peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,929 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

12,661 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-1806 EXP The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access,… Patch early 10.0 high 39.6% 2014-05-14
CVE-2012-6066 EXP freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demonstrated by an OpenSSH client wi… Patch early 9.3 high 39.5% 2012-12-04
CVE-2011-3478 EXP The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12… Patch early 10.0 high 39.5% 2012-01-25
CVE-2002-1412 EXP Gallery photo album package before 1.3.1 allows local and possibly remote attackers to execute arbitrary code via a modified GALLERY_BASEDIR variable… Patch early 7.5 high 39.5% 2003-04-11
CVE-2016-0111 EXP Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corr… Patch early 7.5 high 39.4% 2016-03-09
CVE-2003-0113 EXP Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response… Patch early 7.5 high 39.4% 2003-05-12
CVE-2008-0115 EXP Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office for Mac 2004 allows user-assisted remo… Patch early 9.3 high 39.3% 2008-03-11
CVE-2013-4800 EXP Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1735. Patch early 9.3 high 39.3% 2013-07-29
CVE-2018-10822 EXP Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2… Patch early 7.5 high 39.3% 2018-10-17
CVE-2015-3128 EXP Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.4… Patch early 10.0 high 39.2% 2015-07-09
CVE-2010-3189 EXP The extSetOwner function in the UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll) in Trend Micro Internet Security Pro 2010 allows remote attackers to… Patch early 9.3 high 39.2% 2010-08-31
CVE-2003-1026 EXP Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added… Patch early 9.3 high 39.2% 2004-01-20
CVE-2008-1903 EXP PHP remote file inclusion vulnerability in news_show.php in Newanz NewsOffice 1.0 and 1.1, when register_globals is enabled, allows remote attackers t… Patch early 7.5 high 39.2% 2008-04-22
CVE-2008-5763 EXP PHP remote file inclusion vulnerability in slogin_lib.inc.php in Simple Text-File Login Script (SiTeFiLo) 1.0.6 allows remote attackers to execute arb… Patch early 7.5 high 39.2% 2008-12-30
CVE-2011-4786 EXP A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an arbitrary program… Patch early 9.3 high 39.2% 2012-01-12
CVE-2012-0439 EXP An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arb… Patch early 9.3 high 39.2% 2013-02-24
CVE-2006-1491 EXP Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitra… Patch early 7.5 high 39.2% 2006-03-29
CVE-2016-0108 EXP Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… Patch early 7.5 high 39.2% 2016-03-09
CVE-2004-1166 EXP CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via an… Patch early 7.5 high 39.2% 2004-12-31
CVE-2011-4825 EXP Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6… Patch early 7.5 high 39.2% 2011-12-15
CVE-2016-0063 EXP Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch early 8.8 high 39.1% 2016-02-10
CVE-2013-1309 EXP Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that… Patch early 9.3 high 39.1% 2013-05-15
CVE-2023-32235 EXP Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory travers… Patch early 7.5 high 39.1% 2023-05-05
CVE-2008-1963 EXP PHP remote file inclusion vulnerability in includes/functions.php in Quate Grape Web Statistics 0.2a allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 39% 2008-04-25
CVE-2008-2645 EXP Multiple PHP remote file inclusion vulnerabilities in Brim (formerly Booby) 1.0.1 allow remote attackers to execute arbitrary PHP code via a URL in th… Patch early 7.5 high 39% 2008-06-10
CVE-2017-0283 EXP Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1… Patch early 8.8 high 39% 2017-06-15
CVE-2008-1472 EXP Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5… Patch early 9.3 high 39% 2008-03-24
CVE-2018-12054 EXP Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absolute path traversal. Patch early 7.5 high 39% 2018-06-08
CVE-2021-35380 EXP A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious user gain a… Patch early 7.5 high 39% 2022-02-15
CVE-2003-1328 EXP The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to… Patch early 7.5 high 38.9% 2003-02-19
← previous page 57 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt