peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,011 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

403,011 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2003-0720 EXP Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type. Patch early 7.5 high 12.9% 2003-09-17
CVE-1999-1576 EXP Buffer overflow in Adobe Acrobat ActiveX control (pdf.ocx, PDF.PdfCtrl.1) 1.3.188 for Acrobat Reader 4.0 allows remote attackers to execute arbitrary… Patch early 7.5 high 12.9% 1999-09-27
CVE-2019-1245 EXP An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosu… Patch early 6.5 medium 12.9% 2019-09-11
CVE-2020-29395 EXP The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field. Patch early 6.1 medium 12.9% 2020-11-30
CVE-2011-2505 EXP libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns valu… Patch early 6.4 medium 12.9% 2011-07-14
CVE-2000-0065 EXP Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request. Patch early 10.0 high 12.9% 2000-01-17
CVE-2000-0091 EXP Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password. Patch early 10.0 high 12.9% 2000-01-21
CVE-2003-1505 EXP Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a textarea in… Patch early 4.3 medium 12.9% 2003-12-31
CVE-2008-5587 EXP Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers… Patch early 4.3 medium 12.9% 2008-12-16
CVE-2002-2073 EXP Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arb… Patch early 4.3 medium 12.9% 2002-12-31
CVE-2012-2619 EXP The Broadcom BCM4325 and BCM4329 Wi-Fi chips, as used in certain Acer, Apple, Asus, Ford, HTC, Kyocera, LG, Malata, Motorola, Nokia, Pantech, Samsung,… Patch early 7.8 high 12.9% 2012-11-14
CVE-2021-24926 EXP The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a… Patch early 6.1 medium 12.9% 2022-02-01
CVE-1999-0208 EXP rpc.ypupdated (NIS) allows remote users to execute arbitrary commands. Patch early 10.0 high 12.9% 1995-12-12
CVE-2019-8689 EXP Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watc… Patch early 8.8 high 12.9% 2019-12-18
CVE-2012-2371 EXP Cross-site scripting (XSS) vulnerability in index.php in the WP-FaceThumb plugin 0.1 for WordPress allows remote attackers to inject arbitrary web scr… Patch early 4.3 medium 12.8% 2012-08-13
CVE-2013-1916 EXP In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server h… Patch early 8.8 high 12.8% 2022-06-24
CVE-2005-0710 EXP MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restricti… Patch early 4.6 medium 12.8% 2005-05-02
CVE-2005-1349 EXP Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter to a read o… Patch early 7.5 high 12.8% 2005-05-02
CVE-2000-0156 EXP Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source R… Patch early 5.1 medium 12.8% 2000-02-16
CVE-1999-0281 EXP Denial of service in IIS using long URLs. Patch early 5.0 medium 12.8% 1997-06-01
CVE-2024-25832 EXP F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous typ… Patch early 8.8 high 12.8% 2024-02-29
CVE-2005-2629 EXP Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitr… Patch early 5.1 medium 12.8% 2005-11-18
CVE-2016-3376 EXP The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R… Patch early 7.8 high 12.8% 2016-10-14
CVE-2007-5607 EXP Buffer overflow in the RegistryString function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1… Patch early 7.5 high 12.8% 2008-06-04
CVE-2007-3697 EXP PHP remote file inclusion vulnerability in phpbb/sendmsg.php in FlashBB 1.1.8 and earlier allows remote attackers to execute arbitrary code via a URL… Patch early 7.5 high 12.8% 2007-07-11
CVE-1999-0896 EXP Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and passwo… Patch early 10.0 high 12.8% 1999-11-04
CVE-2004-2275 EXP i-mall.cgi in I-Mall Commerce allows remote attackers to execute arbitrary commands via shell metacharacters via the p parameter. Patch early 10.0 high 12.8% 2004-12-31
CVE-2018-9022 EXP An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands… Patch early 9.8 critical 12.8% 2018-06-18
CVE-2018-6911 EXP The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argumen… Patch early 9.8 critical 12.8% 2018-02-13
CVE-2008-0443 EXP Heap-based buffer overflow in the FileUploader.FUploadCtl.1 ActiveX control in FileUploader.dll 2.0.0.2 in Lycos FileUploader Module allows remote att… Patch early 10.0 high 12.8% 2008-01-25
← previous page 227 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt