peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,108 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

150,428 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2003-0320 EXP header.php in ttCMS 2.3 and earlier allows remote attackers to inject arbitrary PHP code by setting the ttcms_user_admin parameter to "1" and modifyin… Patch early 7.5 high 5.3% 2003-06-09
CVE-2007-5265 EXP Multiple format string vulnerabilities in websrv.cpp in Dawn of Time 1.69s beta4 and earlier allow remote attackers to execute arbitrary code via form… Patch early 7.5 high 5.3% 2007-10-08
CVE-2009-1039 EXP Buffer overflow in CDex 1.70b2 allows remote attackers to execute arbitrary code via a crafted Info header in an Ogg Vorbis (.ogg) file. Patch early 7.5 high 5.3% 2009-03-20
CVE-2023-21752 EXP Windows Backup Service Elevation of Privilege Vulnerability Patch early 7.1 high 5.3% 2023-01-10
CVE-2024-11237 EXP A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this issue is some unknown functio… Patch early 7.5 high 5.3% 2024-11-15
CVE-2008-6186 EXP Stack-based buffer overflow in RaidenFTPD 2.4 build 3620 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary c… Patch early 9.0 high 5.3% 2009-02-19
CVE-2008-6899 EXP Multiple buffer overflows in freeSSHd 1.2.1 allow remote authenticated users to cause a denial of service (crash) and execute arbitrary code via a lon… Patch early 9.0 high 5.3% 2009-08-05
CVE-2007-5332 EXP Multiple unspecified vulnerabilities in (1) mediasvr and (2) caloggerd in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10… Patch early 10.0 high 5.3% 2007-10-13
CVE-2010-1686 EXP Stack-based buffer overflow in (1) Urgent Backup 3.20, and (2) ABC Backup Pro 5.20 and ABC Backup 5.50, allows user-assisted remote attackers to execu… Patch early 9.3 high 5.3% 2010-05-05
CVE-2002-0002 EXP Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to exec… Patch early 7.5 high 5.3% 2002-01-31
CVE-2013-4695 EXP Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution Patch early 7.8 high 5.3% 2019-12-27
CVE-2020-10883 EXP This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. A… Patch early 7.8 high 5.3% 2020-03-25
CVE-2009-0351 EXP Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argument beginn… Patch early 9.0 high 5.3% 2009-01-29
CVE-2008-5073 EXP Heap-based buffer overflow in an ActiveX control in Novell ZENworks Desktop Management 6.5 allows remote attackers to execute arbitrary code via a lon… Patch early 9.3 high 5.3% 2008-11-14
CVE-2018-16083 EXP An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of… Patch early 8.8 high 5.3% 2019-01-09
CVE-2004-0648 EXP Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referen… Patch early 10.0 high 5.3% 2004-08-06
CVE-2017-13797 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 5.3% 2017-11-13
CVE-2008-4247 EXP ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple co… Patch early 7.5 high 5.3% 2008-09-25
CVE-2016-1767 EXP QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafte… Patch early 7.8 high 5.3% 2016-03-24
CVE-2016-1769 EXP QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafte… Patch early 7.8 high 5.3% 2016-03-24
CVE-2015-4614 EXP Multiple SQL injection vulnerabilities in includes/Function.php in the Easy2Map plugin before 1.2.5 for WordPress allow remote attackers to execute ar… Patch early 7.5 high 5.2% 2015-07-08
CVE-2003-1431 EXP Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via a long host string in th… Patch early 7.1 high 5.2% 2003-12-31
CVE-2006-0685 EXP The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allo… Patch early 10.0 high 5.2% 2006-02-15
CVE-2015-8664 EXP Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 47.0.2526.106 allows remote att… Patch early 8.8 high 5.2% 2015-12-24
CVE-2004-1466 EXP The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds after they have been uploaded… Patch early 7.5 high 5.2% 2004-12-31
CVE-2010-4879 EXP PHP remote file inclusion vulnerability in dompdf.php in dompdf 0.6.0 beta1 allows remote attackers to execute arbitrary PHP code via a URL in the inp… Patch early 7.5 high 5.2% 2011-10-07
CVE-2008-1866 EXP admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload… Patch early 9.0 high 5.2% 2008-04-17
CVE-2022-31325 EXP There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php. Patch early 7.2 high 5.2% 2022-06-08
CVE-1999-0765 EXP SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor. Patch early 10.0 high 5.2% 1999-05-19
CVE-2016-3962 EXP Stack-based buffer overflow in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME… Patch early 7.3 high 5.2% 2016-07-03
← previous page 212 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt