peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,941 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

150,376 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-2514 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" co… Patch early 8.8 high 6% 2017-05-22
CVE-2009-3810 EXP Heap-based buffer overflow in Acoustica MP3 Audio Mixer 2.471 allows remote attackers to cause a denial of service (crash) or execute arbitrary code v… Patch early 9.3 high 6% 2009-10-27
CVE-2022-35513 EXP The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage. Patch early 7.5 high 6% 2022-09-07
CVE-1999-0268 EXP MetaInfo MetaWeb web server allows users to upload, execute, and read scripts. Patch early 10.0 high 6% 1999-01-01
CVE-2021-28379 EXP web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different ori… Patch early 8.8 high 6% 2021-03-15
CVE-2025-32023 EXP Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use… Patch early 7.0 high 6% 2025-07-07
CVE-2015-7570 EXP Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate open… Patch early 7.2 high 6% 2017-04-24
CVE-2008-3209 EXP Heap-based buffer overflow in the OpenGifFile function in BiGif.dll in Black Ice Document Imaging SDK 10.95 allows remote attackers to execute arbitra… Patch early 9.3 high 6% 2008-07-18
CVE-2008-4548 EXP Stack-based buffer overflow in the PTZCamPanelCtrl ActiveX control (CamPanel.dll) in RTS Sentry 2.1.0.2 allows remote attackers to execute arbitrary c… Patch early 9.3 high 6% 2008-10-14
CVE-2017-17874 EXP Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can mak… Patch early 8.8 high 6% 2017-12-27
CVE-2006-2225 EXP Buffer overflow in XM Easy Personal FTP Server 4.3 and earlier allows remote attackers to execute arbitrary code, probably via a USER command with a l… Patch early 7.5 high 6% 2006-05-05
CVE-2006-2408 EXP Multiple buffer overflows in Raydium before SVN revision 310 allow remote attackers to execute arbitrary code via a large packet when logged via (1) t… Patch early 7.5 high 6% 2006-05-16
CVE-2001-0173 EXP Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execut… Patch early 10.0 high 6% 2001-05-03
CVE-2011-5006 EXP Stack-based buffer overflow in QQPlayer 3.2.845 allows remote attackers to execute arbitrary code via a crafted PnSize value in a MOV file. Patch early 9.3 high 6% 2011-12-25
CVE-2004-0241 EXP X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php. Patch early 10.0 high 6% 2004-11-23
CVE-2009-4754 EXP Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (… Patch early 9.3 high 6% 2010-03-29
CVE-2009-1071 EXP Stack-based buffer overflow in Icarus 2.0 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a cra… Patch early 9.3 high 6% 2009-03-26
CVE-2009-1327 EXP Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u)… Patch early 9.3 high 6% 2009-04-17
CVE-2008-3733 EXP Stack-based buffer overflow in EO Video (eo-video) 1.36 allows remote attackers to cause a denial of service (application crash) or execute arbitrary… Patch early 9.3 high 6% 2008-08-20
CVE-2007-6649 EXP PHP remote file inclusion vulnerability in includes/tumbnail.php in MatPo Bilder Galerie 1.1 allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 6% 2008-01-04
CVE-2007-6657 EXP PHP remote file inclusion vulnerability in source/includes/load_forum.php in Mihalism Multi Forum Host 3.0.x and earlier allows remote attackers to ex… Patch early 7.5 high 6% 2008-01-04
CVE-2004-0345 EXP Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name. Patch early 10.0 high 6% 2004-11-23
CVE-2008-7209 EXP Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows remote attackers to execute arbi… Patch early 7.5 high 6% 2009-09-11
CVE-2007-2667 EXP Buffer overflow in the DB Software Laboratory VImpX ActiveX control in VImpX.ocx 4.7.3 allows remote attackers to execute arbitrary code via a long Lo… Patch early 9.3 high 6% 2007-05-14
CVE-2008-2283 EXP IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEnhWMF methods in (a) the IDAuto… Patch early 9.3 high 6% 2008-05-18
CVE-2016-4312 EXP XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote auth… Patch early 7.5 high 6% 2017-02-17
CVE-2002-0747 EXP Buffer overflow in lsmcode in AIX 4.3.3. Patch early 10.0 high 6% 2002-08-12
CVE-2018-5708 EXP An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticated to, the administrator's pan… Patch early 8.0 high 6% 2018-03-30
CVE-2018-19550 EXP Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can c… Patch early 8.8 high 6% 2018-11-26
CVE-2007-6542 EXP PHP remote file inclusion vulnerability in admin/frontpage_right.php in Arcadem LE 2.04 and earlier allows remote attackers to execute arbitrary PHP c… Patch early 7.5 high 6% 2007-12-27
← previous page 200 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt