peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,092 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-4176 EXP Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to… Patch early 8.8 high 17.6% 2016-07-13
CVE-2016-4177 EXP Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to… Patch early 8.8 high 17.6% 2016-07-13
CVE-2008-5191 EXP Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the (1) poll_id parameter to poll.… Patch early 7.5 high 17.6% 2008-11-21
CVE-2007-0356 EXP The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attackers to cause a denial of servic… Patch early 5.0 medium 17.6% 2007-01-19
CVE-2022-4395 EXP The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbit… Patch early 9.8 critical 17.6% 2023-01-30
CVE-2011-2960 EXP Heap-based buffer overflow in httpsvr.exe 6.0.5.3 in Sunway ForceControl 6.1 SP1, SP2, and SP3 allows remote attackers to cause a denial of service (c… Patch early 10.0 high 17.6% 2011-07-29
CVE-2015-3897 EXP Directory traversal vulnerability in Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the theme pa… Patch early 5.0 medium 17.6% 2015-06-18
CVE-2017-5135 EXP Certain Technicolor devices have an SNMP access-control bypass, possibly involving an ISP customization in some cases. The Technicolor (formerly Cisco… Patch early 9.1 critical 17.5% 2017-04-27
CVE-2018-1321 EXP An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1… Patch early 7.2 high 17.5% 2018-03-20
CVE-2026-21876 EXP The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 a… Patch early 9.3 critical 17.5% 2026-01-08
CVE-2025-47228 EXP In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connection settings allows authenticat… Patch early 6.7 medium 17.5% 2025-07-05
CVE-2018-18065 EXP _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to r… Patch early 6.5 medium 17.5% 2018-10-08
CVE-1999-1033 EXP Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to… Patch early 5.0 medium 17.5% 1999-05-11
CVE-2016-3373 EXP The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window… Patch early 5.5 medium 17.5% 2016-09-14
CVE-2002-1688 EXP The browser history feature in Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to execute arbitrary script as other users and stea… Patch early 5.0 medium 17.5% 2002-12-31
CVE-2014-0749 EXP Stack-based buffer overflow in lib/Libdis/disrsi_.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x through 2.… Patch early 10.0 high 17.5% 2014-05-16
CVE-2006-3944 EXP Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via a (1) Forms.ListBox.1 or (2) Forms.Li… Patch early 5.0 medium 17.5% 2006-07-31
CVE-2017-12945 EXP Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers to execute a… Patch early 8.8 high 17.5% 2019-11-27
CVE-2008-5112 EXP The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a failed bind attempt depending… Patch early 5.0 medium 17.4% 2008-11-17
CVE-2004-0393 EXP Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string spec… Patch early 10.0 high 17.4% 2004-12-06
CVE-2005-2308 EXP The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute a… Patch early 7.5 high 17.4% 2005-07-19
CVE-2016-1077 EXP Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… Patch early 9.8 critical 17.4% 2016-05-11
CVE-2017-7240 EXP An issue was discovered on Miele Professional PST10 devices. The corresponding embedded webserver "PST10 WebServer" typically listens to port 80 and i… Patch early 7.5 high 17.4% 2017-03-24
CVE-2002-1850 EXP mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by cau… Patch early 7.5 high 17.4% 2002-12-31
CVE-2020-13448 EXP QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via comma… Patch early 8.8 high 17.4% 2020-06-01
CVE-2023-26602 EXP ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmp… Patch early 9.8 critical 17.4% 2023-02-26
CVE-2006-2811 EXP Multiple PHP remote file inclusion vulnerabilities in Cantico Ovidentia 5.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the ba… Patch early 7.5 high 17.4% 2006-06-05
CVE-2013-5045 EXP Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by lever… Patch early 6.2 medium 17.4% 2013-12-11
CVE-2008-0236 EXP An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary commands by invoking the DoCmd meth… Patch early 5.8 medium 17.4% 2008-01-11
CVE-2009-3019 EXP Microsoft Internet Explorer 6 on Windows XP SP2 and SP3, and Internet Explorer 7 on Vista, allows remote attackers to cause a denial of service (appli… Patch early 5.0 medium 17.4% 2009-08-31
← previous page 150 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt