peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,759 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

25,086 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-1661 EXP Stack-based buffer overflow in DoubleTake.exe in HP StorageWorks Storage Mirroring (SWSM) before 4.5 SP2 allows remote attackers to execute arbitrary… Patch early 10.0 high 69% 2008-06-04
CVE-2001-0506 EXP Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long fil… Patch early 7.2 high 68.9% 2001-09-20
CVE-2013-2367 EXP Multiple unspecified vulnerabilities in HP SiteScope 11.20 and 11.21, when SOAP is used, allow remote attackers to execute arbitrary code via unknown… Patch early 10.0 high 68.9% 2013-07-31
CVE-2009-0695 EXP hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access… Patch early 7.5 high 68.9% 2012-06-19
CVE-2016-7286 EXP The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafte… Patch early 7.5 high 68.9% 2016-12-20
CVE-2016-7287 EXP The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of servi… Patch early 7.5 high 68.9% 2016-12-20
CVE-2019-10867 EXP An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will m… Patch early 8.8 high 68.9% 2019-04-04
CVE-2021-34621 EXP A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it p… Patch early 9.8 critical 68.9% 2021-07-07
CVE-2005-0308 EXP Buffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code via a large import or export fu… Patch early 7.5 high 68.9% 2005-01-24
CVE-2003-0050 EXP parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary… Patch early 7.5 high 68.9% 2003-03-07
CVE-2013-3215 EXP vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function. Patch early 9.8 critical 68.8% 2020-01-29
CVE-2007-0785 EXP PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote attackers to execute arbitrary… Patch early 7.5 high 68.8% 2007-02-06
CVE-2008-0960 EXP SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Ses… Patch early 10.0 high 68.8% 2008-06-10
CVE-2014-6039 EXP ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000. Patch early 7.5 high 68.8% 2020-01-13
CVE-2006-1255 EXP Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause a denial of service (applicat… Patch early 10.0 high 68.8% 2006-03-19
CVE-2007-2545 EXP Multiple PHP remote file inclusion vulnerabilities in Persism CMS 0.9.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 68.8% 2007-05-09
CVE-2000-0886 EXP IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating sys… Patch early 7.5 high 68.7% 2000-12-19
CVE-2023-40028 EXP Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload… Patch early 4.9 medium 68.7% 2023-08-15
CVE-2017-8670 EXP Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current… Patch early 7.5 high 68.7% 2017-08-08
CVE-2012-5687 EXP Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and… Patch early 7.8 high 68.7% 2012-11-01
CVE-2007-4313 EXP PHP remote file inclusion vulnerability in public_includes/pub_blocks/activecontent.php in Php Blue Dragon CMS 3.0.0 allows remote attackers to execut… Patch early 6.8 medium 68.7% 2007-08-13
CVE-2004-0567 EXP The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows S… Patch early 7.5 high 68.7% 2004-12-31
CVE-2009-2990 EXP Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitr… Patch early 9.3 high 68.7% 2009-10-19
CVE-2007-3057 EXP PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attackers to exec… Patch early 6.8 medium 68.7% 2007-06-06
CVE-2018-10594 EXP Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS… Patch early 9.8 critical 68.6% 2018-06-26
CVE-2015-7611 EXP Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified ve… Patch early 8.1 high 68.6% 2016-06-07
CVE-2009-2227 EXP Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrary code via a crafted request t… Patch early 10.0 high 68.6% 2009-06-26
CVE-2019-9053 EXP An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-ba… Patch early 8.1 high 68.6% 2019-03-26
CVE-2020-13951 EXP Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack. Patch early 7.5 high 68.6% 2020-09-30
CVE-2018-11646 EXP webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKit, as use… Patch early 7.5 high 68.6% 2018-06-01
← previous page 47 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt