peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,659 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

187,572 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-1904 EXP Buffer overflow in ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to execute arbitrary code via the Internacional property followed by… Patch early 7.5 high 4.9% 2004-12-31
CVE-2005-0906 EXP Buffer overflow in a player logging function in the Tincat network library 2.x before 2.0.28, as used in games such as Sacred and The Settlers: Herita… Patch early 7.5 high 4.9% 2005-05-02
CVE-2005-3491 EXP Multiple buffer overflows in the receiver function in loop.c in FlatFrag 0.3 and earlier allow remote attackers to execute arbitrary code via the (1)… Patch early 7.5 high 4.9% 2005-11-04
CVE-2006-7156 EXP PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a module for miniBB, allows remo… Patch early 10.0 high 4.9% 2007-03-07
CVE-2018-4206 EXP An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2018-001 is affected. tvOS befo… Patch early 7.8 high 4.9% 2018-06-08
CVE-2006-6396 EXP Stack-based buffer overflow in BlazeVideo HDTV Player 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via a long filename… Patch early 7.5 high 4.9% 2006-12-08
CVE-2013-3574 EXP Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote attackers… Patch early 7.8 high 4.9% 2013-06-14
CVE-2019-1089 EXP An elevation of privilege vulnerability exists in rpcss.dll when the RPC service Activation Kernel improperly handles an RPC request. To exploit this… Patch early 7.8 high 4.9% 2019-07-15
CVE-2012-5864 EXP These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. By directly visiting the pages within th… Patch early 9.4 high 4.9% 2012-11-23
CVE-2009-3253 EXP Stack-based buffer overflow in TriceraSoft Swift Ultralite 1.032 allows remote attackers to cause a denial of service (crash) or execute arbitrary cod… Patch early 9.3 high 4.9% 2009-09-18
CVE-2009-1674 EXP Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathname in a… Patch early 9.3 high 4.9% 2009-05-18
CVE-2007-5450 EXP Unspecified vulnerability in Safari on the Apple iPod touch (aka iTouch) and iPhone 1.1.1 allows user-assisted remote attackers to cause a denial of s… Patch early 9.3 high 4.9% 2007-10-14
CVE-2013-5578 EXP Buffer overflow in the ToDot method in the WINGRAPHVIZLib.NEATO ActiveX control in WinGraphviz.dll in StarUML allows remote attackers to execute arbit… Patch early 9.3 high 4.9% 2013-08-25
CVE-2023-31874 EXP Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_process'). Patch early 8.8 high 4.9% 2023-05-29
CVE-2005-4287 EXP PHP remote file include vulnerability in MarmaraWeb E-commerce allows remote attackers to execute arbitrary code via the page parameter to index.php. Patch early 7.5 high 4.9% 2005-12-16
CVE-2008-1244 EXP cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows remote attackers to perform a… Patch early 10.0 high 4.9% 2008-03-10
CVE-1999-0822 EXP Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command. Patch early 10.0 high 4.9% 1999-11-30
CVE-2008-7074 EXP Format string vulnerability in MemeCode Software i.Scribe 1.88 through 2.00 before Beta9 allows remote SMTP servers to cause a denial of service (cras… Patch early 9.3 high 4.9% 2009-08-25
CVE-2006-0072 EXP Buffer overflow in termsh on SCO OpenServer 5.0.7 allows remote attackers to execute arbitrary code via a long -o command line argument. NOTE: this i… Patch early 7.5 high 4.9% 2006-01-04
CVE-2005-2305 EXP DG Remote Control Server 1.6.2 allows remote attackers to cause a denial of service (crash or CPU consumption) and possibly execute arbitrary code via… Patch early 7.5 high 4.9% 2005-07-19
CVE-2016-1755 EXP The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privi… Patch early 7.8 high 4.9% 2016-03-24
CVE-2009-3547 EXP Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference a… Patch early 7.0 high 4.9% 2009-11-04
CVE-2008-4873 EXP board.cgi in Sepal SPBOARD 4.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter during a down_file… Patch early 10.0 high 4.9% 2008-11-01
CVE-2016-9566 EXP base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink atta… Patch early 7.8 high 4.9% 2016-12-15
CVE-2020-8819 EXP An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in the IPN callback processing f… Patch early 8.1 high 4.9% 2020-02-25
CVE-2000-0295 EXP Buffer overflow in LCDproc allows remote attackers to gain root privileges via the screen_add command. Patch early 10.0 high 4.9% 2000-04-21
CVE-2009-3213 EXP Stack-based buffer overflow in broid 1.0 Beta 3a allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrar… Patch early 9.3 high 4.9% 2009-09-16
CVE-2014-9612 EXP SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote… Patch early 9.8 critical 4.9% 2020-02-19
CVE-2018-5315 EXP The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php. Patch early 9.8 critical 4.9% 2018-01-12
CVE-2015-3314 EXP SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5. Patch early 8.1 high 4.9% 2017-09-07
← previous page 270 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt