peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,674 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

187,135 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2000-0017 EXP Buffer overflow in Linux linuxconf package allows remote attackers to gain root privileges via a long parameter. Patch early 10.0 high 8.9% 1999-12-21
CVE-2007-2363 EXP Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file. Patch early 8.5 high 8.9% 2007-04-30
CVE-2013-3541 EXP Directory traversal vulnerability in cgi-bin/admin/fileread in AirLive WL2600CAM and possibly other camera models allows remote attackers to read arbi… Patch early 7.8 high 8.9% 2013-10-04
CVE-2018-5954 EXP phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect commands. Patch early 7.5 high 8.9% 2018-01-25
CVE-2017-15644 EXP SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000. Patch early 8.6 high 8.9% 2017-10-19
CVE-2010-2045 EXP Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Joomla! allows remote attackers to… Patch early 7.5 high 8.9% 2010-05-25
CVE-2013-6830 EXP admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attackers to execute arbitrary command… Patch early 7.5 high 8.9% 2013-11-20
CVE-2019-2107 EXP In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code e… Patch early 8.8 high 8.9% 2019-07-08
CVE-2007-4338 EXP index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's na… Patch early 10.0 high 8.9% 2007-08-14
CVE-2010-2300 EXP Use-after-free vulnerability in the Element::normalizeAttributes function in dom/Element.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 a… Patch early 10.0 high 8.9% 2010-06-15
CVE-2010-1179 EXP Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… Patch early 9.3 high 8.9% 2010-03-29
CVE-2006-4160 EXP Multiple PHP remote file inclusion vulnerabilities in Tony Bibbs and Vincent Furia MVCnPHP 3.0 allow remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 8.9% 2006-08-16
CVE-2001-0899 EXP Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variable. Patch early 7.5 high 8.9% 2001-11-16
CVE-2016-8377 EXP An issue was discovered in Fatek Automation PLC WinProladder Version 3.11 Build 14701. A stack-based buffer overflow vulnerability exists when the sof… Patch early 8.0 high 8.9% 2017-02-13
CVE-2012-4750 EXP A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, which could let a remote malicio… Patch early 9.8 critical 8.9% 2020-01-13
CVE-2001-1291 EXP The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or pass… Patch early 9.8 critical 8.9% 2001-07-12
CVE-2022-2591 EXP A vulnerability classified as critical has been found in TEM FLEX-1085 1.6.0. Affected is an unknown function of the file /sistema/flash/reboot. The m… Patch early 7.5 high 8.9% 2022-08-01
CVE-2009-3658 EXP Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory… Patch early 8.8 high 8.9% 2009-10-09
CVE-2012-1563 EXP Joomla! before 2.5.3 allows Admin Account Creation. Patch early 7.5 high 8.9% 2020-01-15
CVE-2006-4131 EXP Multiple buffer overflows in ArcSoft MMS Composer 1.5.5.6, and possibly earlier, and 2.0.0.13, and possibly earlier, allow remote attackers to cause a… Patch early 7.5 high 8.9% 2006-08-14
CVE-2006-5472 EXP PHP remote file inclusion vulnerability in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 8.9% 2006-10-24
CVE-2017-7042 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 8.8 high 8.9% 2017-07-20
CVE-2008-0485 EXP Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV… Patch early 9.3 high 8.9% 2008-02-05
CVE-2007-0976 EXP Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary code via a long DVD_TOOLS.OpenDVD… Patch early 10.0 high 8.9% 2007-02-16
CVE-2009-0134 EXP Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers t… Patch early 9.3 high 8.9% 2009-01-16
CVE-2001-0766 EXP Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some character… Patch early 9.8 critical 8.9% 2001-10-18
CVE-1999-0283 EXP The Java Web Server would allow remote users to obtain the source code for CGI programs. Patch early 10.0 high 8.9% 1999-01-01
CVE-2015-7894 EXP The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allows remote attackers to cause a… Patch early 8.8 high 8.9% 2017-08-09
CVE-2022-1631 EXP Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, the… Patch early 8.8 high 8.9% 2022-05-09
CVE-2004-2443 EXP Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null pa… Patch early 7.5 high 8.8% 2004-12-31
← previous page 211 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt