peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,999 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

150,377 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2020-5509 EXP PHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile image. Patch early 7.2 high 5.8% 2020-01-14
CVE-2007-6402 EXP Stack-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote attackers… Patch early 9.3 high 5.8% 2007-12-17
CVE-2014-5083 EXP A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a remote mali… Patch early 8.8 high 5.8% 2020-02-10
CVE-2014-5085 EXP A Command Execution vulnerability exists in Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote maliciou… Patch early 8.8 high 5.8% 2020-02-10
CVE-2003-0380 EXP Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of service (crash)… Patch early 7.5 high 5.8% 2003-07-02
CVE-2008-1920 EXP Heap-based buffer overflow in the boxelyRenderer module in the Personal Status Manager feature in ICQ 6.0 build 6043 allows remote attackers to cause… Patch early 7.5 high 5.8% 2008-04-23
CVE-2007-2820 EXP Multiple stack-based buffer overflows in the KSign KSignSWAT ActiveX Control (AxKSignSWAT.dll) 2.0.3.3 allow remote attackers to execute arbitrary cod… Patch early 7.5 high 5.8% 2007-05-22
CVE-2002-0900 EXP Buffer overflow in pks PGP public key web server before 0.9.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitr… Patch early 7.5 high 5.8% 2002-10-04
CVE-2007-1141 EXP PHP remote file inclusion vulnerability in preview.php in Magic News Plus 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 5.8% 2007-03-02
CVE-2000-0166 EXP Buffer overflow in the InterAccess telnet server TelnetD allows remote attackers to execute commands via a long login name. Patch early 10.0 high 5.8% 2000-02-21
CVE-2000-0425 EXP Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands. Patch early 10.0 high 5.8% 2000-05-03
CVE-2021-3394 EXP Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder permissions allowing a malicious… Patch early 8.8 high 5.8% 2021-02-09
CVE-2005-1413 EXP Multiple SQL injection vulnerabilities in enVivo!CMS allow remote attackers to execute arbitrary SQL commands and gain privileges via the (1) username… Patch early 7.5 high 5.8% 2005-05-03
CVE-2013-5692 EXP Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files… Patch early 8.5 high 5.8% 2013-09-30
CVE-2009-3670 EXP Stack-based buffer overflow in KSP Sound Player 2009 R2 and R2.1 allows remote attackers to execute arbitrary code via a long string in a .m3u playlis… Patch early 9.3 high 5.8% 2009-10-11
CVE-2009-4964 EXP Stack-based buffer overflow in KSP 2006 FINAL allows remote attackers to execute arbitrary code via a long string in a .M3U playlist file. Patch early 9.3 high 5.8% 2010-07-28
CVE-2008-6897 EXP Multiple buffer overflows in Getleft.exe in Andres Garcia Getleft 1.2 allow remote attackers to cause a denial of service (crash) and possibly execute… Patch early 9.3 high 5.8% 2009-08-05
CVE-2009-3338 EXP Stack-based buffer overflow in EffectMatrix (E.M.) Magic Morph 1.95b allows remote attackers to execute arbitrary code via a long string in a .mor fil… Patch early 9.3 high 5.8% 2009-09-24
CVE-2017-13784 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 5.8% 2017-11-13
CVE-2017-13785 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 5.8% 2017-11-13
CVE-2017-13792 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 5.8% 2017-11-13
CVE-2017-13795 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 5.8% 2017-11-13
CVE-2017-13802 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 5.8% 2017-11-13
CVE-2005-3558 EXP PHP file inclusion vulnerability in index.php in OSTE 1.0 allows remote attackers to execute arbitrary code via the (1) page and (2) site parameters. Patch early 7.5 high 5.8% 2005-11-16
CVE-2006-1839 EXP PHP remote file inclusion vulnerability in language.php in PHP Album 0.3.2.3, when register_globals is enabled, allows remote attackers to execute arb… Patch early 7.5 high 5.8% 2006-04-19
CVE-2008-6983 EXP modules/tool/hitcounter.php in devalcms 1.4a allows remote attackers to execute arbitrary PHP code via the HTTP Referer header with a target file spec… Patch early 7.5 high 5.8% 2009-08-19
CVE-2008-0148 EXP TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a… Patch early 10.0 high 5.8% 2008-01-09
CVE-2008-4321 EXP Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long response to the PWD command. Patch early 9.3 high 5.8% 2008-09-29
CVE-2003-1142 EXP Help in NIPrint LPD-LPR Print Server 4.10 and earlier executes Windows Explorer with SYSTEM privileges, which allows local users to gain privileges. Patch early 10.0 high 5.8% 2003-11-03
CVE-2016-1828 EXP The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a… Patch early 7.8 high 5.8% 2016-05-20
← previous page 204 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt