peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,003 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

12,661 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-15813 EXP Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary code via a webshell. Patch early 8.8 high 33.2% 2019-09-04
CVE-2020-29607 EXP A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "mana… Patch early 7.2 high 33.2% 2020-12-16
CVE-2010-4321 EXP Stack-based buffer overflow in an ActiveX control in ienipp.ocx in Novell iPrint Client 5.52 allows remote attackers to execute arbitrary code via a l… Patch early 9.3 high 33.2% 2010-12-30
CVE-2016-4228 EXP Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.6… Patch early 8.8 high 33.1% 2016-07-13
CVE-2016-4226 EXP Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.6… Patch early 8.8 high 33.1% 2016-07-13
CVE-2021-45043 EXP HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter. Patch early 7.5 high 33.1% 2021-12-15
CVE-2012-2288 EXP Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers t… Patch early 9.3 high 33.1% 2012-09-04
CVE-2018-14716 EXP A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elemen… Patch early 7.5 high 33% 2018-08-06
CVE-2007-4515 EXP Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 all… Patch early 9.3 high 33% 2007-08-31
CVE-2009-1028 EXP Stack-based buffer overflow in ediSys eZip Wizard 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file. Patch early 9.3 high 33% 2009-03-20
CVE-2011-1213 EXP Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via… Patch early 9.3 high 33% 2011-05-31
CVE-2016-4231 EXP Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.6… Patch early 8.8 high 32.9% 2016-07-13
CVE-2016-4227 EXP Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.6… Patch early 8.8 high 32.9% 2016-07-13
CVE-2018-19458 EXP In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability t… Patch early 7.5 high 32.9% 2018-11-22
CVE-2014-1799 EXP Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch early 9.3 high 32.9% 2014-06-11
CVE-2010-4588 EXP The WBEMSingleView.ocx ActiveX control 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier allows remote attackers to execute arbitrary… Patch early 9.3 high 32.8% 2010-12-23
CVE-2008-3364 EXP Buffer overflow in the ObjRemoveCtrl Class ActiveX control in OfficeScanRemoveCtrl.dll 7.3.0.1020 in Trend Micro OfficeScan Corp Edition (OSCE) Web-De… Patch early 9.3 high 32.8% 2008-07-30
CVE-2015-3137 EXP Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.4… Patch early 10.0 high 32.8% 2015-07-09
CVE-2015-4430 EXP Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.4… Patch early 10.0 high 32.8% 2015-07-09
CVE-2013-3143 EXP Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… Patch early 9.3 high 32.7% 2013-07-10
CVE-2019-0235 EXP Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks. Patch early 8.8 high 32.7% 2020-04-30
CVE-2008-4922 EXP Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers to execute arbitrary code via… Patch early 9.3 high 32.7% 2008-11-04
CVE-2007-2987 EXP Multiple buffer overflows in certain ActiveX controls in sasatl.dll in Zenturi ProgramChecker allow remote attackers to execute arbitrary code via uns… Patch early 9.3 high 32.7% 2007-06-01
CVE-2008-0803 EXP Multiple PHP remote file inclusion vulnerabilities in LookStrike Lan Manager 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 32.7% 2008-02-15
CVE-2008-5711 EXP Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary code via a… Patch early 9.3 high 32.7% 2008-12-24
CVE-2008-2286 EXP SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows remote attackers to execute… Patch early 7.5 high 32.7% 2008-05-18
CVE-2017-2992 EXP Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 header. Successful exploitation… Patch early 8.8 high 32.7% 2017-02-15
CVE-2021-37589 EXP Virtua Cobranca before 12R allows SQL Injection on the login page. Patch early 7.5 high 32.7% 2022-06-07
CVE-2012-5960 EXP Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… Patch early 10.0 high 32.6% 2013-01-31
CVE-2007-1644 EXP The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or confi… Patch early 10.0 high 32.6% 2007-03-24
← previous page 65 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt