peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-2383 EXP Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from othe… Patch early 5.1 medium 20% 2004-12-31
CVE-2008-1765 EXP Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remote attackers and physically pro… Patch early 9.3 high 20% 2008-04-23
CVE-2017-4901 EXP The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory acce… Patch early 9.9 critical 19.9% 2017-06-08
CVE-1999-0107 EXP Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a lar… Patch early 5.0 medium 19.9% 1997-12-30
CVE-2016-3387 EXP Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain… Patch early 7.5 high 19.9% 2016-10-14
CVE-2008-6347 EXP PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b component for Joomla! allows r… Patch early 7.5 high 19.9% 2009-03-02
CVE-2018-1322 EXP An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x whi… Patch early 4.9 medium 19.9% 2018-03-20
CVE-2019-9791 EXP The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMo… Patch early 9.8 critical 19.9% 2019-04-26
CVE-2007-0168 EXP The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Prote… Patch early 7.5 high 19.9% 2007-01-11
CVE-2002-0540 EXP Nortel CVX 1800 is installed with a default "public" community string, which allows remote attackers to read usernames and passwords and modify the CV… Patch early 7.5 high 19.9% 2002-07-03
CVE-2017-16921 EXP In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged i… Patch early 8.8 high 19.9% 2017-12-08
CVE-2016-4273 EXP Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to… Patch early 8.8 high 19.9% 2016-10-13
CVE-2007-5466 EXP Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strings to the… Patch early 10.0 high 19.9% 2007-10-15
CVE-2006-1982 EXP Heap-based buffer overflow in the LZWDecodeVector function in Mac OS X before 10.4.6, as used in applications that use ImageIO or AppKit, allows remot… Patch early 7.5 high 19.9% 2006-04-21
CVE-2015-5568 EXP Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Ado… Patch early 10.0 high 19.9% 2015-09-22
CVE-2007-0977 EXP IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible thro… Patch early 7.1 high 19.9% 2007-02-16
CVE-2012-2376 EXP Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted a… Patch early 10.0 high 19.8% 2012-05-21
CVE-2019-19742 EXP On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field. Patch early 4.8 medium 19.8% 2019-12-18
CVE-2005-3207 EXP The forms servlet (f90servlet) in Oracle Forms 4.5.10.22 allows remote attackers to cause a denial of service (TNS listener stop) via a userid paramet… Patch early 5.0 medium 19.8% 2005-10-14
CVE-2007-1399 EXP Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to e… Patch early 9.8 critical 19.8% 2007-03-10
CVE-2015-4148 EXP The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property i… Patch early 5.0 medium 19.8% 2015-06-09
CVE-2000-0061 EXP Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, whic… Patch early 10.0 high 19.8% 2000-01-07
CVE-2021-43617 EXP Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttr… Patch early 9.8 critical 19.8% 2021-11-14
CVE-2014-8768 EXP Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denia… Patch early 5.0 medium 19.8% 2014-11-20
CVE-2018-5726 EXP MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to obtain sensitive information via a crafted HTTP request, as demonstrated by the usernam… Patch early 9.8 critical 19.8% 2018-01-16
CVE-2006-5972 EXP Stack-based buffer overflow in WG111v2.SYS in NetGear WG111v2 wireless adapter (USB) allows remote attackers to execute arbitrary code via a long 802.… Patch early 10.0 high 19.8% 2006-11-18
CVE-2010-1349 EXP Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Length value, which triggers a hea… Patch early 10.0 high 19.8% 2010-04-12
CVE-2018-4934 EXP Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to informa… Patch early 6.5 medium 19.8% 2018-05-19
CVE-2019-18951 EXP SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files. Patch early 7.5 high 19.8% 2019-11-13
CVE-2020-24215 EXP An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP re… Patch early 9.8 critical 19.8% 2020-10-06
← previous page 140 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt