peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,373 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

187,440 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-0952 EXP An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hu… Patch early 7.8 high 6.2% 2018-08-15
CVE-2009-3969 EXP Stack-based buffer overflow in Faslo Player 7.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… Patch early 9.3 high 6.2% 2009-11-18
CVE-2003-1313 EXP Multiple PHP remote file inclusion vulnerabilities in EternalMart Mailing List Manager (EMLM) 1.32 allow remote attackers to execute arbitrary PHP cod… Patch early 7.5 high 6.2% 2003-12-31
CVE-1999-0997 EXP wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program… Patch early 7.5 high 6.2% 1999-12-20
CVE-2007-0504 EXP Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to execute arbitrary code via the… Patch early 10.0 high 6.2% 2007-01-26
CVE-1999-0210 EXP Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters. Patch early 10.0 high 6.2% 1997-11-26
CVE-2007-2568 EXP Multiple stack-based buffer overflows in VCDGear 3.55 allow user-assisted remote attackers to execute arbitrary code via a long (1) tag or (2) track t… Patch early 9.3 high 6.2% 2007-05-16
CVE-2017-7049 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 8.8 high 6.2% 2017-07-20
CVE-2015-2824 EXP Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL co… Patch early 7.5 high 6.2% 2015-04-06
CVE-2019-10866 EXP In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-ma… Patch early 9.8 critical 6.2% 2019-05-23
CVE-2009-3838 EXP Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash)… Patch early 9.3 high 6.2% 2009-11-02
CVE-2020-20969 EXP File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file. Patch early 7.2 high 6.2% 2023-06-20
CVE-2004-1303 EXP Buffer overflow in the get function in get.c for Yanf 0.4 allows remote malicious web servers to execute arbitrary code via crafted HTTP responses. Patch early 10.0 high 6.2% 2005-01-10
CVE-2009-0422 EXP Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is disabled, allows remote attackers… Patch early 7.5 high 6.2% 2009-02-05
CVE-2007-6273 EXP Multiple format string vulnerabilities in the configuration file in SonicWALL GLobal VPN Client 3.1.556 and 4.0.0.810 allow user-assisted remote attac… Patch early 9.3 high 6.2% 2007-12-07
CVE-2002-0942 EXP Buffer overflows in Lugiment Log Explorer before 3.02 allow attackers with database permissions to execute arbitrary code via long arguments to the ex… Patch early 7.5 high 6.2% 2002-10-04
CVE-2009-2382 EXP admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access by setting the PHPMYBCAdmin co… Patch early 9.8 critical 6.2% 2009-07-08
CVE-2007-0466 EXP Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 allows remote attackers to execute arbitrary code via a crafted ASF_File_Propertie… Patch early 10.0 high 6.2% 2007-01-31
CVE-2024-24409 EXP Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option. Patch early 8.8 high 6.2% 2024-11-08
CVE-2009-0262 EXP Stack-based buffer overflow in Triologic Media Player 7 and 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string… Patch early 9.3 high 6.2% 2009-01-23
CVE-2018-10018 EXP The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a long IsBlackListed argument. Patch early 8.8 high 6.2% 2018-07-13
CVE-2006-7032 EXP PHP remote file inclusion vulnerability in phpbb/getmsg.php in FlashBB 1.1.5 and earlier allows remote attackers to execute arbitrary code via a URL i… Patch early 10.0 high 6.2% 2007-02-23
CVE-2009-2568 EXP Stack-based buffer overflow in Sorinara Streaming Audio Player (SAP) 0.9 allows remote attackers to execute arbitrary code via a long string in a play… Patch early 9.3 high 6.2% 2009-07-22
CVE-2022-47076 EXP An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via DisplayParallelLogData.aspx. Patch early 7.5 high 6.2% 2023-02-28
CVE-2009-1743 EXP Directory traversal vulnerability in InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows… Patch early 9.3 high 6.2% 2009-05-21
CVE-2000-0828 EXP Buffer overflow in ddicgi.exe in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long User-Agen… Patch early 10.0 high 6.2% 2000-11-14
CVE-2007-1412 EXP The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensitive information (script source… Patch early 7.8 high 6.2% 2007-03-12
CVE-1999-0287 EXP Vulnerability in the Wguest CGI program. Patch early 7.5 high 6.2% 1999-04-09
CVE-2004-1301 EXP Buffer overflow in the book_format_sql function in format.c for xlreader 0.9.0 allows remote attackers to execute arbitrary code via a crafted Excel (… Patch early 10.0 high 6.2% 2005-01-10
CVE-2006-3491 EXP Stack-based buffer overflow in Kaillera Server 0.86 and earlier allows remote attackers to execute arbitrary code via a long nickname. Patch early 7.5 high 6.2% 2006-07-10
← previous page 249 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt