peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,121 CVEs 1,733 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-1415 EXP Multiple PHP remote file inclusion vulnerabilities in PMB Services 3.0.13 and earlier allow remote attackers to execute arbitrary PHP code via a URL i… Patch early 7.5 high 9.3% 2007-03-12
CVE-2017-2464 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… Patch early 8.8 high 9.3% 2017-04-02
CVE-2013-2560 EXP Directory traversal vulnerability in the web interface on Foscam devices with firmware before 11.37.2.49 allows remote attackers to read arbitrary fil… Patch early 7.8 high 9.3% 2013-03-15
CVE-2009-4219 EXP Stack-based buffer overflow in the MYACTIVEX.MyActiveXCtrl.1 ActiveX control in MyActiveX.ocx 1.4.8.0 in Haihaisoft Universal Player allows remote att… Patch early 9.3 high 9.3% 2009-12-07
CVE-2007-0635 EXP Multiple PHP remote file inclusion vulnerabilities in EncapsCMS 0.3.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) config… Patch early 7.5 high 9.3% 2007-01-31
CVE-2011-0018 EXP The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authenticated users to execute arbitr… Patch early 9.0 high 9.3% 2011-01-28
CVE-2019-5789 EXP An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed a remote attacker who had comp… Patch early 8.8 high 9.3% 2019-05-23
CVE-2014-9208 EXP Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitrary code vi… Patch early 10.0 high 9.3% 2015-09-11
CVE-2013-3431 EXP Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers… Patch early 7.8 high 9.3% 2013-07-25
CVE-2009-2344 EXP The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges v… Patch early 9.0 high 9.3% 2009-07-07
CVE-2004-1888 EXP display.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file variable. Patch early 7.5 high 9.3% 2004-12-31
CVE-2008-3162 EXP Stack-based buffer overflow in the str_read_packet function in libavformat/psxstr.c in FFmpeg before r13993 allows remote attackers to cause a denial… Patch early 9.3 high 9.3% 2008-07-14
CVE-2010-5028 EXP SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 9.2% 2011-11-02
CVE-2002-1275 EXP Unknown vulnerability in html2ps HTML/PostScript converter 1.0, when used within LPRng, allows remote attackers to execute arbitrary code via "unsanit… Patch early 7.5 high 9.2% 2002-11-12
CVE-2007-4821 EXP Buffer overflow in a certain ActiveX control in officeviewer.ocx 5.2.218.1 in EDraw Office Viewer Component 5.2 allows remote attackers to execute arb… Patch early 9.3 high 9.2% 2007-09-11
CVE-2008-0096 EXP Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to execute arbitrary code via a (1)… Patch early 7.5 high 9.2% 2008-01-08
CVE-2010-1869 EXP Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a cra… Patch early 9.3 high 9.2% 2010-05-12
CVE-2003-0767 EXP Buffer overflow in RogerWilco graphical server 1.4.1.6 and earlier, dedicated server 0.32a and earlier for Windows, and 0.27 and earlier for Linux and… Patch early 7.5 high 9.2% 2003-09-17
CVE-2008-0778 EXP Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow remote attackers to cause a de… Patch early 7.5 high 9.2% 2008-02-14
CVE-2016-8023 EXP Authentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote un… Patch early 8.1 high 9.2% 2017-03-14
CVE-2000-0787 EXP IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which XC… Patch early 7.5 high 9.2% 2000-10-20
CVE-2008-5183 EXP cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large numbe… Patch early 7.5 high 9.2% 2008-11-21
CVE-2008-4101 EXP Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands b… Patch early 9.3 high 9.2% 2008-09-18
CVE-2015-5895 EXP Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors. Patch early 10.0 high 9.2% 2015-09-18
CVE-2011-1519 EXP The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specif… Patch early 10.0 high 9.2% 2011-03-25
CVE-2018-6092 EXP An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code insid… Patch early 8.8 high 9.2% 2018-12-04
CVE-2022-26982 EXP SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because… Patch early 7.2 high 9.2% 2022-04-05
CVE-2014-7226 EXP The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with… Patch early 7.5 high 9.2% 2014-10-10
CVE-2021-46360 EXP Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrary code via uploading a PHP she… Patch early 8.8 high 9.2% 2022-02-09
CVE-2011-2194 EXP Integer overflow in the XSPF playlist parser in VideoLAN VLC media player 0.8.5 through 1.1.9 allows remote attackers to cause a denial of service (cr… Patch early 9.3 high 9.2% 2011-06-24
← previous page 137 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt