peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,659 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

403,659 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-0543 EXP Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read files outside the web root, in… Patch early 5.0 medium 9.8% 2002-07-03
CVE-2014-1905 EXP Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows… Patch early 10.0 high 9.8% 2014-12-29
CVE-2018-20580 EXP The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request param… Patch early 8.8 high 9.8% 2019-05-03
CVE-2013-5945 EXP Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N wit… Patch early 9.8 critical 9.8% 2020-02-11
CVE-2016-1240 EXP The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and l… Patch early 7.8 high 9.8% 2016-10-03
CVE-2010-2752 EXP Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.… Patch early 9.3 high 9.8% 2010-07-30
CVE-2005-1523 EXP Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitr… Patch early 7.5 high 9.8% 2005-05-26
CVE-2004-2513 EXP Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via a long SELECT command. Patch early 10.0 high 9.8% 2004-12-31
CVE-2000-0074 EXP PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions. Patch early 7.5 high 9.8% 2000-01-11
CVE-2017-14089 EXP An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the Office… Patch early 9.8 critical 9.8% 2017-10-06
CVE-2001-1196 EXP Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argument… Patch early 10.0 high 9.8% 2001-12-17
CVE-2014-5086 EXP A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let… Patch early 8.8 high 9.8% 2020-02-10
CVE-2011-3498 EXP Heap-based buffer overflow in Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (crash) and possibl… Patch early 10.0 high 9.8% 2011-09-16
CVE-2019-8662 EXP This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able… Patch early 9.8 critical 9.8% 2019-12-18
CVE-2012-2227 EXP Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local files via… Patch early 7.5 high 9.8% 2012-08-26
CVE-2001-0702 EXP Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long (1) username, (2) p… Patch early 7.5 high 9.8% 2001-09-20
CVE-2004-0069 EXP Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifie… Patch early 7.5 high 9.8% 2004-02-17
CVE-2002-0313 EXP Buffer overflow in Essentia Web Server 2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long URL. Patch early 7.5 high 9.8% 2002-06-25
CVE-2011-5167 EXP Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strateg… Patch early 9.3 high 9.8% 2012-09-15
CVE-2018-11479 EXP The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that establishes… Patch early 7.8 high 9.8% 2018-05-25
CVE-2019-6215 EXP A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for W… Patch early 8.8 high 9.8% 2019-03-05
CVE-2008-4694 EXP Unspecified vulnerability in Opera before 9.60 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via… Patch early 9.3 high 9.8% 2008-10-23
CVE-2008-7103 EXP Stack-based buffer overflow in an ActiveX control in najdisitoolbar.dll in Najdi.si Toolbar 2.0.4.1 allows remote attackers to cause a denial of servi… Patch early 9.3 high 9.8% 2009-08-27
CVE-2013-3934 EXP Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allows remote attackers to execute… Patch early 9.3 high 9.8% 2013-09-10
CVE-2016-4535 EXP Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to cause a denial of service (memo… Patch early 7.5 high 9.8% 2016-05-05
CVE-2014-4663 EXP TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary commands via shell metacharac… Patch early 6.8 medium 9.8% 2014-07-15
CVE-2006-1243 EXP Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitra… Patch early 7.5 high 9.7% 2006-03-15
CVE-2007-2584 EXP Buffer overflow in the IsOldAppInstalled function in the McSubMgr.McSubMgr Subscription Manager ActiveX control (MCSUBMGR.DLL) in McAfee SecurityCente… Patch early 10.0 high 9.7% 2007-05-10
CVE-2019-9832 EXP The AirDrop application through 2.0 for Android allows remote attackers to cause a denial of service via a client that makes many socket connections t… Patch early 7.5 high 9.7% 2019-03-15
CVE-2006-2026 EXP Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly e… Patch early 6.5 medium 9.7% 2006-04-25
← previous page 263 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt