peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,265 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

12,661 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-6554 EXP pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to write to arbitrary files and con… Patch early 7.2 high 15.6% 2017-04-14
CVE-2022-1103 EXP The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could… Patch early 8.8 high 15.6% 2022-05-16
CVE-2008-0177 EXP The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldo… Patch early 7.8 high 15.5% 2008-02-07
CVE-2015-7250 EXP Absolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to rea… Patch early 7.5 high 15.5% 2015-12-30
CVE-2002-0005 EXP Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long arg… Patch early 10.0 high 15.5% 2002-01-31
CVE-2005-3560 EXP Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1,… Patch early 7.5 high 15.5% 2005-11-16
CVE-2018-1041 EXP A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could… Patch early 7.5 high 15.5% 2018-02-15
CVE-2006-4059 EXP Multiple PHP remote file inclusion vulnerabilities in USOLVED NEWSolved Lite 1.9.2, and possibly earlier, allow remote attackers to execute arbitrary… Patch early 7.5 high 15.5% 2006-08-10
CVE-2007-4646 EXP Buffer overflow in the pop3 service in Hexamail Server 3.0.0.001 Lite allows remote attackers to cause a denial of service (daemon crash) and probably… Patch early 10.0 high 15.5% 2007-08-31
CVE-2009-3373 EXP Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote at… Patch early 10.0 high 15.5% 2009-10-29
CVE-2007-2666 EXP Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attac… Patch early 7.6 high 15.5% 2007-05-14
CVE-2019-1151 EXP A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who succes… Patch early 8.8 high 15.5% 2019-08-14
CVE-2002-1368 EXP Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary c… Patch early 7.5 high 15.5% 2002-12-26
CVE-2012-6429 EXP Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7 allows remote attackers to exe… Patch early 10.0 high 15.5% 2014-04-04
CVE-2003-0101 EXP miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (C… Patch early 10.0 high 15.5% 2003-03-03
CVE-2004-1423 EXP Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Of… Patch early 7.5 high 15.5% 2004-12-31
CVE-2004-0935 EXP Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and gl… Patch early 7.5 high 15.5% 2005-01-27
CVE-2014-2069 EXP Absolute path traversal vulnerability in Eshtery CMS allows remote attackers to read arbitrary files via a full pathname in the file parameter to File… Patch early 7.5 high 15.4% 2018-04-16
CVE-2008-0175 EXP Unrestricted file upload vulnerability in GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier allows remote attackers to execute arbitrary c… Patch early 7.5 high 15.4% 2008-01-29
CVE-2003-0870 EXP Heap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a large number of escaped charact… Patch early 7.5 high 15.4% 2003-11-17
CVE-2003-0845 EXP Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remo… Patch early 7.5 high 15.4% 2003-11-17
CVE-2012-3575 EXP Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitrary code b… Patch early 10.0 high 15.4% 2012-06-16
CVE-2018-8463 EXP An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser,… Patch early 7.4 high 15.4% 2018-09-13
CVE-2018-8469 EXP An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser,… Patch early 7.4 high 15.4% 2018-09-13
CVE-2022-1565 EXP The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions… Patch early 7.2 high 15.4% 2022-07-18
CVE-2017-9414 EXP Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the authentica… Patch early 8.8 high 15.4% 2018-02-05
CVE-2010-4719 EXP Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to read arbitrary files via direct… Patch early 7.5 high 15.4% 2011-02-01
CVE-2018-20220 EXP An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it can be inte… Patch early 7.5 high 15.4% 2019-03-21
CVE-2012-0677 EXP Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application c… Patch early 9.3 high 15.4% 2012-06-12
CVE-2010-3141 EXP Untrusted search path vulnerability in Microsoft PowerPoint 2010 allows local users, and possibly remote attackers, to execute arbitrary code and cond… Patch early 9.3 high 15.4% 2010-08-27
← previous page 97 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt