peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-3729 EXP DataSourceControl in Internet Explorer 6 on Windows XP SP2 with Office installed allows remote attackers to cause a denial of service (crash) via a la… Patch early 2.6 low 20.6% 2006-07-21
CVE-2019-1127 EXP A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerabili… Patch early 8.8 high 20.6% 2019-07-15
CVE-2000-0983 EXP Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null… Patch early 5.0 medium 20.6% 2000-12-19
CVE-2014-9734 EXP Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to read arbitrary files… Patch early 5.0 medium 20.6% 2015-06-30
CVE-2000-0967 EXP PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error mess… Patch early 10.0 high 20.6% 2000-12-19
CVE-2015-6018 EXP The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary comm… Patch early 9.8 critical 20.6% 2015-12-31
CVE-2008-5666 EXP WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequence of FTP se… Patch early 3.5 low 20.6% 2008-12-19
CVE-2019-14312 EXP Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer. This vulnerability allows a remote a… Patch early 6.5 medium 20.6% 2019-08-09
CVE-2015-4664 EXP An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands. Patch early 9.8 critical 20.6% 2018-06-18
CVE-2009-4873 EXP Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (serve… Patch early 10.0 high 20.6% 2010-05-26
CVE-2011-1930 EXP In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker t… Patch early 9.8 critical 20.5% 2019-11-14
CVE-2006-3656 EXP Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which… Patch early 2.6 low 20.5% 2006-07-18
CVE-2016-7982 EXP Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the syste… Patch early 7.5 high 20.5% 2017-01-18
CVE-2002-2031 EXP Internet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to determine the existence of arbitrary files via a scr… Patch early 5.0 medium 20.5% 2002-12-31
CVE-2019-14348 EXP The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-york… Patch early 9.8 critical 20.5% 2019-08-05
CVE-2004-0399 EXP Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denia… Patch early 7.5 high 20.5% 2004-07-07
CVE-2010-3967 EXP Untrusted search path vulnerability in Microsoft Windows Movie Maker (WMM) 2.6 allows local users to gain privileges via a Trojan horse DLL in the cur… Patch early 9.3 high 20.5% 2010-12-16
CVE-2008-2949 EXP Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change the location property of a frame via the String da… Patch early 6.8 medium 20.5% 2008-06-30
CVE-2017-13156 EXP An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID… Patch early 7.8 high 20.5% 2017-12-06
CVE-2000-0676 EXP Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a… Patch early 5.0 medium 20.5% 2000-10-20
CVE-2016-4175 EXP Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to… Patch early 8.8 high 20.5% 2016-07-13
CVE-2016-4179 EXP Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to… Patch early 8.8 high 20.5% 2016-07-13
CVE-2008-0237 EXP The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure Sav… Patch early 6.8 medium 20.5% 2008-01-11
CVE-1999-0681 EXP Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause… Patch early 5.0 medium 20.5% 2001-03-12
CVE-2013-1598 EXP A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, whi… Patch early 8.8 high 20.5% 2020-01-24
CVE-2024-38200 EXP Microsoft Office Spoofing Vulnerability Patch early 6.5 medium 20.5% 2024-08-12
CVE-2016-4071 EXP Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows r… Patch early 9.8 critical 20.5% 2016-05-20
CVE-2014-1769 EXP Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… Patch early 9.3 high 20.5% 2014-06-11
CVE-2014-1774 EXP Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web sit… Patch early 9.3 high 20.5% 2014-06-11
CVE-2014-1788 EXP Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web sit… Patch early 9.3 high 20.5% 2014-06-11
← previous page 137 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt