peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,746 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

321,607 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-9767 EXP Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a c… Patch early 7.8 high 8% 2019-03-14
CVE-2002-0741 EXP psyBNC 2.3 allows remote attackers to cause a denial of service (CPU consumption and resource exhaustion) by sending a PASS command with a long passwo… Patch early 5.0 medium 8% 2002-08-12
CVE-2013-5123 EXP The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perfor… Patch early 5.9 medium 8% 2019-11-05
CVE-2004-0580 EXP DHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly clear previously used buffer con… Patch early 5.0 medium 8% 2004-08-06
CVE-2006-4611 EXP Buffer overflow in the _tor_resolve function in dsocks.c in dsocks before 1.4 allows remote attackers to execute arbitrary code via unspecified vector… Patch early 7.5 high 8% 2006-09-07
CVE-2006-4125 EXP Stack-based buffer overflow in main.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to execute arbitrary code via a large nickname, whi… Patch early 7.5 high 8% 2006-08-14
CVE-2008-0399 EXP Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arb… Patch early 6.8 medium 8% 2008-01-23
CVE-2006-4952 EXP The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail… Patch early 7.5 high 8% 2006-09-23
CVE-2006-4954 EXP The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information… Patch early 7.5 high 8% 2006-09-23
CVE-2002-1652 EXP Buffer overflow in cgicso.c for cgiemail 1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a lo… Patch early 7.5 high 8% 2002-12-31
CVE-2000-0652 EXP IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which co… Patch early 5.0 medium 8% 2000-07-24
CVE-2009-4840 EXP Heap-based buffer overflow in the IAManager ActiveX control in IAManager.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code… Patch early 9.3 high 8% 2010-05-06
CVE-2015-3000 EXP SysAid Help Desk before 15.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of nested entity ref… Patch early 7.8 high 8% 2015-06-08
CVE-2001-1109 EXP Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST,… Patch early 7.5 high 8% 2001-09-12
CVE-2003-0409 EXP Buffer overflow in BRS WebWeaver 1.04 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via… Patch early 10.0 high 8% 2003-06-30
CVE-2004-2117 EXP Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via malformed HTTP requests such as (1) a GET request without the HTTP ve… Patch early 5.0 medium 8% 2004-01-24
CVE-2012-0789 EXP Memory leak in the timezone functionality in PHP before 5.3.9 allows remote attackers to cause a denial of service (memory consumption) by triggering… Patch early 5.0 medium 8% 2012-02-14
CVE-2013-6227 EXP Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5.0.4 allow… Patch early 7.5 high 8% 2014-12-27
CVE-2007-1060 EXP Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl are enabled,… Patch early 6.8 medium 8% 2007-02-22
CVE-2019-9766 EXP Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a c… Patch early 7.8 high 8% 2019-03-14
CVE-2000-0705 EXP ntop running in web mode allows remote attackers to read arbitrary files via a .. (dot dot) attack. Patch early 5.0 medium 8% 2000-10-20
CVE-2017-7061 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 8.8 high 8% 2017-07-20
CVE-2000-1177 EXP bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows remote attackers to determine… Patch early 5.0 medium 8% 2001-01-09
CVE-2004-0293 EXP Directory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP request to (1) g… Patch early 5.0 medium 8% 2004-11-23
CVE-2004-0327 EXP Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequen… Patch early 5.0 medium 8% 2004-11-23
CVE-2022-29457 EXP Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure dur… Patch early 8.8 high 7.9% 2022-04-18
CVE-2008-1055 EXP Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to… Patch early 7.5 high 7.9% 2008-02-27
CVE-2015-2125 EXP Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote authenticated users to bypass intended access restricti… Patch early 4.0 medium 7.9% 2015-06-07
CVE-2025-52089 EXP A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arbi… Patch early 8.8 high 7.9% 2025-07-11
CVE-2002-0504 EXP Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers… Patch early 7.5 high 7.9% 2002-08-12
← previous page 248 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt