peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,733 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

12,661 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-3357 EXP Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word… Patch early 7.8 high 54.8% 2016-09-14
CVE-2007-2222 EXP Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explor… Patch early 9.3 high 54.7% 2007-06-12
CVE-2007-2888 EXP Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrary code via a long FILE string… Patch early 7.6 high 54.7% 2007-05-30
CVE-2012-0270 EXP Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a crafted (1) hetro file to the get… Patch early 7.5 high 54.7% 2014-02-17
CVE-2011-5124 EXP Stack-based buffer overflow in the BCAAA component before build 60258, as used by Blue Coat ProxySG 4.2.3 through 6.1 and ProxyOne, allows remote atta… Patch early 10.0 high 54.6% 2012-08-26
CVE-2007-1765 EXP Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (… Patch early 9.3 high 54.6% 2007-03-30
CVE-2009-4223 EXP PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 54.6% 2009-12-07
CVE-2017-8657 EXP Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the cu… Patch early 7.5 high 54.6% 2017-08-08
CVE-2008-3008 EXP Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series allows remote attackers… Patch early 9.3 high 54.6% 2008-09-11
CVE-2019-16667 EXP diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs be… Patch early 8.8 high 54.5% 2019-09-26
CVE-2009-1730 EXP Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read or modify arbitrary files via… Patch early 10.0 high 54.5% 2009-05-20
CVE-2016-2056 EXP xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the a… Patch early 8.8 high 54.5% 2016-04-13
CVE-2012-0202 EXP Multiple stack-based buffer overflows in tm1admsd.exe in the Admin Server in IBM Cognos TM1 9.4.x and 9.5.x before 9.5.2 FP2 allow remote attackers to… Patch early 10.0 high 54.5% 2012-05-04
CVE-2002-0371 EXP Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to exec… Patch early 7.5 high 54.4% 2002-07-03
CVE-2007-3040 EXP Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a… Patch early 9.3 high 54.4% 2007-09-12
CVE-2011-0027 EXP Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation f… Patch early 9.3 high 54.4% 2011-01-12
CVE-2019-6453 EXP mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc://… Patch early 8.1 high 54.3% 2019-02-18
CVE-2018-18326 EXP DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue e… Patch early 7.5 high 54.3% 2019-07-03
CVE-1999-0661 EXP A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) u… Patch early 10.0 high 54.2% 1999-01-01
CVE-2017-8487 EXP Windows OLE in Windows XP and Windows Server 2003 allows an attacker to execute code when a victim opens a specially crafted file or program aka "Wind… Patch early 7.8 high 54.1% 2017-06-15
CVE-2001-0800 EXP lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters. Patch early 10.0 high 54.1% 2001-12-06
CVE-2019-19609 EXP The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel,… Patch early 7.2 high 54.1% 2019-12-05
CVE-2010-1663 EXP The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy… Patch early 10.0 high 54.1% 2010-05-03
CVE-2006-2379 EXP Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers t… Patch early 9.3 high 54.1% 2006-06-13
CVE-2008-1610 EXP Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service or execute arbitrary code via a… Patch early 7.5 high 53.9% 2008-04-01
CVE-2007-3896 EXP The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attack… Patch early 9.3 high 53.8% 2007-10-11
CVE-2008-0550 EXP Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a c… Patch early 10.0 high 53.8% 2008-02-01
CVE-2016-5676 EXP cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows r… Patch early 7.5 high 53.7% 2016-08-31
CVE-2008-4255 EXP Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0,… Patch early 9.3 high 53.7% 2008-12-10
CVE-2006-3459 EXP Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow context-depe… Patch early 7.5 high 53.7% 2006-08-03
← previous page 43 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt