peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,143 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

25,086 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-3752 EXP Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a denial of service (application c… Patch early 9.3 high 36% 2012-11-09
CVE-2010-1527 EXP Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a long call-back-url parameter i… Patch early 9.3 high 36% 2010-08-23
CVE-2008-5518 EXP Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allo… Patch early 9.4 high 35.9% 2009-04-17
CVE-1999-1412 EXP A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flo… Patch early 5.0 medium 35.9% 1999-06-03
CVE-2006-5162 EXP wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a denial of service (unhandled exception and crash) vi… Patch early 5.0 medium 35.9% 2006-10-05
CVE-2014-0784 EXP Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a cr… Patch early 8.3 high 35.9% 2014-03-14
CVE-2014-8998 EXP lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a crafted HTTP header to index.ph… Patch early 6.5 medium 35.9% 2014-11-20
CVE-2000-0097 EXP The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed Hit-Highlighting Argument" vuln… Patch early 5.0 medium 35.9% 2000-01-26
CVE-2012-5975 EXP The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 through 6.3.2… Patch early 9.3 high 35.9% 2012-12-04
CVE-2007-5107 EXP Stack-based buffer overflow in the AskJeevesToolBar.SettingsPlugin.1 ActiveX control in askBar.dll in IAC Search & Media ask.com Ask Toolbar 4.0.2.53… Patch early 9.3 high 35.9% 2007-09-26
CVE-2008-5626 EXP XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument to the NLST command, as demons… Patch early 4.0 medium 35.9% 2008-12-17
CVE-2018-16288 EXP LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs. Patch early 8.6 high 35.8% 2018-09-14
CVE-2005-0511 EXP misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 35.8% 2005-02-21
CVE-2021-43936 EXP The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the p… Patch early 10.0 critical 35.8% 2021-12-06
CVE-2021-22146 EXP All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting… Patch early 7.5 high 35.8% 2021-07-21
CVE-2004-2074 EXP Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or… Patch early 5.0 medium 35.8% 2004-12-31
CVE-2006-1516 EXP The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read… Patch early 5.0 medium 35.8% 2006-05-05
CVE-2007-1658 EXP Windows Mail in Microsoft Windows Vista might allow user-assisted remote attackers to execute certain programs via a link to a (1) local file or (2) U… Patch early 9.3 high 35.8% 2007-03-24
CVE-2015-3783 EXP SceneKit in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and applicatio… Patch early 7.5 high 35.8% 2015-08-16
CVE-2008-3571 EXP The Xerox Phaser 8400 allows remote attackers to cause a denial of service (reboot) via an empty UDP packet to port 1900. Patch early 7.8 high 35.7% 2008-08-10
CVE-2022-47878 EXP Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the locat… Patch early 8.8 high 35.7% 2023-05-02
CVE-2021-31251 EXP An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a… Patch early 9.8 critical 35.7% 2021-06-04
CVE-2003-1336 EXP Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL. Patch early 9.3 high 35.7% 2003-12-31
CVE-2012-6330 EXP The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a den… Patch early 5.0 medium 35.7% 2013-01-04
CVE-2010-2746 EXP Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vist… Patch early 7.6 high 35.7% 2010-10-13
CVE-2015-2510 EXP Buffer overflow in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2, Office 2007 SP3, Office 2010 SP2, Lync 2010… Patch early 9.3 high 35.6% 2015-09-09
CVE-2013-6420 EXP The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1… Patch early 7.5 high 35.6% 2013-12-17
CVE-1999-1575 EXP The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5)… Patch early 5.1 medium 35.6% 1999-09-10
CVE-2021-43405 EXP An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained to be numeric). Patch early 8.8 high 35.6% 2021-11-05
CVE-2015-2456 EXP Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Go… Patch early 9.3 high 35.6% 2015-08-15
← previous page 99 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt