peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,157 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

25,087 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-5299 EXP Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl file. NOTE: it has been report… Patch early 6.8 medium 33.6% 2014-05-23
CVE-2021-31761 EXP Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature. Patch early 9.6 critical 33.6% 2021-04-25
CVE-2015-2444 EXP Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch early 9.3 high 33.6% 2015-08-14
CVE-2013-3111 EXP Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch early 9.3 high 33.5% 2013-06-12
CVE-2009-0076 EXP Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the zoom style directive in conju… Patch early 9.3 high 33.5% 2009-02-10
CVE-2000-0711 EXP Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to creat… Patch early 7.5 high 33.5% 2000-10-20
CVE-2022-48194 EXP TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploa… Patch early 8.8 high 33.5% 2022-12-30
CVE-2016-0971 EXP Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on… Patch early 8.8 high 33.5% 2016-02-10
CVE-2015-0050 EXP Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted w… Patch early 9.3 high 33.5% 2015-02-11
CVE-2017-16885 EXP Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Chang… Patch early 9.8 critical 33.5% 2018-01-12
CVE-2008-2069 EXP Buffer overflow in Novell GroupWise 7 allows remote attackers to cause a denial of service or execute arbitrary code via a long argument in a mailto:… Patch early 9.3 high 33.4% 2008-05-02
CVE-2000-0673 EXP The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoof… Patch early 5.0 medium 33.4% 2000-07-27
CVE-2013-1306 EXP Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers a… Patch early 9.3 high 33.4% 2013-05-15
CVE-2015-3124 EXP Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.4… Patch early 10.0 high 33.4% 2015-07-09
CVE-2018-11094 EXP An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasic… Patch early 9.8 critical 33.4% 2018-05-15
CVE-2014-8682 EXP Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow remote attackers to execute arb… Patch early 7.5 high 33.4% 2014-11-21
CVE-2008-0117 EXP Unspecified vulnerability in Microsoft Excel 2000 SP3 and 2002 SP2, and Office 2004 and 2008 for Mac, allows user-assisted remote attackers to execute… Patch early 9.3 high 33.4% 2008-03-11
CVE-2011-1772 EXP Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow… Patch early 2.6 low 33.3% 2011-05-13
CVE-2002-0193 EXP Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fi… Patch early 7.5 high 33.3% 2002-05-29
CVE-2005-1980 EXP Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transact… Patch early 5.0 medium 33.3% 2005-10-12
CVE-2014-1766 EXP Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch early 9.3 high 33.3% 2014-04-27
CVE-2009-1394 EXP Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code by sending a long malformed st… Patch early 9.3 high 33.3% 2009-06-26
CVE-2009-1612 EXP Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary… Patch early 9.3 high 33.3% 2009-05-11
CVE-2019-15813 EXP Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary code via a webshell. Patch early 8.8 high 33.2% 2019-09-04
CVE-2025-1097 EXP A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be… Patch early 8.8 high 33.2% 2025-03-25
CVE-2020-29607 EXP A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "mana… Patch early 7.2 high 33.2% 2020-12-16
CVE-2010-4321 EXP Stack-based buffer overflow in an ActiveX control in ienipp.ocx in Novell iPrint Client 5.52 allows remote attackers to execute arbitrary code via a l… Patch early 9.3 high 33.2% 2010-12-30
CVE-2015-3337 EXP Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read… Patch early 4.3 medium 33.2% 2015-05-01
CVE-2016-4226 EXP Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.6… Patch early 8.8 high 33.1% 2016-07-13
CVE-2016-4228 EXP Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.6… Patch early 8.8 high 33.1% 2016-07-13
← previous page 103 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt