CVE-2025-2126 EXP A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the fi… Patch early 6.3 medium 11.2% 2025-03-09
CVE-2004-1584 EXP CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HT… Patch early 5.0 medium 11.2% 2004-12-31
CVE-2009-4880 EXP Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attacker… Patch early 5.0 medium 11.2% 2010-06-01
CVE-2013-5660 EXP Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file. Patch early 9.3 high 11.2% 2014-04-25
← previous page 194 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt