peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,939 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

12,661 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-6008 EXP Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter. Patch early 7.5 high 36.8% 2018-01-29
CVE-2015-3042 EXP Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to… Patch early 10.0 high 36.8% 2015-04-14
CVE-2017-13872 EXP An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The issue involves the "Directory Ut… Patch early 8.1 high 36.8% 2017-11-29
CVE-2009-0119 EXP Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly… Patch early 10.0 high 36.7% 2009-01-14
CVE-2010-2343 EXP Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbitrary code via a crafted pls p… Patch early 9.3 high 36.7% 2010-06-21
CVE-2009-3853 EXP Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 be… Patch early 9.3 high 36.7% 2009-11-04
CVE-2003-0111 EXP The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote… Patch early 7.5 high 36.7% 2003-05-05
CVE-2007-5660 EXP Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2… Patch early 9.3 high 36.6% 2007-11-02
CVE-2007-0352 EXP Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt fi… Patch early 9.3 high 36.6% 2007-01-19
CVE-2007-2193 EXP Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build 195 allows user-assisted remo… Patch early 9.3 high 36.6% 2007-04-24
CVE-2007-3490 EXP Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified vectors, possibly related to t… Patch early 7.5 high 36.6% 2007-06-29
CVE-2017-0084 EXP Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT… Patch early 8.8 high 36.5% 2017-03-17
CVE-2009-0546 EXP Stack-based buffer overflow in NewsGator FeedDemon 2.7 and earlier allows user-assisted remote attackers to execute arbitrary code via a long text att… Patch early 9.3 high 36.5% 2009-02-12
CVE-2007-0018 EXP Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers… Patch early 9.3 high 36.5% 2007-01-24
CVE-2016-4232 EXP Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to… Patch early 7.5 high 36.5% 2016-07-13
CVE-2018-7582 EXP WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to TCP port 9991. Patch early 7.5 high 36.4% 2018-03-09
CVE-2011-3490 EXP Multiple stack-based buffer overflows in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to cause a denial of service (cr… Patch early 10.0 high 36.4% 2011-09-16
CVE-2008-5790 EXP Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla! allow remote attackers to ex… Patch early 7.5 high 36.4% 2008-12-31
CVE-2015-2461 EXP ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Wind… Patch early 9.3 high 36.4% 2015-08-15
CVE-2012-4924 EXP Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 allows remote attackers to execut… Patch early 9.3 high 36.3% 2012-09-15
CVE-2009-1831 EXP The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted… Patch early 9.3 high 36.3% 2009-05-29
CVE-2012-0284 EXP Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.ocx on the Cisco WVC200 Wireles… Patch early 9.3 high 36.3% 2012-07-19
CVE-2009-0215 EXP Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo comp… Patch early 9.3 high 36.3% 2009-03-25
CVE-2022-26965 EXP In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution. Patch early 7.2 high 36.3% 2022-03-18
CVE-2008-5664 EXP Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows remote attackers to execute a… Patch early 9.3 high 36.2% 2008-12-19
CVE-2008-3878 EXP Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows r… Patch early 9.3 high 36.2% 2008-09-02
CVE-2007-2884 EXP Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption)… Patch early 9.3 high 36.2% 2007-05-30
CVE-2021-42697 EXP Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to… Patch early 7.5 high 36.1% 2021-11-02
CVE-2011-2763 EXP The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitrary commands via a modified req… Patch early 7.5 high 36.1% 2011-09-02
CVE-2007-3410 EXP Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPlayer 10, 10.1, and possibly 10.… Patch early 9.3 high 36.1% 2007-06-26
← previous page 61 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt