peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,734 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

403,734 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-5954 EXP phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect commands. Patch early 7.5 high 8.9% 2018-01-25
CVE-2017-15644 EXP SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000. Patch early 8.6 high 8.9% 2017-10-19
CVE-2010-2045 EXP Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Joomla! allows remote attackers to… Patch early 7.5 high 8.9% 2010-05-25
CVE-2006-2458 EXP Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code via (1) the asf_read_header f… Patch early 4.0 medium 8.9% 2006-05-18
CVE-2013-6830 EXP admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attackers to execute arbitrary command… Patch early 7.5 high 8.9% 2013-11-20
CVE-2019-2107 EXP In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code e… Patch early 8.8 high 8.9% 2019-07-08
CVE-2007-4338 EXP index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's na… Patch early 10.0 high 8.9% 2007-08-14
CVE-2002-0737 EXP Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a denial of service (resource exhau… Patch early 6.4 medium 8.9% 2002-08-12
CVE-2010-2300 EXP Use-after-free vulnerability in the Element::normalizeAttributes function in dom/Element.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 a… Patch early 10.0 high 8.9% 2010-06-15
CVE-2008-4324 EXP The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dere… Patch early 5.0 medium 8.9% 2008-09-29
CVE-2014-2575 EXP Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and… Patch early 6.5 medium 8.9% 2014-06-06
CVE-2010-1179 EXP Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… Patch early 9.3 high 8.9% 2010-03-29
CVE-2006-4160 EXP Multiple PHP remote file inclusion vulnerabilities in Tony Bibbs and Vincent Furia MVCnPHP 3.0 allow remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 8.9% 2006-08-16
CVE-2001-0899 EXP Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variable. Patch early 7.5 high 8.9% 2001-11-16
CVE-2010-0313 EXP The core_get_proxyauth_dn function in ns-slapd in Sun Java System Directory Server Enterprise Edition 7.0 allows remote attackers to cause a denial of… Patch early 5.0 medium 8.9% 2010-01-14
CVE-2012-4982 EXP Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary w… Patch early 5.8 medium 8.9% 2012-12-05
CVE-2016-8377 EXP An issue was discovered in Fatek Automation PLC WinProladder Version 3.11 Build 14701. A stack-based buffer overflow vulnerability exists when the sof… Patch early 8.0 high 8.9% 2017-02-13
CVE-2019-11269 EXP Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versi… Patch early 5.4 medium 8.9% 2019-06-12
CVE-2012-4750 EXP A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, which could let a remote malicio… Patch early 9.8 critical 8.9% 2020-01-13
CVE-2018-1123 EXP procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maps a guard page at the… Patch early 3.9 low 8.9% 2018-05-23
CVE-2006-2555 EXP The parse_command function in Genecys 0.2 and earlier allows remote attackers to cause a denial of service (crash) via a command with a missing ":" (c… Patch early 5.0 medium 8.9% 2006-05-24
CVE-2001-1291 EXP The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or pass… Patch early 9.8 critical 8.9% 2001-07-12
CVE-2022-2591 EXP A vulnerability classified as critical has been found in TEM FLEX-1085 1.6.0. Affected is an unknown function of the file /sistema/flash/reboot. The m… Patch early 7.5 high 8.9% 2022-08-01
CVE-2009-3658 EXP Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory… Patch early 8.8 high 8.9% 2009-10-09
CVE-2012-1563 EXP Joomla! before 2.5.3 allows Admin Account Creation. Patch early 7.5 high 8.9% 2020-01-15
CVE-2013-6890 EXP denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (inc… Patch early 5.0 medium 8.9% 2013-12-23
CVE-2008-0364 EXP Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; on Windows… Patch early 5.0 medium 8.9% 2008-01-18
CVE-2006-4131 EXP Multiple buffer overflows in ArcSoft MMS Composer 1.5.5.6, and possibly earlier, and 2.0.0.13, and possibly earlier, allow remote attackers to cause a… Patch early 7.5 high 8.9% 2006-08-14
CVE-2006-5472 EXP PHP remote file inclusion vulnerability in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 8.9% 2006-10-24
CVE-2017-7042 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 8.8 high 8.9% 2017-07-20
← previous page 278 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt