peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,032 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-3376 EXP The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R… Patch early 7.8 high 12.8% 2016-10-14
CVE-2007-5607 EXP Buffer overflow in the RegistryString function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1… Patch early 7.5 high 12.8% 2008-06-04
CVE-2007-3697 EXP PHP remote file inclusion vulnerability in phpbb/sendmsg.php in FlashBB 1.1.8 and earlier allows remote attackers to execute arbitrary code via a URL… Patch early 7.5 high 12.8% 2007-07-11
CVE-1999-0896 EXP Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and passwo… Patch early 10.0 high 12.8% 1999-11-04
CVE-2004-2275 EXP i-mall.cgi in I-Mall Commerce allows remote attackers to execute arbitrary commands via shell metacharacters via the p parameter. Patch early 10.0 high 12.8% 2004-12-31
CVE-2018-9022 EXP An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands… Patch early 9.8 critical 12.8% 2018-06-18
CVE-2018-6911 EXP The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argumen… Patch early 9.8 critical 12.8% 2018-02-13
CVE-2008-0443 EXP Heap-based buffer overflow in the FileUploader.FUploadCtl.1 ActiveX control in FileUploader.dll 2.0.0.2 in Lycos FileUploader Module allows remote att… Patch early 10.0 high 12.8% 2008-01-25
CVE-2020-6627 EXP The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_lau… Patch early 9.8 critical 12.8% 2022-12-06
CVE-2014-6043 EXP ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote a… Patch early 6.5 medium 12.8% 2014-09-11
CVE-2008-1767 EXP Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arb… Patch early 7.5 high 12.8% 2008-05-23
CVE-2008-2935 EXP Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFuncti… Patch early 7.5 high 12.8% 2008-08-01
CVE-2010-4156 EXP The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive inform… Patch early 5.0 medium 12.8% 2010-11-10
CVE-2017-12718 EXP A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. A third-par… Patch early 8.1 high 12.8% 2018-02-15
CVE-2015-2826 EXP WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information. Patch early 5.3 medium 12.8% 2017-09-20
CVE-2021-44664 EXP An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a malicio… Patch early 8.8 high 12.8% 2022-02-24
CVE-2009-0650 EXP Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remote attackers to cause a denial… Patch early 10.0 high 12.8% 2009-02-20
CVE-2009-0693 EXP Multiple buffer overflows in Wyse Device Manager (WDM) 4.7.x allow remote attackers to execute arbitrary code via (1) the User-Agent HTTP header to hs… Patch early 7.5 high 12.8% 2012-06-19
CVE-2018-7448 EXP Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary… Patch early 7.5 high 12.8% 2018-02-26
CVE-2015-0057 EXP win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wind… Patch early 7.2 high 12.8% 2015-02-11
CVE-2014-8498 EXP SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (… Patch early 6.5 medium 12.7% 2014-11-17
CVE-2005-1163 EXP Multiple buffer overflows in Yager 5.24 and earlier allow remote attackers to execute arbitrary code via (1) a crafted nickname or (2) a packet with a… Patch early 6.4 medium 12.7% 2005-05-02
CVE-2003-0886 EXP Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code. Patch early 10.0 high 12.7% 2003-12-01
CVE-2018-8056 EXP Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/manage/channel/addchannel or a d… Patch early 7.5 high 12.7% 2018-03-11
CVE-2013-1601 EXP An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LIN… Patch early 5.3 medium 12.7% 2020-01-28
CVE-1999-0042 EXP Buffer overflow in University of Washington's implementation of IMAP and POP servers. Patch early 10.0 high 12.7% 1997-04-07
CVE-2007-6613 EXP Stack-based buffer overflow in the print_iso9660_recurse function in iso-info (src/iso-info.c) in GNU Compact Disc Input and Control Library (libcdio)… Patch early 5.0 medium 12.7% 2008-01-03
CVE-2011-2577 EXP Unspecified vulnerability in Cisco TelePresence C Series Endpoints, E/EX Personal Video units, and MXP Series Codecs, when using software versions bef… Patch early 7.8 high 12.7% 2011-08-31
CVE-2018-11538 EXP servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token By… Patch early 8.8 high 12.7% 2018-06-01
CVE-2011-1467 EXP Unspecified vulnerability in the NumberFormatter::setSymbol (aka numfmt_set_symbol) function in the Intl extension in PHP before 5.3.6 allows context-… Patch early 5.0 medium 12.7% 2011-03-20
← previous page 185 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt