peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,957 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-0388 EXP Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap… Patch early 10.0 high 13.3% 2009-02-04
CVE-2010-3709 EXP The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of… Patch early 4.3 medium 13.3% 2010-11-09
CVE-2019-8017 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 9.8 critical 13.3% 2019-08-20
CVE-2015-3798 EXP The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute arbitrary code or cause a deni… Patch early 7.5 high 13.3% 2015-08-17
CVE-2018-8880 EXP Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing the /deviceIP information, which… Patch early 7.5 high 13.3% 2018-04-23
CVE-2019-12477 EXP Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authe… Patch early 5.5 medium 13.3% 2019-06-07
CVE-2002-1605 EXP Buffer overflow in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows attackers to execute arbitrary code via a long _XKB_CHARSET environment variab… Patch early 7.5 high 13.3% 2002-09-02
CVE-2007-1721 EXP Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 10.0 high 13.3% 2007-03-28
CVE-2015-4153 EXP Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to include and execute arb… Patch early 5.0 medium 13.3% 2015-06-10
CVE-2007-3473 EXP The gdImageCreateXbm function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (cra… Patch early 4.3 medium 13.3% 2007-06-28
CVE-2020-35775 EXP CITSmart before 9.1.2.23 allows LDAP Injection. Patch early 9.8 critical 13.3% 2021-02-15
CVE-2019-9599 EXP The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash) via many simultaneous sdctl/… Patch early 7.5 high 13.3% 2019-03-06
CVE-2013-4858 EXP Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) via a crafted .wav… Patch early 4.3 medium 13.3% 2013-12-30
CVE-2001-0008 EXP Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures. Patch early 10.0 high 13.3% 2001-02-12
CVE-2019-10266 EXP An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the f… Patch early 7.5 high 13.3% 2019-07-26
CVE-2009-5114 EXP Directory traversal vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 5.0 medium 13.3% 2012-03-19
CVE-2009-1376 EXP Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpu… Patch early 9.3 high 13.3% 2009-05-26
CVE-2009-2195 EXP Buffer overflow in WebKit in Apple Safari before 4.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application cra… Patch early 9.3 high 13.3% 2009-08-12
CVE-2015-7805 EXP Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF fi… Patch early 9.3 high 13.3% 2015-11-17
CVE-2015-2791 EXP The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a craft… Patch early 6.4 medium 13.3% 2015-03-30
CVE-2016-7998 EXP The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML fil… Patch early 8.8 high 13.3% 2017-01-18
CVE-2016-8022 EXP Authentication bypass by spoofing vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated… Patch early 7.5 high 13.3% 2017-03-14
CVE-1999-0487 EXP The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files. Patch early 2.6 low 13.3% 1999-05-01
CVE-1999-0793 EXP Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet. Patch early 2.6 low 13.3% 1999-11-17
CVE-2012-2027 EXP Use-after-free vulnerability in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary cod… Patch early 9.3 high 13.3% 2012-05-09
CVE-2019-8613 EXP A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote attacker may… Patch early 9.8 critical 13.3% 2019-12-18
CVE-2006-2548 EXP Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url… Patch early 7.5 high 13.3% 2006-05-23
CVE-2007-4430 EXP Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routi… Patch early 5.0 medium 13.3% 2007-08-20
CVE-2019-12828 EXP An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and origin2:// URI schemes, it is poss… Patch early 8.8 high 13.3% 2019-06-14
CVE-2011-1468 EXP Multiple memory leaks in the OpenSSL extension in PHP before 5.3.6 might allow remote attackers to cause a denial of service (memory consumption) via… Patch early 4.3 medium 13.3% 2011-03-20
← previous page 180 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt