peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,208 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

25,087 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-0803 EXP Multiple PHP remote file inclusion vulnerabilities in LookStrike Lan Manager 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 32.7% 2008-02-15
CVE-2008-5711 EXP Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary code via a… Patch early 9.3 high 32.7% 2008-12-24
CVE-2008-2286 EXP SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows remote attackers to execute… Patch early 7.5 high 32.7% 2008-05-18
CVE-2017-2992 EXP Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 header. Successful exploitation… Patch early 8.8 high 32.7% 2017-02-15
CVE-2021-37589 EXP Virtua Cobranca before 12R allows SQL Injection on the login page. Patch early 7.5 high 32.7% 2022-06-07
CVE-2012-5960 EXP Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… Patch early 10.0 high 32.6% 2013-01-31
CVE-2009-3830 EXP The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP… Patch early 5.0 medium 32.6% 2009-10-30
CVE-2007-1644 EXP The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or confi… Patch early 10.0 high 32.6% 2007-03-24
CVE-2013-1017 EXP Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via… Patch early 9.3 high 32.6% 2013-05-24
CVE-2022-31854 EXP Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel. Patch early 7.2 high 32.5% 2022-07-07
CVE-2015-5471 EXP Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allows remote attackers to read ar… Patch early 5.3 medium 32.5% 2016-01-12
CVE-2016-4229 EXP Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.6… Patch early 8.8 high 32.5% 2016-07-13
CVE-2009-5109 EXP Stack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long entry in a .pls file. Patch early 9.3 high 32.5% 2011-12-25
CVE-2018-15534 EXP Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information including usernames and hashes via a d… Patch early 9.8 critical 32.4% 2018-08-21
CVE-2013-3827 EXP Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2; the Oracle JDeveloper componen… Patch early 5.0 medium 32.4% 2013-10-16
CVE-2008-3979 EXP Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authenticated users to affect confide… Patch early 5.5 medium 32.4% 2009-01-14
CVE-2015-3107 EXP Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.4… Patch early 10.0 high 32.4% 2015-06-10
CVE-2001-0144 EXP CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer over… Patch early 10.0 high 32.4% 2001-03-12
CVE-2012-1153 EXP Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers to execute arbitrary… Patch early 6.8 medium 32.4% 2012-10-06
CVE-2016-7054 EXP In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads.… Patch early 7.5 high 32.4% 2017-05-04
CVE-1999-0920 EXP Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command. Patch early 10.0 high 32.4% 1999-05-26
CVE-2013-6935 EXP Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the SourcePath… Patch early 9.3 high 32.4% 2013-12-04
CVE-2015-2458 EXP ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Wind… Patch early 9.3 high 32.4% 2015-08-15
CVE-2015-2459 EXP ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Wind… Patch early 9.3 high 32.4% 2015-08-15
CVE-2011-0340 EXP Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed… Patch early 9.3 high 32.3% 2011-05-04
CVE-2007-5941 EXP Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a denial of service and possibly ex… Patch early 10.0 high 32.3% 2007-11-14
CVE-2000-0495 EXP Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "Malformed Windows Media Encoder… Patch early 5.0 medium 32.3% 2000-05-30
CVE-2011-2013 EXP Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allo… Patch early 9.8 critical 32.3% 2011-11-08
CVE-2000-0567 EXP Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email heade… Patch early 5.0 medium 32.3% 2000-07-18
CVE-2013-4468 EXP VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary commands via shell… Patch early 6.5 medium 32.3% 2014-05-14
← previous page 105 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt