peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,011 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

150,377 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-1825 EXP IOHIDFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corru… Patch early 7.8 high 5.6% 2016-05-20
CVE-2009-3484 EXP Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code via a long hostname in an FTP s… Patch early 9.3 high 5.6% 2009-09-30
CVE-2017-13056 EXP The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file. Patch early 7.8 high 5.6% 2017-12-27
CVE-2014-8356 EXP The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modif… Patch early 8.8 high 5.6% 2019-11-21
CVE-2018-10260 EXP A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user. Patch early 8.8 high 5.6% 2018-05-01
CVE-2011-1513 EXP Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, all… Patch early 7.5 high 5.6% 2011-11-04
CVE-2009-0731 EXP Directory traversal vulnerability in pages/play.php in Free Arcade Script 1.0 allows remote attackers to include and execute arbitrary local files via… Patch early 9.3 high 5.6% 2009-02-24
CVE-2012-4864 EXP Oreans WinLicense 2.1.8.0 allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a… Patch early 9.3 high 5.6% 2012-09-06
CVE-2002-0907 EXP Buffer overflow in SHOUTcast 1.8.9 and other versions before 1.8.12 allows a remote authenticated DJ to execute arbitrary code on the server via a lon… Patch early 7.5 high 5.6% 2002-10-04
CVE-2008-6563 EXP Buffer overflow in the XML parser in Trillian 3.1.9.0, and possibly earlier, allows remote attackers to cause a denial of service (crash) and possibly… Patch early 9.3 high 5.6% 2009-03-31
CVE-2002-1904 EXP Buffer overflow in the Log function in util.c in GazTek ghttpd 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a long HTTP GET… Patch early 7.5 high 5.6% 2002-12-31
CVE-2005-1784 EXP Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in… Patch early 7.5 high 5.6% 2005-05-27
CVE-2005-3304 EXP Multiple SQL injection vulnerabilities in PHP-Nuke 7.8 allow remote attackers to modify SQL queries and execute arbitrary PHP code via (1) the usernam… Patch early 7.5 high 5.6% 2005-10-26
CVE-2018-4193 EXP An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Windows Server" component. It allows atta… Patch early 7.8 high 5.6% 2018-06-08
CVE-2008-2573 EXP Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a long directory name in an SSH_… Patch early 8.5 high 5.6% 2008-06-06
CVE-2003-0803 EXP Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED acces… Patch early 7.5 high 5.6% 2003-10-06
CVE-2003-0586 EXP Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php. Patch early 7.5 high 5.6% 2003-08-18
CVE-2006-2411 EXP Buffer overflow in raydium_network_read function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to execute arbitrary cod… Patch early 7.5 high 5.6% 2006-05-16
CVE-2017-15035 EXP EmTec PyroBatchFTP before 3.18 allows remote servers to cause a denial of service (application crash). Patch early 7.5 high 5.6% 2017-10-05
CVE-2009-4216 EXP Directory traversal vulnerability in funzioni/lib/menulast.php in klinza professional cms 5.0.1 and earlier allows remote attackers to include and exe… Patch early 9.3 high 5.6% 2009-12-07
CVE-2016-1827 EXP The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a… Patch early 7.8 high 5.6% 2016-05-20
CVE-2006-2645 EXP PHP remote file inclusion vulnerability in manager/frontinc/prepend.php for Plume 1.0.3 allows remote attackers to execute arbitrary code via a URL in… Patch early 7.5 high 5.6% 2006-05-30
CVE-2000-0343 EXP Buffer overflow in Sniffit 0.3.x with the -L logging option enabled allows remote attackers to execute arbitrary commands via a long MAIL FROM mail he… Patch early 10.0 high 5.6% 2000-05-02
CVE-2007-0766 EXP Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of service (application crash) a… Patch early 9.3 high 5.6% 2007-02-06
CVE-2013-4091 EXP The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocomplete attribute for the passwo… Patch early 7.5 high 5.6% 2013-06-28
CVE-2002-0895 EXP Buffer overflow in MatuFtpServer 1.1.3.0 (1.1.3) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long P… Patch early 7.5 high 5.6% 2002-10-04
CVE-2007-5824 EXP webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon cr… Patch early 7.1 high 5.6% 2007-11-05
CVE-2009-4836 EXP Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbitrary PHP code via the anticod… Patch early 7.5 high 5.6% 2010-05-06
CVE-2009-4668 EXP Stack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute arbitrary code via a long ID3… Patch early 9.3 high 5.6% 2010-03-05
CVE-2010-2331 EXP Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to execute arbitrary code via a long HEAD request. Patch early 9.3 high 5.6% 2010-06-18
← previous page 207 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt