peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,265 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

319,118 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-0023 EXP Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass som… Patch early 5.0 medium 37% 2002-03-08
CVE-2014-7883 EXP HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive information by… Patch early 5.0 medium 37% 2015-02-15
CVE-2005-0582 EXP Buffer overflow in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to execute arbitrary code via a long filename in a PUTOLF… Patch early 10.0 high 37% 2005-05-02
CVE-2016-3115 EXP Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command… Patch early 6.4 medium 37% 2016-03-22
CVE-2011-5165 EXP Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted remote attackers to execute arbit… Patch early 9.3 high 37% 2012-09-15
CVE-2018-11529 EXP VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV fi… Patch early 8.0 high 37% 2018-07-11
CVE-2007-1525 EXP Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code via the cat… Patch early 6.8 medium 37% 2007-03-20
CVE-2015-4624 EXP Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens. Patch early 7.5 high 37% 2017-03-31
CVE-2017-6019 EXP An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. A series of rapid requests t… Patch early 7.5 high 36.9% 2017-04-07
CVE-2012-5961 EXP Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… Patch early 10.0 high 36.9% 2013-01-31
CVE-2012-5962 EXP Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… Patch early 10.0 high 36.9% 2013-01-31
CVE-2012-5963 EXP Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… Patch early 10.0 high 36.9% 2013-01-31
CVE-2012-5964 EXP Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… Patch early 10.0 high 36.9% 2013-01-31
CVE-2012-5965 EXP Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… Patch early 10.0 high 36.9% 2013-01-31
CVE-2008-1074 EXP PHP remote file inclusion vulnerability in lib/head_auth.php in GROUP-E 1.6.41 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 6.8 medium 36.9% 2008-02-29
CVE-2007-3624 EXP Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long string in the… Patch early 10.0 high 36.8% 2007-07-09
CVE-2007-6530 EXP Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury… Patch early 9.3 high 36.8% 2007-12-27
CVE-2012-0201 EXP Stack-based buffer overflow in pcspref.dll in pcsws.exe in IBM Personal Communications 5.9.x before 5.9.8 and 6.0.x before 6.0.4 might allow remote at… Patch early 9.3 high 36.8% 2012-03-02
CVE-2008-1436 EXP Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalServ… Patch early 9.0 high 36.8% 2008-04-21
CVE-2011-3659 EXP Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before… Patch early 9.3 high 36.8% 2012-02-01
CVE-2018-6008 EXP Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter. Patch early 7.5 high 36.8% 2018-01-29
CVE-2015-3042 EXP Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to… Patch early 10.0 high 36.8% 2015-04-14
CVE-2019-2588 EXP Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported vers… Patch early 4.9 medium 36.8% 2019-04-23
CVE-2017-13872 EXP An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The issue involves the "Directory Ut… Patch early 8.1 high 36.8% 2017-11-29
CVE-2016-0120 EXP The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gol… Patch early 6.5 medium 36.7% 2016-03-09
CVE-2009-0119 EXP Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly… Patch early 10.0 high 36.7% 2009-01-14
CVE-2010-2343 EXP Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbitrary code via a crafted pls p… Patch early 9.3 high 36.7% 2010-06-21
CVE-2009-3853 EXP Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 be… Patch early 9.3 high 36.7% 2009-11-04
CVE-2003-0111 EXP The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote… Patch early 7.5 high 36.7% 2003-05-05
CVE-2007-5660 EXP Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2… Patch early 9.3 high 36.6% 2007-11-02
← previous page 105 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt