peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,237 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

321,944 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-6808 EXP Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML v… Patch early 6.8 medium 6.9% 2006-12-28
CVE-2000-0396 EXP The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to… Patch early 5.0 medium 6.9% 2000-05-24
CVE-2012-0242 EXP Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers… Patch early 10.0 high 6.9% 2012-02-21
CVE-2009-1670 EXP user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin accounts via unspecified vector… Patch early 7.5 high 6.9% 2009-05-18
CVE-2008-3667 EXP Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTTP header. Patch early 6.8 medium 6.9% 2008-08-13
CVE-2010-4437 EXP Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.4, 10.0.2, 10.3.2, and 10.3.3 allows remot… Patch early 5.8 medium 6.9% 2011-01-19
CVE-2003-0863 EXP The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is n… Patch early 7.5 high 6.9% 2003-11-17
CVE-2017-6192 EXP Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arbitrary code via a crafted imag… Patch early 5.5 medium 6.9% 2018-02-20
CVE-1999-0414 EXP In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the conne… Patch early 5.0 medium 6.9% 1999-03-01
CVE-2000-0208 EXP The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters… Patch early 5.0 medium 6.9% 2000-02-29
CVE-2008-2390 EXP Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows remote attackers to execute ar… Patch early 6.8 medium 6.9% 2008-05-21
CVE-2002-0730 EXP Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields… Patch early 7.5 high 6.9% 2002-08-12
CVE-2009-1642 EXP Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp… Patch early 9.3 high 6.9% 2009-05-15
CVE-2009-4756 EXP Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execute arbitrary code via a long s… Patch early 9.3 high 6.9% 2010-03-29
CVE-2008-0747 EXP Stack-based buffer overflow in COWON America jetAudio 7.0.5 and earlier allows user-assisted remote attackers to execute arbitrary code via a long URL… Patch early 9.3 high 6.9% 2008-02-13
CVE-2011-4529 EXP Multiple buffer overflows in Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allow remote attackers to execute arbitrary code via a… Patch early 7.5 high 6.9% 2012-01-08
CVE-2004-0682 EXP comersus_gatewayPayPal.asp in Comersus Cart 5.09, and possibly other versions before 5.098, allows remote attackers to change the prices of items by d… Patch early 7.5 high 6.9% 2004-08-06
CVE-2008-1727 EXP KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin accou… Patch early 7.5 high 6.9% 2008-04-11
CVE-2008-5219 EXP The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require k… Patch early 7.5 high 6.9% 2008-11-25
CVE-2012-0901 EXP Cross-site scripting (XSS) vulnerability in yousaytoo.php in YouSayToo auto-publishing plugin 1.0 for WordPress allows remote attackers to inject arbi… Patch early 4.3 medium 6.9% 2012-01-20
CVE-2015-0104 EXP IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 an… Patch early 8.8 high 6.8% 2017-04-24
CVE-2013-5657 EXP AultWare pwStore 2010.8.30.0 has DoS via an empty HTTP request Patch early 7.5 high 6.8% 2020-01-07
CVE-2015-8283 EXP Directory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00. Patch early 6.5 medium 6.8% 2017-04-13
CVE-2004-2614 EXP Buffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET requ… Patch early 7.5 high 6.8% 2004-12-31
CVE-2004-1214 EXP Format string vulnerability in Kreed 1.05 and earlier allows remote attackers to execute arbitrary code via format specifiers in (1) a nickname or (2)… Patch early 10.0 high 6.8% 2005-01-10
CVE-2011-5162 EXP Stack-based buffer overflow in GOM Player 2.1.33.5071 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI… Patch early 9.3 high 6.8% 2012-09-15
CVE-2005-2075 EXP PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows… Patch early 5.0 medium 6.8% 2005-06-29
CVE-2002-1435 EXP class.atkdateattribute.js.php in Achievo 0.7.0 through 0.9.1, except 0.8.2, allows remote attackers to execute arbitrary PHP code when the 'allow_url_… Patch early 7.5 high 6.8% 2003-04-11
CVE-2007-6550 EXP form.php in PMOS Help Desk 2.4 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct eval inject… Patch early 7.5 high 6.8% 2007-12-28
CVE-2006-2180 EXP Buffer overflow in Golden FTP Server Pro 2.70 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via… Patch early 6.4 medium 6.8% 2006-05-04
← previous page 281 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt