peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,557 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

187,512 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-30350 EXP FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin password. Patch early 8.8 high 5.3% 2023-05-29
CVE-2002-0332 EXP Buffer overflows in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to execute arbitrary code via (1) a long DNS hostna… Patch early 7.5 high 5.3% 2002-06-25
CVE-2001-0442 EXP Buffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly execute arbi… Patch early 7.5 high 5.3% 2001-06-27
CVE-2010-4280 EXP Multiple SQL injection vulnerabilities in Pandora FMS before 3.1.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the id_g… Patch early 7.5 high 5.3% 2010-12-02
CVE-2007-0016 EXP Stack-based buffer overflow in MoviePlay 4.76 allows remote attackers to execute arbitrary code via a long filename in a LST file. Patch early 7.5 high 5.3% 2007-01-03
CVE-1999-0477 EXP The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not… Patch early 7.5 high 5.3% 1999-12-25
CVE-1999-0753 EXP The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories. Patch early 7.5 high 5.3% 1999-08-17
CVE-2003-0320 EXP header.php in ttCMS 2.3 and earlier allows remote attackers to inject arbitrary PHP code by setting the ttcms_user_admin parameter to "1" and modifyin… Patch early 7.5 high 5.3% 2003-06-09
CVE-2007-5265 EXP Multiple format string vulnerabilities in websrv.cpp in Dawn of Time 1.69s beta4 and earlier allow remote attackers to execute arbitrary code via form… Patch early 7.5 high 5.3% 2007-10-08
CVE-2009-1039 EXP Buffer overflow in CDex 1.70b2 allows remote attackers to execute arbitrary code via a crafted Info header in an Ogg Vorbis (.ogg) file. Patch early 7.5 high 5.3% 2009-03-20
CVE-2023-21752 EXP Windows Backup Service Elevation of Privilege Vulnerability Patch early 7.1 high 5.3% 2023-01-10
CVE-2022-2025 EXP an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param len… Patch early 9.8 critical 5.3% 2022-09-23
CVE-2024-11237 EXP A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this issue is some unknown functio… Patch early 7.5 high 5.3% 2024-11-15
CVE-2016-2417 EXP media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initial… Patch early 9.8 critical 5.3% 2016-04-18
CVE-2008-6186 EXP Stack-based buffer overflow in RaidenFTPD 2.4 build 3620 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary c… Patch early 9.0 high 5.3% 2009-02-19
CVE-2008-6899 EXP Multiple buffer overflows in freeSSHd 1.2.1 allow remote authenticated users to cause a denial of service (crash) and execute arbitrary code via a lon… Patch early 9.0 high 5.3% 2009-08-05
CVE-2007-5332 EXP Multiple unspecified vulnerabilities in (1) mediasvr and (2) caloggerd in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10… Patch early 10.0 high 5.3% 2007-10-13
CVE-2017-14507 EXP Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via… Patch early 9.8 critical 5.3% 2017-09-29
CVE-2010-1686 EXP Stack-based buffer overflow in (1) Urgent Backup 3.20, and (2) ABC Backup Pro 5.20 and ABC Backup 5.50, allows user-assisted remote attackers to execu… Patch early 9.3 high 5.3% 2010-05-05
CVE-2002-0002 EXP Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to exec… Patch early 7.5 high 5.3% 2002-01-31
CVE-2013-4695 EXP Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution Patch early 7.8 high 5.3% 2019-12-27
CVE-2020-10883 EXP This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. A… Patch early 7.8 high 5.3% 2020-03-25
CVE-2009-0351 EXP Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argument beginn… Patch early 9.0 high 5.3% 2009-01-29
CVE-2008-5073 EXP Heap-based buffer overflow in an ActiveX control in Novell ZENworks Desktop Management 6.5 allows remote attackers to execute arbitrary code via a lon… Patch early 9.3 high 5.3% 2008-11-14
CVE-2018-16083 EXP An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of… Patch early 8.8 high 5.3% 2019-01-09
CVE-2018-10969 EXP SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the i… Patch early 9.8 critical 5.3% 2018-06-17
CVE-2004-0648 EXP Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referen… Patch early 10.0 high 5.3% 2004-08-06
CVE-2017-13797 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… Patch early 8.8 high 5.3% 2017-11-13
CVE-2008-4247 EXP ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple co… Patch early 7.5 high 5.3% 2008-09-25
CVE-2015-4614 EXP Multiple SQL injection vulnerabilities in includes/Function.php in the Easy2Map plugin before 1.2.5 for WordPress allow remote attackers to execute ar… Patch early 7.5 high 5.2% 2015-07-08
← previous page 264 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt