peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,887 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

321,703 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-5764 EXP Micro Focus Rumba FTP 4.X client buffer overflow makes it possible to corrupt the stack and allow arbitrary code execution. Fixed in: Rumba FTP 4.5 (H… Patch early 8.8 high 7.8% 2016-10-27
CVE-2009-5026 EXP The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave i… Patch early 6.8 medium 7.8% 2012-08-17
CVE-2006-3323 EXP PHP remote file inclusion vulnerability in admin/admin.php in MF Piadas 1.0 allows remote attackers to execute arbitrary PHP code via the page paramet… Patch early 7.5 high 7.8% 2006-06-30
CVE-2003-1263 EXP ICAL.EXE in iCal 3.7 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, possibly due to an invalid method name… Patch early 5.0 medium 7.8% 2003-12-31
CVE-2011-5012 EXP Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflection 2008, Re… Patch early 10.0 high 7.8% 2011-12-25
CVE-2005-1703 EXP Warrior Kings: Battles 1.23 and earlier allows remote attackers to cause a denial of service (server crash) via a partial join packet that triggers a… Patch early 5.0 medium 7.7% 2005-05-24
CVE-2009-4541 EXP Multiple PHP remote file inclusion vulnerabilities in IsolSoft Support Center 2.5 allow remote attackers to execute arbitrary PHP code via a URL in th… Patch early 7.5 high 7.7% 2010-01-04
CVE-2000-0937 EXP Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allo… Patch early 7.5 high 7.7% 2000-12-19
CVE-2008-4514 EXP The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a font tag with a long color value… Patch early 5.0 medium 7.7% 2008-10-09
CVE-2012-2271 EXP Buffer overflow in the InitLicenKeys function in a certain ActiveX control in SkinCrafter3_vs2005.dll in SkinCrafter 3.0 allows remote attackers to ex… Patch early 10.0 high 7.7% 2012-05-21
CVE-2004-2507 EXP Absolute path traversal vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to read arbitrary files v… Patch early 5.0 medium 7.7% 2004-12-31
CVE-2004-2107 EXP Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use… Patch early 7.5 high 7.7% 2004-12-31
CVE-2012-3585 EXP Heap-based buffer overflow in jpeg_ls.dll in the Jpeg_LS (aka JLS) plugin in the formats plugins in IrfanView PlugIns before 4.34 allows remote attack… Patch early 9.3 high 7.7% 2012-07-05
CVE-2014-5084 EXP A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let a remote malicious user execut… Patch early 8.8 high 7.7% 2020-02-10
CVE-2011-4643 EXP Multiple directory traversal vulnerabilities in Splunk 4.x before 4.2.5 allow remote authenticated users to read arbitrary files via a .. (dot dot) in… Patch early 4.0 medium 7.7% 2012-01-03
CVE-2006-4850 EXP PHP remote file inclusion vulnerability in system/_b/contentFiles/gBIndex.php in BolinOS 4.5.5 and earlier allows remote attackers to execute arbitrar… Patch early 5.1 medium 7.7% 2006-09-19
CVE-2005-3487 EXP Multiple buffer overflows in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole::addLine, (2… Patch early 7.5 high 7.7% 2005-11-03
CVE-2004-1471 EXP Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access t… Patch early 7.1 high 7.7% 2004-12-31
CVE-2012-4889 EXP Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 7.7% 2012-09-10
CVE-2019-8611 EXP Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safa… Patch early 8.8 high 7.7% 2019-12-18
CVE-2019-8671 EXP Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safa… Patch early 8.8 high 7.7% 2019-12-18
CVE-2008-0767 EXP ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain "number of URLs" field is consistent with the… Patch early 5.0 medium 7.7% 2008-02-13
CVE-2008-3396 EXP Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via… Patch early 5.0 medium 7.7% 2008-07-31
CVE-2003-1386 EXP AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displ… Patch early 6.4 medium 7.7% 2003-12-31
CVE-1999-0996 EXP Buffer overflow in Infoseek Ultraseek search engine allows remote attackers to execute commands via a long GET request. Patch early 7.5 high 7.7% 1999-12-15
CVE-2006-5558 EXP Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via format… Patch early 10.0 high 7.7% 2006-10-27
CVE-2008-0702 EXP Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of service (daemon crash or hang)… Patch early 9.3 high 7.7% 2008-02-12
CVE-2009-5134 EXP Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions before 1.8.3 (Build 16010), al… Patch early 6.8 medium 7.7% 2013-01-18
CVE-2008-3155 EXP Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to cause a denial of serv… Patch early 9.3 high 7.7% 2008-07-11
CVE-2017-0245 EXP The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1 and Windows Server 2012 Gold allow a local authenticated attacker to exec… Patch early 4.7 medium 7.7% 2017-05-12
← previous page 254 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt