peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,105 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

12,661 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2013-1017 EXP Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via… Patch early 9.3 high 32.6% 2013-05-24
CVE-2022-31854 EXP Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel. Patch early 7.2 high 32.5% 2022-07-07
CVE-2016-4229 EXP Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.6… Patch early 8.8 high 32.5% 2016-07-13
CVE-2009-5109 EXP Stack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long entry in a .pls file. Patch early 9.3 high 32.5% 2011-12-25
CVE-2015-3107 EXP Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.4… Patch early 10.0 high 32.4% 2015-06-10
CVE-2001-0144 EXP CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer over… Patch early 10.0 high 32.4% 2001-03-12
CVE-2016-7054 EXP In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads.… Patch early 7.5 high 32.4% 2017-05-04
CVE-1999-0920 EXP Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command. Patch early 10.0 high 32.4% 1999-05-26
CVE-2013-6935 EXP Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the SourcePath… Patch early 9.3 high 32.4% 2013-12-04
CVE-2015-2458 EXP ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Wind… Patch early 9.3 high 32.4% 2015-08-15
CVE-2015-2459 EXP ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Wind… Patch early 9.3 high 32.4% 2015-08-15
CVE-2011-0340 EXP Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed… Patch early 9.3 high 32.3% 2011-05-04
CVE-2007-5941 EXP Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a denial of service and possibly ex… Patch early 10.0 high 32.3% 2007-11-14
CVE-2015-2482 EXP The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote… Patch early 9.3 high 32.3% 2015-10-14
CVE-2014-4138 EXP Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… Patch early 9.3 high 32.2% 2014-10-15
CVE-2008-0112 EXP Unspecified vulnerability in Microsoft Excel 2000 SP3, and Office for Mac 2004 and 2008 allows user-assisted remote attackers to execute arbitrary cod… Patch early 9.3 high 32.2% 2008-03-11
CVE-2016-4230 EXP Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.6… Patch early 8.8 high 32.2% 2016-07-13
CVE-2008-5232 EXP Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services… Patch early 9.3 high 32.2% 2008-11-26
CVE-2009-1568 EXP Stack-based buffer overflow in ienipp.ocx in Novell iPrint Client 5.30, and possibly other versions before 5.32, allows remote attackers to execute ar… Patch early 9.3 high 32.2% 2009-12-08
CVE-2019-13024 EXP Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using th… Patch early 8.8 high 32.2% 2019-07-01
CVE-2017-7692 EXP SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file that is mish… Patch early 8.8 high 32.2% 2017-04-20
CVE-2009-3837 EXP Stack-based buffer overflow in Eureka Email 2.2q allows remote POP3 servers to execute arbitrary code via a long error message. Patch early 9.3 high 32.1% 2009-11-02
CVE-2009-4588 EXP Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlier in AwingSoft Awakening Web3D… Patch early 9.3 high 32% 2010-01-07
CVE-2018-12827 EXP Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. Patch early 7.5 high 32% 2018-08-29
CVE-2013-3174 EXP DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows… Patch early 9.3 high 32% 2013-07-10
CVE-2010-5193 EXP Stack-based buffer overflow in the TIFMergeMultiFiles function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageViewer2.ocx) in Viscom Image Viewe… Patch early 9.3 high 32% 2012-08-31
CVE-2011-5170 EXP Stack-based buffer overflow in Castillo Bueno Systems CCMPlayer 1.5 allows remote attackers to execute arbitrary code via a long track name in an m3u… Patch early 9.3 high 32% 2012-09-15
CVE-2018-1133 EXP An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval… Patch early 8.8 high 31.9% 2018-05-25
CVE-2021-46378 EXP DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download. Patch early 7.5 high 31.9% 2022-03-04
CVE-2009-1029 EXP Stack-based buffer overflow in POP Peeper 3.4.0.0 and earlier allows remote POP3 servers to execute arbitrary code via a long Date header, related to… Patch early 9.3 high 31.8% 2009-03-20
← previous page 66 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt