peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,554 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

12,661 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-7066 EXP Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating an object inside an iframe, d… Patch early 7.1 high 22.2% 2007-03-02
CVE-2011-2131 EXP Adobe Photoshop 12.0 in Creative Suite 5 (CS5) and 12.1 in Creative Suite 5.1 (CS5.1) allows remote attackers to execute arbitrary code or cause a den… Patch early 9.3 high 22.2% 2011-08-11
CVE-2008-0590 EXP Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of service (crash) and possibly execute… Patch early 9.0 high 22.2% 2008-02-05
CVE-2006-2444 EXP The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) vi… Patch early 7.8 high 22.1% 2006-05-25
CVE-2006-4494 EXP Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiat… Patch early 7.5 high 22.1% 2006-08-31
CVE-2006-7206 EXP Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating a ADODB.Recordset object and… Patch early 7.8 high 22.1% 2007-06-22
CVE-2002-1179 EXP Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digi… Patch early 7.5 high 22.1% 2002-10-28
CVE-2022-4510 EXP A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesyste… Patch early 7.8 high 22% 2023-01-26
CVE-2013-3846 EXP Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (m… Patch early 9.3 high 22% 2013-12-29
CVE-2018-19246 EXP PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access to their… Patch early 7.5 high 22% 2018-11-13
CVE-2003-0666 EXP Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters… Patch early 7.5 high 21.9% 2003-10-20
CVE-2020-10884 EXP This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750… Patch early 8.8 high 21.9% 2020-03-25
CVE-2010-1938 EXP Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE… Patch early 9.3 high 21.9% 2010-05-28
CVE-2007-3927 EXP Multiple buffer overflows in Ipswitch IMail Server 2006 before 2006.21 (1) allow remote attackers to execute arbitrary code via unspecified vectors in… Patch early 10.0 high 21.9% 2007-07-21
CVE-2012-0016 EXP Untrusted search path vulnerability in Microsoft Expression Design; Expression Design SP1; and Expression Design 2, 3, and 4 allows local users to gai… Patch early 9.3 high 21.9% 2012-03-13
CVE-2015-3302 EXP The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers… Patch early 7.5 high 21.8% 2017-12-29
CVE-2017-2985 EXP Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript 3 BitmapData class. Successful… Patch early 8.8 high 21.8% 2017-02-15
CVE-2022-34047 EXP An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/s… Patch early 7.5 high 21.8% 2022-07-20
CVE-2014-1772 EXP Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… Patch early 9.3 high 21.7% 2014-06-11
CVE-2014-1805 EXP Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch early 9.3 high 21.7% 2014-06-11
CVE-2014-2754 EXP Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web sit… Patch early 9.3 high 21.7% 2014-06-11
CVE-2006-0544 EXP urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and pos… Patch early 7.5 high 21.7% 2006-02-04
CVE-2004-0989 EXP Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via… Patch early 10.0 high 21.7% 2005-03-01
CVE-2022-46770 EXP qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and lo… Patch early 7.5 high 21.7% 2022-12-07
CVE-2005-3277 EXP The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary code via shell metacharacters ("`" or single backq… Patch early 10.0 high 21.7% 2005-10-21
CVE-2009-1330 EXP Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long filename in a playlist (.pls) fil… Patch early 9.3 high 21.7% 2009-04-17
CVE-2010-3338 EXP The Windows Task Scheduler in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine th… Patch early 7.2 high 21.7% 2010-12-16
CVE-2013-0249 EXP Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when neg… Patch early 7.5 high 21.6% 2013-03-08
CVE-2011-0222 EXP WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and ap… Patch early 9.3 high 21.6% 2011-07-21
CVE-2021-40379 EXP An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization. Patch early 7.5 high 21.6% 2021-09-01
← previous page 80 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt