peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,893 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-0013 EXP Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arb… Patch early 7.5 high 12.5% 2010-01-09
CVE-2014-5246 EXP The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain administrator access… Patch early 10.0 high 12.5% 2014-08-22
CVE-2008-2321 EXP Unspecified vulnerability in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of… Patch early 9.3 high 12.5% 2008-08-04
CVE-2006-0306 EXP The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Back… Patch early 5.0 medium 12.5% 2006-01-19
CVE-2018-10824 EXP An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-… Patch early 9.8 critical 12.5% 2018-10-17
CVE-2017-14095 EXP A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution… Patch early 8.1 high 12.5% 2018-01-19
CVE-2022-28213 EXP When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the X… Patch early 8.1 high 12.5% 2022-04-12
CVE-2016-7065 EXP The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and poss… Patch early 8.8 high 12.5% 2016-10-13
CVE-2012-0547 EXP Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has n… Patch early 0.0 low 12.5% 2012-08-30
CVE-2007-5184 EXP Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute arbitrary code via format strin… Patch early 7.5 high 12.5% 2007-10-03
CVE-2016-7567 EXP Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact via a craf… Patch early 9.8 critical 12.5% 2017-01-23
CVE-2009-3613 EXP The swiotlb functionality in the r8169 driver in drivers/net/r8169.c in the Linux kernel before 2.6.27.22 allows remote attackers to cause a denial of… Patch early 7.8 high 12.5% 2009-10-19
CVE-2006-2554 EXP Buffer overflow in the tell_player_surr_changes function in Genecys 0.2 and earlier might allow remote attackers to execute arbitrary code via long ar… Patch early 6.4 medium 12.5% 2006-05-24
CVE-1999-0178 EXP Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a… Patch early 7.5 high 12.5% 1997-01-01
CVE-2006-1260 EXP Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which… Patch early 5.0 medium 12.5% 2006-03-19
CVE-2005-3507 EXP Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" se… Patch early 5.0 medium 12.4% 2005-11-06
CVE-2010-1033 EXP Multiple stack-based buffer overflows in a certain Tetradyne ActiveX control in HP Operations Manager 7.5, 8.10, and 8.16 might allow remote attackers… Patch early 9.3 high 12.4% 2010-04-21
CVE-2019-11448 EXP An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the s… Patch early 9.8 critical 12.4% 2019-04-22
CVE-2020-23342 EXP A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users. Patch early 8.8 high 12.4% 2021-01-19
CVE-2021-25155 EXP A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x… Patch early 6.5 medium 12.4% 2021-03-30
CVE-2015-3796 EXP The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute arbitrary code or cause a deni… Patch early 7.5 high 12.4% 2015-08-17
CVE-2015-3292 EXP The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, whi… Patch early 10.0 high 12.4% 2015-05-31
CVE-2000-0733 EXP Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrar… Patch early 10.0 high 12.4% 2000-10-20
CVE-2008-0234 EXP Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute… Patch early 9.3 high 12.4% 2008-01-11
CVE-2009-4496 EXP Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title,… Patch early 5.0 medium 12.4% 2010-01-13
CVE-2004-1286 EXP Buffer overflow in the auto_filter_extern function in auto.c for NapShare 1.2, with the extern filter enabled, allows remote attackers to execute arbi… Patch early 10.0 high 12.4% 2005-01-10
CVE-2006-1015 EXP Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additi… Patch early 6.4 medium 12.4% 2006-03-07
CVE-2005-1261 EXP Stack-based buffer overflow in the URL parsing function in Gaim before 1.3.0 allows remote attackers to execute arbitrary code via an instant message… Patch early 7.5 high 12.4% 2005-05-11
CVE-2014-2044 EXP Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass int… Patch early 7.5 high 12.4% 2014-10-06
CVE-2017-0785 EXP A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1… Patch early 6.5 medium 12.4% 2017-09-14
← previous page 188 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt