peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,579 CVEs 1,726 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

12,661 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-7286 EXP The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafte… Patch early 7.5 high 68.9% 2016-12-20
CVE-2016-7287 EXP The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of servi… Patch early 7.5 high 68.9% 2016-12-20
CVE-2019-10867 EXP An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will m… Patch early 8.8 high 68.9% 2019-04-04
CVE-2003-0050 EXP parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary… Patch early 7.5 high 68.9% 2003-03-07
CVE-2005-0308 EXP Buffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code via a large import or export fu… Patch early 7.5 high 68.9% 2005-01-24
CVE-2007-0785 EXP PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote attackers to execute arbitrary… Patch early 7.5 high 68.8% 2007-02-06
CVE-2008-0960 EXP SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Ses… Patch early 10.0 high 68.8% 2008-06-10
CVE-2014-6039 EXP ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000. Patch early 7.5 high 68.8% 2020-01-13
CVE-2006-1255 EXP Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause a denial of service (applicat… Patch early 10.0 high 68.8% 2006-03-19
CVE-2007-2545 EXP Multiple PHP remote file inclusion vulnerabilities in Persism CMS 0.9.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 68.8% 2007-05-09
CVE-2000-0886 EXP IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating sys… Patch early 7.5 high 68.7% 2000-12-19
CVE-2017-8670 EXP Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current… Patch early 7.5 high 68.7% 2017-08-08
CVE-2012-5687 EXP Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and… Patch early 7.8 high 68.7% 2012-11-01
CVE-2004-0567 EXP The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows S… Patch early 7.5 high 68.7% 2004-12-31
CVE-2009-2990 EXP Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitr… Patch early 9.3 high 68.7% 2009-10-19
CVE-2015-7611 EXP Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified ve… Patch early 8.1 high 68.6% 2016-06-07
CVE-2009-2227 EXP Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrary code via a crafted request t… Patch early 10.0 high 68.6% 2009-06-26
CVE-2019-9053 EXP An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-ba… Patch early 8.1 high 68.6% 2019-03-26
CVE-2020-13951 EXP Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack. Patch early 7.5 high 68.6% 2020-09-30
CVE-2018-11646 EXP webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKit, as use… Patch early 7.5 high 68.6% 2018-06-01
CVE-2005-0684 EXP Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET reque… Patch early 10.0 high 68.5% 2005-04-25
CVE-2018-8631 EXP A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vu… Patch early 7.5 high 68.5% 2018-12-12
CVE-2017-11893 EXP ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the contex… Patch early 7.5 high 68.5% 2017-12-12
CVE-2017-9833 EXP /cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NO… Patch early 7.5 high 68.5% 2017-06-24
CVE-2001-0537 EXP HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being use… Patch early 9.3 high 68.5% 2001-07-21
CVE-2012-1195 EXP Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkMa… Patch early 7.5 high 68.4% 2012-02-18
CVE-2006-0460 EXP Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error messages. Patch early 7.5 high 68.4% 2006-02-17
CVE-2015-1486 EXP The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a… Patch early 7.5 high 68.3% 2015-08-01
CVE-2006-1359 EXP Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain crea… Patch early 9.3 high 68.3% 2006-03-23
CVE-2001-1320 EXP Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via exceptional… Patch early 7.5 high 68.3% 2001-07-16
← previous page 28 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt