peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,922 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

321,744 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2000-0851 EXP Buffer overflow in the Still Image Service in Windows 2000 allows local users to gain additional privileges via a long WM_USER message, aka the "Still… Patch early 4.6 medium 7.6% 2000-11-14
CVE-2000-0853 EXP YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a .. (dot dot) attack. Patch early 5.0 medium 7.6% 2000-11-14
CVE-2000-1016 EXP The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read packa… Patch early 5.0 medium 7.6% 2000-12-11
CVE-2001-1170 EXP AmTote International homebet program stores the homebet.log file in the homebet/ virtual directory, which allows remote attackers to steal account and… Patch early 5.0 medium 7.6% 2001-09-29
CVE-2007-0228 EXP The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service (service crash) via a (1) &CO… Patch early 5.0 medium 7.6% 2007-01-13
CVE-2002-2154 EXP Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences. Patch early 5.0 medium 7.6% 2002-12-31
CVE-2007-5694 EXP Absolute path traversal vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to read arbitrary… Patch early 6.8 medium 7.6% 2007-10-29
CVE-2013-2225 EXP inc/ticket.class.php in GLPI 0.83.9 and earlier allows remote attackers to unserialize arbitrary PHP objects via the _predefined_fields parameter to f… Patch early 6.4 medium 7.6% 2014-05-27
CVE-2001-1263 EXP telnet95.exe in Pragma InterAccess 4.0 build 5 allows remote attackers to cause a denial of service (crash) via a large number of characters to port 2… Patch early 5.0 medium 7.6% 2001-06-06
CVE-2008-0100 EXP Stack-based buffer overflow in the Scene::errorf function in Scene.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbit… Patch early 7.5 high 7.6% 2008-01-08
CVE-2006-2245 EXP PHP remote file inclusion vulnerability in auction\auction_common.php in Auction mod 1.3m for phpBB allows remote attackers to execute arbitrary PHP c… Patch early 6.8 medium 7.6% 2006-05-09
CVE-2006-1718 EXP Magus Perde Clever Copy 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attacker… Patch early 5.0 medium 7.6% 2006-04-11
CVE-2006-4559 EXP Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attackers to execute arbitrary PHP co… Patch early 7.5 high 7.6% 2006-09-06
CVE-2000-1033 EXP Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attem… Patch early 7.5 high 7.6% 2000-12-11
CVE-2007-2186 EXP Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document. Patch early 5.0 medium 7.6% 2007-04-24
CVE-2023-27167 EXP Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/absence?search_month=1. Patch early 6.5 medium 7.6% 2023-03-29
CVE-2000-0582 EXP Check Point FireWall-1 4.0 and 4.1 allows remote attackers to cause a denial of service by sending a stream of invalid commands (such as binary zeros)… Patch early 5.0 medium 7.6% 2000-06-30
CVE-2008-1498 EXP Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitrary code vi… Patch early 9.0 high 7.6% 2008-03-25
CVE-2014-1771 EXP SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same during renegotiation as it was befo… Patch early 6.8 medium 7.6% 2014-06-11
CVE-2002-0892 EXP The default configuration of NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to determine the path of the web root via a direct request to co… Patch early 5.0 medium 7.6% 2002-10-04
CVE-2000-0131 EXP Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands. Patch early 5.0 medium 7.6% 2000-02-01
CVE-2017-6549 EXP Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U… Patch early 8.8 high 7.6% 2017-03-09
CVE-2023-34634 EXP Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .greenshot file is opened. Patch early 7.8 high 7.6% 2023-08-01
CVE-2020-11803 EXP An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lea… Patch early 8.8 high 7.6% 2020-09-17
CVE-2005-0614 EXP sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie. Patch early 7.5 high 7.6% 2005-05-02
CVE-2001-0007 EXP Buffer overflow in NetScreen Firewall WebUI allows remote attackers to cause a denial of service via a long URL request to the web administration inte… Patch early 5.0 medium 7.6% 2001-02-12
CVE-2004-1664 EXP Call of Duty 1.4 and earlier allows remote attackers to cause a denial of service (game end) via a large (1) query or (2) reply packet, which is not p… Patch early 5.0 medium 7.6% 2004-09-05
CVE-2021-28976 EXP Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess. Patch early 7.2 high 7.5% 2021-06-23
CVE-2017-6193 EXP Buffer overflow in APNGDis 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted imag… Patch early 5.5 medium 7.5% 2018-02-20
CVE-2007-1244 EXP Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions… Patch early 6.8 medium 7.5% 2007-03-03
← previous page 259 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt