peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,317 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-40946 EXP On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via the sys_token parameter in a cg… Patch early 7.5 high 7.5% 2023-04-16
CVE-2011-4644 EXP Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally does… Patch early 9.3 high 7.5% 2012-01-03
CVE-2011-5002 EXP Multiple stack-based buffer overflows in Final Draft 8 before 8.02 allow remote attackers to execute arbitrary code via a .fdx or .fdxt file with long… Patch early 10.0 high 7.5% 2011-12-25
CVE-2008-5680 EXP Multiple buffer overflows in Opera before 9.63 might allow (1) remote attackers to execute arbitrary code via a crafted text area, or allow (2) user-a… Patch early 9.3 high 7.5% 2008-12-19
CVE-2018-7449 EXP SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an invalid LIST, STOR, or RETR comm… Patch early 7.5 high 7.5% 2018-03-04
CVE-2015-5074 EXP Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM before 5.0.9… Patch early 7.5 high 7.5% 2015-09-29
CVE-2007-2787 EXP Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in LeadTools Raster Thumbnail Object… Patch early 7.5 high 7.5% 2007-05-21
CVE-2009-0259 EXP The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary c… Patch early 9.3 high 7.5% 2009-01-22
CVE-2010-3000 EXP Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows… Patch early 9.3 high 7.5% 2010-08-30
CVE-2016-7098 EXP Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass inte… Patch early 8.1 high 7.5% 2016-09-26
CVE-2007-1029 EXP Stack-based buffer overflow in the Connect method in the IMAP4 component in Quiksoft EasyMail Objects before 6.5 allows remote attackers to execute ar… Patch early 7.6 high 7.5% 2007-02-21
CVE-2022-39290 EXP ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by mod… Patch early 8.0 high 7.5% 2022-10-07
CVE-2018-20735 EXP An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement and escalation… Patch early 7.8 high 7.5% 2019-01-17
CVE-2014-9262 EXP The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files. Patch early 8.2 high 7.5% 2017-08-07
CVE-2007-5248 EXP Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3… Patch early 9.3 high 7.5% 2007-10-06
CVE-2011-4221 EXP Unspecified vulnerability in Investintech.com Able2Doc and Able2Doc Professional allows remote attackers to cause a denial of service (application cra… Patch early 9.3 high 7.5% 2011-11-01
CVE-2011-4222 EXP Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a denial of service (application c… Patch early 9.3 high 7.5% 2011-11-01
CVE-2007-1074 EXP Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long (1) DataPa… Patch early 9.3 high 7.5% 2007-02-22
CVE-2006-7236 EXP The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attacke… Patch early 9.3 high 7.5% 2009-01-02
CVE-2001-0262 EXP Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL. Patch early 7.5 high 7.5% 2001-07-02
CVE-2004-1926 EXP Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4)… Patch early 7.5 high 7.5% 2004-04-11
CVE-2011-1984 EXP WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over th… Patch early 7.2 high 7.5% 2011-09-15
CVE-2007-3360 EXP hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data containing NICK and EXEC strings,… Patch early 9.3 high 7.5% 2007-06-22
CVE-2021-43116 EXP An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and th… Patch early 8.8 high 7.5% 2022-07-05
CVE-1999-0347 EXP Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which caus… Patch early 10.0 high 7.5% 1999-01-26
CVE-2010-0655 EXP Use-after-free vulnerability in Google Chrome before 4.0.249.78 allows user-assisted remote attackers to cause a denial of service (application crash)… Patch early 9.3 high 7.5% 2010-02-18
CVE-2007-1842 EXP Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a ..… Patch early 7.5 high 7.5% 2007-04-03
CVE-2002-1991 EXP PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php. Patch early 7.5 high 7.5% 2002-12-31
CVE-2014-5370 EXP Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDragon before 7.1.1.18527 allows… Patch early 7.5 high 7.5% 2015-04-21
CVE-2007-1471 EXP admin/default.asp in Orion-Blog 2.0 allows remote attackers to bypass authentication controls and gain privileges via a direct URL request for admin/A… Patch early 7.5 high 7.4% 2007-03-16
← previous page 157 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt