peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,003 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

25,086 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-1006 EXP Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 56.6% 2012-02-07
CVE-2008-1087 EXP Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to e… Patch early 9.3 high 56.6% 2008-04-08
CVE-2015-3080 EXP Use-after-free vulnerability in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.4… Patch early 10.0 high 56.6% 2015-05-13
CVE-2015-4074 EXP Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot do… Patch early 7.5 high 56.5% 2017-09-20
CVE-2003-0558 EXP Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response to a PASV request. Patch early 7.5 high 56.5% 2003-08-18
CVE-2006-3086 EXP Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attacker… Patch early 9.3 high 56.5% 2006-06-19
CVE-2022-1104 EXP The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as… Patch early 4.8 medium 56.4% 2022-05-09
CVE-2018-12634 EXP CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html… Patch early 9.8 critical 56.4% 2018-06-22
CVE-2007-4607 EXP Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used in Postcast Server Pro 3.0.61… Patch early 9.3 high 56.4% 2007-08-31
CVE-2010-4742 EXP Stack-based buffer overflow in a certain ActiveX control in MediaDBPlayback.DLL 2.2.0.5 in the Moxa ActiveX SDK allows remote attackers to execute arb… Patch early 10.0 high 56.4% 2011-02-18
CVE-2011-2882 EXP Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0… Patch early 9.3 high 56.4% 2011-07-21
CVE-2007-4809 EXP Multiple PHP remote file inclusion vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 allow remote attackers to execute arbitrary PHP code… Patch early 7.5 high 56.4% 2007-09-11
CVE-2008-0659 EXP Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used in MySpace MySpaceUploader.ocx… Patch early 10.0 high 56.3% 2008-02-08
CVE-2016-0784 EXP Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated ad… Patch early 6.5 medium 56.3% 2016-04-11
CVE-2007-3456 EXP Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1)… Patch early 9.3 high 56.3% 2007-07-11
CVE-2008-4008 EXP Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7… Patch early 10.0 high 56.3% 2008-10-14
CVE-2006-6707 EXP Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Express 3.25 and NeoTrace Pro (a… Patch early 7.5 high 56.2% 2006-12-23
CVE-2018-17173 EXP LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail. Patch early 9.8 critical 56.2% 2018-09-21
CVE-2007-1579 EXP Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSCRIBE command. Patch early 10.0 high 56.2% 2007-03-21
CVE-2016-3078 EXP Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buffe… Patch early 9.8 critical 56.1% 2016-08-07
CVE-2013-1469 EXP Directory traversal vulnerability in install.php in Piwigo before 2.4.7 allows remote attackers to read and delete arbitrary files via a .. (dot dot)… Patch early 4.0 medium 56% 2013-03-13
CVE-2010-2115 EXP SolarWinds TFTP Server 10.4.0.10 allows remote attackers to cause a denial of service (no new connections) via a crafted read request. Patch early 5.0 medium 56% 2010-05-28
CVE-2007-0046 EXP Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbi… Patch early 7.5 high 55.9% 2007-01-03
CVE-2008-3704 EXP Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Vis… Patch early 9.3 high 55.9% 2008-08-18
CVE-2006-3280 EXP Cross-domain vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to access restricted information from other domains via an objec… Patch early 7.5 high 55.9% 2006-06-28
CVE-2007-0044 EXP Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to ma… Patch early 4.3 medium 55.9% 2007-01-03
CVE-2017-8635 EXP Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold… Patch early 7.5 high 55.9% 2017-08-08
CVE-2019-7255 EXP Linear eMerge E3-Series devices allow XSS. Patch early 6.1 medium 55.8% 2019-07-02
CVE-2019-14322 EXP In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames. Patch early 7.5 high 55.8% 2019-07-28
CVE-2011-3494 EXP WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a… Patch early 10.0 high 55.8% 2011-09-16
← previous page 66 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt