peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,331 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

400,331 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-4790 EXP Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the Microsoft Visual FoxPro 6.0 fp… Patch early 7.5 high 54.9% 2007-09-10
CVE-2003-0347 EXP Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to exe… Patch early 10.0 high 54.9% 2003-10-20
CVE-2004-0594 EXP The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allo… Patch early 5.1 medium 54.9% 2004-07-27
CVE-2007-2485 EXP PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allows remote attackers to execute… Patch early 7.5 high 54.9% 2007-05-03
CVE-2008-2168 EXP Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded… Patch early 4.3 medium 54.9% 2008-05-13
CVE-2017-11810 EXP Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows… Patch early 7.5 high 54.8% 2017-10-13
CVE-2016-3357 EXP Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word… Patch early 7.8 high 54.8% 2016-09-14
CVE-2007-2222 EXP Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explor… Patch early 9.3 high 54.7% 2007-06-12
CVE-2014-5446 EXP Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allows remote a… Patch early 5.0 medium 54.7% 2014-12-04
CVE-2007-2888 EXP Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrary code via a long FILE string… Patch early 7.6 high 54.7% 2007-05-30
CVE-2012-0270 EXP Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a crafted (1) hetro file to the get… Patch early 7.5 high 54.7% 2014-02-17
CVE-2011-5124 EXP Stack-based buffer overflow in the BCAAA component before build 60258, as used by Blue Coat ProxySG 4.2.3 through 6.1 and ProxyOne, allows remote atta… Patch early 10.0 high 54.6% 2012-08-26
CVE-2007-1765 EXP Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (… Patch early 9.3 high 54.6% 2007-03-30
CVE-2009-4223 EXP PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 54.6% 2009-12-07
CVE-2017-8657 EXP Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the cu… Patch early 7.5 high 54.6% 2017-08-08
CVE-2008-3008 EXP Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series allows remote attackers… Patch early 9.3 high 54.6% 2008-09-11
CVE-2022-36267 EXP In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can… Patch early 9.8 critical 54.5% 2022-08-08
CVE-2019-16667 EXP diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs be… Patch early 8.8 high 54.5% 2019-09-26
CVE-2010-3863 EXP Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows r… Patch early 5.0 medium 54.5% 2010-11-05
CVE-2009-1730 EXP Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read or modify arbitrary files via… Patch early 10.0 high 54.5% 2009-05-20
CVE-2016-2056 EXP xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the a… Patch early 8.8 high 54.5% 2016-04-13
CVE-2022-24562 EXP In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the enti… Patch early 9.8 critical 54.5% 2022-06-16
CVE-2024-11972 EXP The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install an… Patch early 9.8 critical 54.5% 2024-12-31
CVE-2012-0202 EXP Multiple stack-based buffer overflows in tm1admsd.exe in the Admin Server in IBM Cognos TM1 9.4.x and 9.5.x before 9.5.2 FP2 allow remote attackers to… Patch early 10.0 high 54.5% 2012-05-04
CVE-2025-49132 EXP Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespac… Patch early 10.0 critical 54.5% 2025-06-20
CVE-2002-0371 EXP Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to exec… Patch early 7.5 high 54.4% 2002-07-03
CVE-2007-3040 EXP Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a… Patch early 9.3 high 54.4% 2007-09-12
CVE-2021-36356 EXP KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary e… Patch early 9.8 critical 54.4% 2021-08-31
CVE-2011-0027 EXP Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation f… Patch early 9.3 high 54.4% 2011-01-12
CVE-2023-41425 EXP Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded… Patch early 6.1 medium 54.3% 2023-11-07
← previous page 111 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt