peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,674 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

187,135 results

CVESummaryPriorityCVSSEPSSPublished
CVE-1999-0953 EXP WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers. Patch early 10.0 high 8.6% 1999-09-16
CVE-2003-1148 EXP Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and po… Patch early 7.5 high 8.6% 2003-10-25
CVE-2007-0614 EXP The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a… Patch early 7.8 high 8.6% 2007-01-31
CVE-2008-6953 EXP Buffer overflow in oovoo.exe in ooVoo 1.7.1.35, and possibly other versions before 1.7.1.59, allows remote attackers to cause a denial of service (cra… Patch early 9.3 high 8.6% 2009-08-12
CVE-2002-0962 EXP Cross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via (1) the url variable in the L… Patch early 7.5 high 8.6% 2002-10-04
CVE-2003-0651 EXP Buffer overflow in the mylo_log logging function for mod_mylo 0.2.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET… Patch early 7.5 high 8.6% 2003-08-27
CVE-2018-4200 EXP An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud before 7.5 on Windows is affe… Patch early 8.8 high 8.6% 2018-06-08
CVE-2017-17110 EXP Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request. Patch early 9.8 critical 8.6% 2017-12-11
CVE-2018-11736 EXP An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the… Patch early 9.8 critical 8.6% 2018-06-05
CVE-2023-27290 EXP Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require… Patch early 9.1 critical 8.6% 2023-03-03
CVE-2009-1830 EXP Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long search query. Patch early 10.0 high 8.6% 2009-05-29
CVE-2010-1176 EXP Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… Patch early 9.3 high 8.6% 2010-03-29
CVE-2019-3999 EXP Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to exe… Patch early 7.8 high 8.6% 2020-02-25
CVE-2008-0127 EXP The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute ar… Patch early 8.8 high 8.6% 2008-01-10
CVE-2014-6389 EXP backup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the d parameter. Patch early 7.5 high 8.6% 2014-10-06
CVE-2014-9144 EXP Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metacharacters in the ping field (s… Patch early 7.5 high 8.6% 2014-12-05
CVE-2010-1685 EXP Stack-based buffer overflow in CursorArts ZipWrangler 1.20 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing a… Patch early 9.3 high 8.6% 2010-05-04
CVE-2008-0379 EXP Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to c… Patch early 9.3 high 8.6% 2008-01-22
CVE-2008-6833 EXP Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and execute arbitrary local files… Patch early 10.0 high 8.6% 2009-06-22
CVE-2012-0406 EXP The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a deni… Patch early 7.8 high 8.6% 2012-04-20
CVE-2002-0955 EXP Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execute arbitra… Patch early 7.5 high 8.6% 2002-10-04
CVE-2010-1132 EXP The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute… Patch early 9.3 high 8.5% 2010-03-27
CVE-2007-2536 EXP PicoZip allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous fil… Patch early 7.8 high 8.5% 2007-05-09
CVE-2014-3437 EXP The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requ… Patch early 7.5 high 8.5% 2014-11-07
CVE-2018-10575 EXP An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged S… Patch early 9.8 critical 8.5% 2018-04-30
CVE-2006-3970 EXP PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows remote attackers to execute arb… Patch early 7.5 high 8.5% 2006-08-01
CVE-2000-0187 EXP EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metachar… Patch early 7.5 high 8.5% 2000-02-27
CVE-2008-0396 EXP Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Ente… Patch early 7.8 high 8.5% 2008-01-23
CVE-2017-2800 EXP A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate vali… Patch early 9.8 critical 8.5% 2017-05-24
CVE-2008-1262 EXP The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote… Patch early 10.0 high 8.5% 2008-03-10
← previous page 215 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt