peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,286 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

150,481 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-6008 EXP install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands via the adminPassword paramete… Patch early 7.5 high 4.8% 2015-09-28
CVE-1999-0873 EXP Buffer overflow in Skyfull mail server via MAIL FROM command. Patch early 7.5 high 4.8% 1999-10-30
CVE-2009-1059 EXP Stack-based buffer overflow in Trident PowerZip 7.2 might allow remote attackers to execute arbitrary code via a crafted .zip file. NOTE: CVE has not… Patch early 9.3 high 4.8% 2009-03-24
CVE-2009-2961 EXP Stack-based buffer overflow in Thaddy de Konng KOL Player 1.0 allows remote attackers to cause a denial of service (crash) or execute arbitrary code v… Patch early 9.3 high 4.8% 2009-08-25
CVE-2009-3947 EXP Buffer overflow in the FTP service on the Tandberg MXP F7.0 allows remote attackers to cause a denial of service (process crash or device reboot) or p… Patch early 9.3 high 4.8% 2009-11-16
CVE-2009-4759 EXP Buffer overflow in BrotherSoft BMXPlay 0.4.4b allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary c… Patch early 9.3 high 4.8% 2010-03-29
CVE-2008-6932 EXP Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uploading a fi… Patch early 7.5 high 4.8% 2009-08-11
CVE-2008-2267 EXP Incomplete blacklist vulnerability in javaUpload.php in Postlet in the FileManager module in CMS Made Simple 1.2.4 and earlier allows remote attackers… Patch early 7.5 high 4.8% 2008-05-16
CVE-2009-3574 EXP Tuniac 090517c allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long File1 argument in a .pls pla… Patch early 9.3 high 4.8% 2009-10-06
CVE-2007-4754 EXP Format string vulnerability in the safe_bprintf function in acesrc/acebot_cmds.c in Alien Arena 2007 6.10 and earlier allows remote attackers to cause… Patch early 7.5 high 4.8% 2007-09-08
CVE-2008-1319 EXP Untrusted search path and argument injection vulnerability in the VersantD service in Versant Object Database 7.0.1.3 and earlier, as used in Borland… Patch early 9.3 high 4.8% 2008-03-13
CVE-2018-16071 EXP A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted video… Patch early 8.8 high 4.8% 2019-01-09
CVE-2016-1819 EXP Use-after-free vulnerability in the IOAccelContext2::clientMemoryForType method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and… Patch early 7.8 high 4.8% 2016-05-20
CVE-2005-0979 EXP Multiple buffer overflows in RUMBA 7.3 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted… Patch early 7.5 high 4.8% 2005-05-02
CVE-2013-7187 EXP SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL comma… Patch early 7.5 high 4.8% 2013-12-20
CVE-2008-4486 EXP Directory traversal vulnerability in index.php in SAC.php (SACphp), as used in Yerba 6.3 and earlier, allows remote attackers to include and execute a… Patch early 10.0 high 4.8% 2008-10-08
CVE-1999-0705 EXP Buffer overflow in INN inews program. Patch early 7.5 high 4.8% 1999-09-01
CVE-2006-4584 EXP Tr Forum 2.0 allows remote attackers to bypass authentication and add an administrative account via the login and password parameters to admin/insert_… Patch early 7.5 high 4.8% 2006-09-06
CVE-2008-2574 EXP Unrestricted file upload vulnerability in admin/Editor/imgupload.php in FlashBlog 0.31 beta allows remote attackers to execute arbitrary code by uploa… Patch early 7.5 high 4.8% 2008-06-06
CVE-2015-3315 EXP Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a sym… Patch early 7.8 high 4.8% 2017-06-26
CVE-2009-3254 EXP Multiple stack-based buffer overflows in Ultimate Player 1.56 beta allow remote attackers to execute arbitrary code via a long string in a (1) .m3u or… Patch early 9.3 high 4.8% 2009-09-18
CVE-2004-0261 EXP oj.cgi in OpenJournal 2.0 through 2.0.5 allows remote attackers to bypass authentication and access the control panel via a 0 in the uid parameter. Patch early 10.0 high 4.8% 2004-11-23
CVE-2004-1327 EXP Buffer overflow in Crystal FTP Client 2.8 allows remote malicious servers to execute arbitrary code via a response to a LIST command that contains a f… Patch early 7.5 high 4.8% 2004-12-31
CVE-2026-5027 EXP The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbi… Patch early 8.8 high 4.8% 2026-03-27
CVE-2017-2474 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchO… Patch early 7.8 high 4.8% 2017-04-02
CVE-2017-2478 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchO… Patch early 7.0 high 4.7% 2017-04-02
CVE-2007-1640 EXP Multiple PHP remote file inclusion vulnerabilities in ClassWeb 2.03 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 10.0 high 4.7% 2007-03-23
CVE-2007-0261 EXP snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administ… Patch early 10.0 high 4.7% 2007-01-16
CVE-2006-5552 EXP Multiple heap-based buffer overflows in RevilloC MailServer 1.21 and earlier allow remote attackers to cause a denial of service (CPU consumption or a… Patch early 7.5 high 4.7% 2006-10-26
CVE-2016-1821 EXP IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL point… Patch early 7.8 high 4.7% 2016-05-20
← previous page 219 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt