peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,602 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

403,602 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-17961 EXP Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this is… Patch early 8.6 high 10% 2018-10-15
CVE-2013-6283 EXP VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a lon… Patch early 7.5 high 10% 2013-10-25
CVE-2007-2807 EXP Stack-based buffer overflow in mod/server.mod/servrmsg.c in Eggdrop 1.6.18, and possibly earlier, allows user-assisted, remote IRC servers to execute… Patch early 6.8 medium 10% 2007-05-22
CVE-2006-4019 EXP Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variabl… Patch early 6.4 medium 10% 2006-08-11
CVE-2010-2939 EXP Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and possibly ot… Patch early 4.3 medium 10% 2010-08-17
CVE-2021-33904 EXP In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are conf… Patch early 6.1 medium 10% 2021-06-07
CVE-2020-25538 EXP An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web pa… Patch early 8.8 high 10% 2020-11-13
CVE-2020-25557 EXP In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs… Patch early 8.8 high 10% 2020-11-13
CVE-2012-4552 EXP Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute arbitrary code via a crafted 3… Patch early 6.8 medium 10% 2012-11-18
CVE-2005-1666 EXP Multiple buffer overflows in Orenosv HTTP/FTP Server 0.8.1 allow remote authenticated users to cause a denial of service (server crash) and possibly e… Patch early 7.5 high 10% 2005-05-18
CVE-2007-4582 EXP Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ACTi Network Video Recorder (NVR) SP2 2.… Patch early 7.5 high 10% 2007-08-29
CVE-2011-5265 EXP Cross-site scripting (XSS) vulnerability in cached_image.php in the Featurific For WordPress plugin 1.6.2 for WordPress allows remote attackers to inj… Patch early 4.3 medium 10% 2013-02-12
CVE-2013-0238 EXP The try_parse_v4_netmask function in hostmask.c in IRCD-Hybrid before 8.0.6 does not properly validate masks, which allows remote attackers to cause a… Patch early 5.0 medium 10% 2013-02-13
CVE-2003-1247 EXP Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile,… Patch early 7.5 high 10% 2003-12-31
CVE-2008-7170 EXP GSC build 2067 and earlier relies on the client to enforce administrator privileges, which allows remote attackers to execute arbitrary administrator… Patch early 10.0 high 9.9% 2009-09-08
CVE-2008-3877 EXP Stack-based buffer overflow in Acoustica Mixcraft 4.1 Build 96 and 4.2 Build 98 allows user-assisted attackers to execute arbitrary code via a crafted… Patch early 9.3 high 9.9% 2008-09-02
CVE-2008-4686 EXP Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote atta… Patch early 9.3 high 9.9% 2008-10-22
CVE-2012-3448 EXP Unspecified vulnerability in Ganglia Web before 3.5.1 allows remote attackers to execute arbitrary PHP code via unknown attack vectors. Patch early 7.5 high 9.9% 2012-08-06
CVE-2012-1617 EXP Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbitrary files via a .. (dot dot)… Patch early 6.4 medium 9.9% 2012-09-26
CVE-2010-1476 EXP Directory traversal vulnerability in the AlphaUserPoints (com_alphauserpoints) component 1.5.5 for Joomla! allows remote attackers to read arbitrary f… Patch early 6.8 medium 9.9% 2010-04-19
CVE-2005-2409 EXP Format string vulnerability in util.c in nbsmtp 0.99 and earlier, while running in debug mode, allows remote attackers to execute arbitrary code via f… Patch early 7.5 high 9.9% 2005-08-01
CVE-2019-5009 EXP Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and h… Patch early 7.2 high 9.9% 2019-01-04
CVE-2004-2761 EXP The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as dem… Patch early 9.8 critical 9.9% 2009-01-05
CVE-2016-0862 EXP General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive… Patch early 6.5 medium 9.9% 2016-02-05
CVE-2010-4717 EXP Multiple stack-based buffer overflows in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote a… Patch early 6.5 medium 9.9% 2011-01-31
CVE-2014-2996 EXP XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administrators to execute arbitrary com… Patch early 7.1 high 9.9% 2014-04-25
CVE-2000-0527 EXP userreg.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters. Patch early 10.0 high 9.9% 2000-06-09
CVE-2000-0177 EXP DNSTools CGI applications allow remote attackers to execute arbitrary commands via shell metacharacters. Patch early 10.0 high 9.9% 2000-03-02
CVE-2003-1029 EXP The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loop and memory consumption) via… Patch early 5.0 medium 9.9% 2004-02-17
CVE-2009-5135 EXP The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an external en… Patch early 5.0 medium 9.9% 2013-05-02
← previous page 260 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt