peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,661 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

25,086 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-3579 EXP Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier for remote attackers to obtain p… Patch early 7.9 high 40.2% 2012-08-29
CVE-2009-2011 EXP Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not r… Patch early 9.3 high 40.2% 2009-06-16
CVE-2022-23513 EXP Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. In case of an attack, the threa… Patch early 5.3 medium 40.2% 2022-12-23
CVE-2013-1710 EXP The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.… Patch early 10.0 high 40.1% 2013-08-07
CVE-2007-2481 EXP PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled… Patch early 6.8 medium 40.1% 2007-05-03
CVE-2014-8586 EXP SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands vi… Patch early 7.5 high 40.1% 2014-11-04
CVE-2009-1968 EXP Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknow… Patch early 4.3 medium 40.1% 2009-07-14
CVE-2009-1025 EXP PHP remote file inclusion vulnerability in linkadmin.php in Beerwin PHPLinkAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL i… Patch early 7.5 high 40.1% 2009-03-20
CVE-2016-3371 EXP The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window… Patch early 5.5 medium 40.1% 2016-09-14
CVE-2007-5243 EXP Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0.257, allow remote attackers t… Patch early 9.3 high 40.1% 2007-10-06
CVE-2009-2754 EXP Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe),… Patch early 10.0 high 40.1% 2010-03-05
CVE-2014-2928 EXP The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through… Patch early 7.1 high 40.1% 2014-05-12
CVE-2002-1973 EXP Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in… Patch early 7.5 high 40% 2002-12-31
CVE-1999-0154 EXP IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL. Patch early 5.0 medium 40% 1999-12-31
CVE-2019-7442 EXP An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attacker… Patch early 9.8 critical 40% 2019-05-08
CVE-2019-7269 EXP Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution. Patch early 9.8 critical 40% 2019-07-02
CVE-2010-4051 EXP The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to… Patch early 5.0 medium 40% 2011-01-13
CVE-2009-0187 EXP Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote attackers to execute arbitrar… Patch early 9.3 high 40% 2009-02-26
CVE-2006-4110 EXP Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate… Patch early 4.3 medium 40% 2006-08-14
CVE-2009-3033 EXP Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in Sy… Patch early 9.3 high 40% 2009-11-25
CVE-2018-0833 EXP The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2 allows a denial of service vu… Patch early 5.3 medium 39.9% 2018-02-15
CVE-1999-0368 EXP Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto. Patch early 10.0 high 39.8% 1999-02-09
CVE-2012-0217 EXP The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris… Patch early 7.2 high 39.8% 2012-06-12
CVE-2010-1900 EXP Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Vi… Patch early 9.3 high 39.8% 2010-08-11
CVE-2025-7441 EXP The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42. This vulnerability occurs th… Patch early 9.8 critical 39.8% 2025-08-16
CVE-2004-0727 EXP Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass… Patch early 7.5 high 39.8% 2004-07-27
CVE-2006-1193 EXP Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assiste… Patch early 2.6 low 39.8% 2006-06-13
CVE-2007-1819 EXP Stack-based buffer overflow in the SPIDERLib.Loader ActiveX control (Spider90.ocx) 9.1.0.4353 in TestDirector (TD) for Mercury Quality Center 9.0 befo… Patch early 9.3 high 39.7% 2007-04-02
CVE-2018-10088 EXP Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725. Patch early 9.8 critical 39.7% 2018-06-08
CVE-2012-2516 EXP An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1,… Patch early 9.3 high 39.7% 2012-07-05
← previous page 90 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt