peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,986 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

25,086 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-5388 EXP Multiple PHP remote file inclusion vulnerabilities in WebDesktop 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) app par… Patch early 6.8 medium 38.4% 2007-10-12
CVE-2006-1518 EXP Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via craft… Patch early 6.5 medium 38.4% 2006-05-05
CVE-2000-0305 EXP Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a la… Patch early 7.8 high 38.4% 2000-05-19
CVE-2011-3142 EXP Stack-based buffer overflow in an ActiveX control in KVWebSvr.dll in WellinTech KingView 6.52 and 6.53 allows remote attackers to execute arbitrary co… Patch early 10.0 high 38.4% 2011-08-16
CVE-2011-2089 EXP Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0 in the WebHMI subsystem in ICO… Patch early 9.3 high 38.3% 2011-05-13
CVE-2002-0764 EXP Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies… Patch early 7.5 high 38.3% 2002-08-12
CVE-2021-24750 EXP The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX acti… Patch early 8.8 high 38.3% 2021-12-21
CVE-2012-2174 EXP The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted notes:// URL. Patch early 9.3 high 38.3% 2012-06-20
CVE-2012-0163 EXP Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attacke… Patch early 9.3 high 38.3% 2012-04-10
CVE-2013-0090 EXP Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that… Patch early 8.8 high 38.2% 2013-03-13
CVE-2018-2791 EXP Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected ar… Patch early 8.2 high 38.2% 2018-04-19
CVE-2004-0695 EXP Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbitrary code via a long FTP comma… Patch early 7.5 high 38.2% 2004-07-27
CVE-2018-8474 EXP A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for Mac 2011 Se… Patch early 7.5 high 38.2% 2018-09-13
CVE-2015-5544 EXP Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… Patch early 10.0 high 38.2% 2015-08-14
CVE-2015-5545 EXP Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… Patch early 10.0 high 38.2% 2015-08-14
CVE-2015-5546 EXP Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… Patch early 10.0 high 38.2% 2015-08-14
CVE-2015-5547 EXP Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… Patch early 10.0 high 38.2% 2015-08-14
CVE-2015-5548 EXP Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… Patch early 10.0 high 38.2% 2015-08-14
CVE-2015-5549 EXP Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… Patch early 10.0 high 38.2% 2015-08-14
CVE-2007-0216 EXP wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbi… Patch early 9.3 high 38.1% 2008-02-12
CVE-2019-15977 EXP Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker… Patch early 7.5 high 38.1% 2020-01-06
CVE-2018-7583 EXP Proxy.exe in DualDesk 20 allows Remote Denial Of Service (daemon crash) via a long string to TCP port 5500. Patch early 7.5 high 38.1% 2018-03-04
CVE-2016-6896 EXP Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authent… Patch early 7.1 high 38.1% 2017-01-18
CVE-1999-0911 EXP Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested… Patch early 10.0 high 38.1% 1999-08-27
CVE-2018-14009 EXP Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689. Patch early 9.8 critical 38% 2018-07-12
CVE-2007-6514 EXP Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed c… Patch early 4.3 medium 38% 2007-12-21
CVE-2007-6387 EXP Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics AnswerWorks,… Patch early 9.3 high 38% 2007-12-15
CVE-2019-10945 EXP An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to ac… Patch early 9.8 critical 38% 2019-04-10
CVE-2007-5603 EXP Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allows remot… Patch early 9.3 high 38% 2007-11-05
CVE-2015-2843 EXP Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute arbitrary SQL commands via the… Patch early 7.5 high 37.9% 2015-05-12
← previous page 94 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt