peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,829 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

187,214 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-4323 EXP Heap-based buffer overflow in novell-tftp.exe in Novell ZENworks Configuration Manager (ZCM) 10.3.1, 10.3.2, and 11.0, and earlier versions, allows re… Patch early 7.5 high 8.1% 2011-02-19
CVE-2023-1934 EXP The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Pres… Patch early 9.8 critical 8.1% 2023-05-12
CVE-2017-9742 EXP The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and appl… Patch early 7.8 high 8.1% 2017-06-19
CVE-2017-9750 EXP opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers to cause a denial of service (b… Patch early 7.8 high 8.1% 2017-06-19
CVE-2017-9756 EXP The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overf… Patch early 7.8 high 8.1% 2017-06-19
CVE-2005-3405 EXP ATutor 1.4.1 through 1.5.1-pl1 allows remote attackers to execute arbitrary PHP functions via a direct request to forum.inc.php with a modified addsla… Patch early 7.5 high 8.1% 2005-11-01
CVE-2008-0729 EXP Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion and device crash) via certain Ja… Patch early 7.1 high 8.1% 2008-02-12
CVE-2006-1749 EXP PHP remote file inclusion vulnerability in config.php in phpListPro 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the retu… Patch early 7.5 high 8.1% 2006-04-12
CVE-2003-0304 EXP one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Ins… Patch early 10.0 high 8.1% 2003-06-09
CVE-1999-1508 EXP Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented UR… Patch early 10.0 high 8.1% 1999-11-16
CVE-2018-7316 EXP Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action. Patch early 9.8 critical 8.1% 2018-02-22
CVE-2014-4912 EXP An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation. Patch early 9.8 critical 8.1% 2018-03-22
CVE-2015-1371 EXP Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code by uploading a file with an exe… Patch early 7.5 high 8.1% 2015-01-27
CVE-2000-1093 EXP Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command. Patch early 7.5 high 8.1% 2001-01-09
CVE-1999-1521 EXP Computalynx CMail 2.4 and CMail 2.3 SP2 SMTP servers are vulnerable to a buffer overflow attack in the MAIL FROM command that may allow a remote attac… Patch early 10.0 high 8.1% 1999-09-12
CVE-2008-0763 EXP Stack-based buffer overflow in NPSpcSVR.exe in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier allows remote attackers to execute arb… Patch early 10.0 high 8.1% 2008-02-13
CVE-2002-1656 EXP X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via sniffing or th… Patch early 7.5 high 8.1% 2002-12-31
CVE-2017-14523 EXP WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that ex… Patch early 7.5 high 8% 2018-01-26
CVE-2017-6823 EXP Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action. Patch early 8.8 high 8% 2017-03-12
CVE-2007-0873 EXP nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) config_ed… Patch early 7.5 high 8% 2007-02-12
CVE-2017-2491 EXP Use after free vulnerability in the String.replace method JavaScriptCore in Apple Safari in iOS before 10.3 allows remote attackers to execute arbitra… Patch early 8.8 high 8% 2017-06-27
CVE-2007-2371 EXP admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows re… Patch early 10.0 high 8% 2007-04-30
CVE-2013-1638 EXP Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document. Patch early 9.3 high 8% 2013-02-08
CVE-2007-2317 EXP Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other products, allow… Patch early 7.5 high 8% 2007-04-26
CVE-2007-2891 EXP Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_da… Patch early 7.5 high 8% 2007-05-30
CVE-2002-0733 EXP Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, whi… Patch early 7.5 high 8% 2002-08-12
CVE-2007-2429 EXP ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for t… Patch early 10.0 high 8% 2007-05-02
CVE-2017-7056 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 8.8 high 8% 2017-07-20
CVE-2008-3317 EXP admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrar… Patch early 7.5 high 8% 2008-07-25
CVE-2008-2888 EXP Multiple PHP remote file inclusion vulnerabilities in MiGCMS 2.0.5, when register_globals is enabled, allow remote attackers to execute arbitrary PHP… Patch early 10.0 high 8% 2008-06-27
← previous page 221 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt