peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,265 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

186,105 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-11793 EXP Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows… Patch early 7.5 high 49.6% 2017-10-13
CVE-2006-0006 EXP Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000… Patch early 9.3 high 49.6% 2006-02-14
CVE-2013-3563 EXP Stack-based buffer overflow in db_netserver in Lianja SQL Server before 1.0.0RC5.2 allows remote attackers to cause a denial of service (daemon crash)… Patch early 7.5 high 49.5% 2013-07-04
CVE-2001-0876 EXP Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arbitrary code via a NOTIFY direc… Patch early 7.5 high 49.5% 2001-12-20
CVE-2022-37109 EXP patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control. Access to the passwo… Patch early 9.8 critical 49.5% 2022-11-14
CVE-2016-0015 EXP DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2,… Patch early 7.8 high 49.4% 2016-01-13
CVE-2018-13862 EXP Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attackers to reset the authentication… Patch early 9.8 critical 49.3% 2018-07-17
CVE-2008-4114 EXP srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remot… Patch early 7.1 high 49.3% 2008-09-16
CVE-2020-6010 EXP LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection Patch early 8.8 high 49.2% 2020-04-30
CVE-2023-3710 EXP Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 v… Patch early 9.9 critical 49% 2023-09-12
CVE-2004-0200 EXP Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers… Patch early 9.3 high 49% 2004-09-28
CVE-2016-0736 EXP In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CB… Patch early 7.5 high 49% 2017-07-27
CVE-2012-1803 EXP RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, whi… Patch early 8.5 high 49% 2012-04-28
CVE-2007-4776 EXP Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a Vis… Patch early 9.3 high 49% 2007-09-10
CVE-2018-9126 EXP The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover database credent… Patch early 9.8 critical 48.9% 2018-04-04
CVE-2009-0517 EXP Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields paramet… Patch early 10.0 high 48.9% 2009-02-11
CVE-2007-2223 EXP Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode o… Patch early 9.3 high 48.7% 2007-08-14
CVE-2022-31188 EXP CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-si… Patch early 8.6 high 48.6% 2022-08-01
CVE-2003-1339 EXP Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare allows remote attackers to cau… Patch early 10.0 high 48.6% 2003-12-31
CVE-2008-1043 EXP PHP remote file inclusion vulnerability in templates/default/header.inc.php in Linux Web Shop (LWS) php User Base 1.3 BETA allows remote attackers to… Patch early 7.5 high 48.6% 2008-02-27
CVE-2016-0170 EXP GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, a… Patch early 8.8 high 48.6% 2016-05-11
CVE-2003-0725 EXP Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 an… Patch early 7.5 high 48.6% 2003-10-20
CVE-2017-11855 EXP Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows… Patch early 7.5 high 48.6% 2017-11-15
CVE-2013-2568 EXP A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a re… Patch early 9.8 critical 48.5% 2020-01-29
CVE-2017-9232 EXP Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege… Patch early 9.8 critical 48.5% 2017-05-28
CVE-2009-0182 EXP Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in a File line in a .pls file, as… Patch early 8.8 high 48.4% 2009-01-20
CVE-2003-0816 EXP Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL co… Patch early 7.5 high 48.4% 2004-02-03
CVE-2020-5377 EXP Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. An unauthenticated remote atta… Patch early 9.1 critical 48.3% 2020-07-28
CVE-2008-1059 EXP PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers t… Patch early 7.5 high 48.3% 2008-02-28
CVE-2010-0028 EXP Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a c… Patch early 9.3 high 48.3% 2010-02-10
← previous page 101 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt