peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,105 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

12,661 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-1559 EXP Multiple stack-based buffer overflows in SonicDVDDashVRNav.dll in Roxio CinePlayer 3.2 allow remote attackers to execute arbitrary code via (1) unspec… Patch early 9.3 high 31.8% 2007-04-11
CVE-2018-7777 EXP The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder softwar… Patch early 8.8 high 31.8% 2018-07-03
CVE-2008-6898 EXP Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote attackers to cause a denial o… Patch early 9.3 high 31.7% 2009-08-05
CVE-2007-2244 EXP Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code… Patch early 9.3 high 31.7% 2007-04-25
CVE-2013-3120 EXP Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… Patch early 9.3 high 31.6% 2013-06-12
CVE-2015-8410 EXP Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 o… Patch early 10.0 high 31.6% 2015-12-10
CVE-2015-8048 EXP Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 o… Patch early 10.0 high 31.6% 2015-12-10
CVE-2015-8413 EXP Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 o… Patch early 10.0 high 31.6% 2015-12-10
CVE-2015-8412 EXP Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 o… Patch early 10.0 high 31.6% 2015-12-10
CVE-2015-8411 EXP Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 o… Patch early 10.0 high 31.6% 2015-12-10
CVE-2008-4728 EXP Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in Hummingbird Deployment Wizard… Patch early 9.3 high 31.6% 2008-10-24
CVE-2001-0010 EXP Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges. Patch early 10.0 high 31.6% 2001-02-12
CVE-2009-4656 EXP Stack-based buffer overflow in E-Soft DJ Studio Pro 4.2 including 4.2.2.7.5, and 5.x including 5.1.4.3.1, allows user-assisted remote attackers to cau… Patch early 9.3 high 31.6% 2010-03-03
CVE-2012-2176 EXP Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-002a for Domino allow remote att… Patch early 9.3 high 31.6% 2012-05-25
CVE-2013-3482 EXP Stack-based buffer overflow in the rf_report_error function in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.1.1301 allows remote attackers… Patch early 9.3 high 31.5% 2014-01-19
CVE-2008-5178 EXP Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI. NOTE: this might overla… Patch early 9.3 high 31.5% 2008-11-20
CVE-2015-2525 EXP Task Scheduler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and… Patch early 7.2 high 31.5% 2015-09-09
CVE-2013-2088 EXP contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary c… Patch early 7.1 high 31.5% 2013-07-31
CVE-2020-23972 EXP In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can als… Patch early 7.5 high 31.4% 2020-08-27
CVE-2013-5912 EXP VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute arbitrary code via a URL in t… Patch early 10.0 high 31.4% 2013-11-28
CVE-2019-9041 EXP An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting i… Patch early 7.2 high 31.4% 2019-02-23
CVE-2009-4265 EXP Stack-based buffer overflow in Ideal Administration 2009 9.7.1, and possibly other versions, allows remote attackers to execute arbitrary code via a l… Patch early 9.3 high 31.4% 2009-12-10
CVE-2012-0708 EXP Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.… Patch early 9.3 high 31.4% 2012-04-22
CVE-2009-4962 EXP Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a .wav file. NOTE: some of thes… Patch early 9.3 high 31.4% 2010-07-28
CVE-2002-0693 EXP Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal… Patch early 7.5 high 31.3% 2002-10-10
CVE-2015-2460 EXP ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Wind… Patch early 9.3 high 31.3% 2015-08-15
CVE-2007-3493 EXP A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other produ… Patch early 7.5 high 31.3% 2007-06-29
CVE-2010-1465 EXP Stack-based buffer overflow in Trellian FTP client 3.01, including 3.1.3.1789, allows remote attackers to execute arbitrary code via a long PASV respo… Patch early 9.3 high 31.3% 2010-04-16
CVE-2006-0143 EXP Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file conta… Patch early 7.5 high 31.3% 2006-01-09
CVE-2019-0667 EXP A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code E… Patch early 7.5 high 31.3% 2019-04-08
← previous page 67 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt