peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,218 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

400,218 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-0532 EXP Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for… Patch early 10.0 high 57.1% 2008-03-14
CVE-2013-3632 EXP The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands… Patch early 8.8 high 57.1% 2014-09-29
CVE-2011-3497 EXP service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related… Patch early 10.0 high 57.1% 2011-09-16
CVE-2008-1083 EXP Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and S… Patch early 8.1 high 57.1% 2008-04-08
CVE-2019-12276 EXP A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attac… Patch early 7.5 high 57.1% 2019-06-05
CVE-2008-1358 EXP Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary code via a F… Patch early 6.5 medium 57.1% 2008-03-17
CVE-2019-5434 EXP An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in t… Patch early 9.8 critical 57% 2019-05-06
CVE-2005-1009 EXP Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a modified computer name and length… Patch early 10.0 high 57% 2005-05-02
CVE-2015-2997 EXP SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getAgentLogFil… Patch early 5.0 medium 57% 2015-06-08
CVE-2021-45428 EXP TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HT… Patch early 9.8 critical 56.9% 2022-01-03
CVE-2022-28080 EXP Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter. Patch early 8.8 high 56.9% 2022-05-05
CVE-2008-0320 EXP Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly… Patch early 9.3 high 56.9% 2008-04-17
CVE-2017-6361 EXP QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors. Patch early 9.8 critical 56.8% 2017-03-23
CVE-2005-2287 EXP SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large TCP packet with a leading space… Patch early 5.0 medium 56.8% 2005-07-18
CVE-2016-3222 EXP Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microso… Patch early 8.8 high 56.8% 2016-06-16
CVE-2001-0731 EXP Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" quer… Patch early 5.0 medium 56.8% 2001-10-01
CVE-2015-4553 EXP A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell. Patch early 8.8 high 56.7% 2020-01-06
CVE-2014-0782 EXP Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 an… Patch early 8.3 high 56.7% 2014-05-16
CVE-2015-1397 EXP SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1.0 and Ent… Patch early 6.5 medium 56.7% 2015-04-29
CVE-2017-6527 EXP An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal attack allowing an unauthenticate… Patch early 7.5 high 56.6% 2017-03-09
CVE-2004-0842 EXP Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memo… Patch early 7.5 high 56.6% 2004-12-23
CVE-2012-1006 EXP Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 56.6% 2012-02-07
CVE-2008-1087 EXP Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to e… Patch early 9.3 high 56.6% 2008-04-08
CVE-2015-3080 EXP Use-after-free vulnerability in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.4… Patch early 10.0 high 56.6% 2015-05-13
CVE-2015-4074 EXP Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot do… Patch early 7.5 high 56.5% 2017-09-20
CVE-2003-0558 EXP Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response to a PASV request. Patch early 7.5 high 56.5% 2003-08-18
CVE-2006-3086 EXP Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attacker… Patch early 9.3 high 56.5% 2006-06-19
CVE-2022-1104 EXP The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as… Patch early 4.8 medium 56.4% 2022-05-09
CVE-2018-12634 EXP CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html… Patch early 9.8 critical 56.4% 2018-06-22
CVE-2007-4607 EXP Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used in Postcast Server Pro 3.0.61… Patch early 9.3 high 56.4% 2007-08-31
← previous page 108 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt