peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,557 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

403,557 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2013-3969 EXP The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitializ… Patch early 6.5 medium 10.1% 2013-10-01
CVE-2008-4652 EXP Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execute arbitr… Patch early 9.3 high 10.1% 2008-10-22
CVE-2007-2156 EXP Multiple PHP remote file inclusion vulnerabilities in Rezervi Generic 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the root p… Patch early 7.5 high 10.1% 2007-04-19
CVE-2007-2597 EXP Multiple PHP remote file inclusion vulnerabilities in telltarget CMS 1.3.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) o… Patch early 7.5 high 10.1% 2007-05-11
CVE-2007-3217 EXP Multiple PHP remote file inclusion vulnerabilities in Prototype of an PHP application 0.1 allow remote attackers to execute arbitrary PHP code via a U… Patch early 7.5 high 10.1% 2007-06-14
CVE-2007-0561 EXP Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root… Patch early 7.5 high 10.1% 2007-01-30
CVE-2013-2681 EXP Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access. Patch early 9.8 critical 10.1% 2020-02-05
CVE-2009-2364 EXP Stack-based buffer overflow in Mp3-Nator 2.0 allows remote attackers to execute arbitrary code via (1) a long string in a .plf file and (2) a long str… Patch early 9.3 high 10.1% 2009-07-08
CVE-2008-2693 EXP Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to… Patch early 9.3 high 10.1% 2008-06-13
CVE-2009-0756 EXP The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that… Patch early 5.0 medium 10.1% 2009-03-03
CVE-2006-5058 EXP Buffer overflow in (1) Call of Duty 1.5b and earlier, (2) Call of Duty United Offensive 1.51b and earlier, and (3) Call of Duty 2 1.3 and earlier allo… Patch early 7.5 high 10.1% 2006-09-28
CVE-2011-4618 EXP Cross-site scripting (XSS) vulnerability in advancedtext.php in Advanced Text Widget plugin before 2.0.2 for WordPress allows remote attackers to inje… Patch early 4.3 medium 10.1% 2013-01-24
CVE-1999-1588 EXP Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string begi… Patch early 9.8 critical 10.1% 1999-12-31
CVE-2017-12929 EXP Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files lead… Patch early 8.8 high 10.1% 2017-09-21
CVE-2017-12969 EXP Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a den… Patch early 8.8 high 10.1% 2017-11-10
CVE-2016-4806 EXP Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server… Patch early 7.5 high 10.1% 2017-01-11
CVE-2005-2199 EXP PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via… Patch early 7.5 high 10.1% 2005-07-11
CVE-2007-4722 EXP Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie07051001.dll 1.0.0.1 in Move Media Pl… Patch early 6.8 medium 10.1% 2007-09-05
CVE-2005-3488 EXP Scorched 3D 39.1 (bf) and earlier allows remote attackers to cause a denial of service (long loop and server hang) via a negative numplayers value tha… Patch early 7.8 high 10.1% 2005-11-03
CVE-2011-0885 EXP A certain Comcast Business Gateway configuration of the SMC SMCD3G-CCR with firmware before 1.4.0.49.2 has a default password of D0nt4g3tme for the ms… Patch early 10.0 high 10.1% 2011-02-08
CVE-2009-3305 EXP Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that… Patch early 5.0 medium 10.1% 2009-12-24
CVE-2004-1695 EXP EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administration feature via a URL that cont… Patch early 10.0 high 10.1% 2004-09-20
CVE-2021-30149 EXP Composr 10.0.36 allows upload and execution of PHP files. Patch early 9.8 critical 10.1% 2021-04-06
CVE-2007-2816 EXP Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP code via a URL in the root pa… Patch early 7.5 high 10.1% 2007-05-22
CVE-2012-0278 EXP Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file… Patch early 9.3 high 10.1% 2012-04-18
CVE-2011-3981 EXP PHP remote file inclusion vulnerability in actions.php in the Allwebmenus plugin 1.1.3 for WordPress allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 10.1% 2011-10-04
CVE-2014-10011 EXP Stack-based buffer overflow in UltraCamLib in the UltraCam ActiveX Control (UltraCamX.ocx) for the TRENDnet SecurView camera TV-IP422WN allows remote… Patch early 7.5 high 10.1% 2015-01-13
CVE-2000-0272 EXP RealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at port 7070. Patch early 7.8 high 10.1% 2000-04-20
CVE-2009-0103 EXP Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) apps_pat… Patch early 7.5 high 10.1% 2009-01-09
CVE-2017-11435 EXP The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management consol… Patch early 9.8 critical 10.1% 2017-07-19
← previous page 258 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt