peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,014 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

149,724 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-4273 EXP stap-server in SystemTap before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in stap command-line arguments in a… Patch early 10.0 high 17.7% 2010-01-26
CVE-2016-1768 EXP QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafte… Patch early 7.8 high 17.7% 2016-03-24
CVE-2017-5177 EXP A Stack Buffer Overflow issue was discovered in VIPA Controls WinPLC7 5.0.45.5921 and prior. A stack-based buffer overflow vulnerability has been iden… Patch early 7.5 high 17.7% 2017-05-19
CVE-2014-1677 EXP Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information. Patch early 7.5 high 17.7% 2017-04-03
CVE-2018-19627 EXP In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer bou… Patch early 7.5 high 17.7% 2018-11-29
CVE-2012-4992 EXP Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode string to (1)… Patch early 9.0 high 17.7% 2012-09-19
CVE-2011-4041 EXP webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code value via a long string in an… Patch early 10.0 high 17.7% 2012-02-06
CVE-2015-8257 EXP The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app par… Patch early 8.8 high 17.7% 2017-05-02
CVE-2008-5282 EXP Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code via (1) a link with a long HREF… Patch early 10.0 high 17.6% 2008-11-29
CVE-2016-4176 EXP Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to… Patch early 8.8 high 17.6% 2016-07-13
CVE-2016-4177 EXP Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to… Patch early 8.8 high 17.6% 2016-07-13
CVE-2008-5191 EXP Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the (1) poll_id parameter to poll.… Patch early 7.5 high 17.6% 2008-11-21
CVE-2011-2960 EXP Heap-based buffer overflow in httpsvr.exe 6.0.5.3 in Sunway ForceControl 6.1 SP1, SP2, and SP3 allows remote attackers to cause a denial of service (c… Patch early 10.0 high 17.6% 2011-07-29
CVE-2018-1321 EXP An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1… Patch early 7.2 high 17.5% 2018-03-20
CVE-2014-0749 EXP Stack-based buffer overflow in lib/Libdis/disrsi_.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x through 2.… Patch early 10.0 high 17.5% 2014-05-16
CVE-2017-12945 EXP Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers to execute a… Patch early 8.8 high 17.5% 2019-11-27
CVE-2016-9587 EXP Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker… Patch early 8.1 high 17.5% 2018-04-24
CVE-2004-0393 EXP Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string spec… Patch early 10.0 high 17.4% 2004-12-06
CVE-2005-2308 EXP The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute a… Patch early 7.5 high 17.4% 2005-07-19
CVE-2017-7240 EXP An issue was discovered on Miele Professional PST10 devices. The corresponding embedded webserver "PST10 WebServer" typically listens to port 80 and i… Patch early 7.5 high 17.4% 2017-03-24
CVE-2002-1850 EXP mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by cau… Patch early 7.5 high 17.4% 2002-12-31
CVE-2020-13448 EXP QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via comma… Patch early 8.8 high 17.4% 2020-06-01
CVE-2006-2811 EXP Multiple PHP remote file inclusion vulnerabilities in Cantico Ovidentia 5.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the ba… Patch early 7.5 high 17.4% 2006-06-05
CVE-2019-6706 EXP Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a de… Patch early 7.5 high 17.4% 2019-01-23
CVE-2009-4637 EXP FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a stack-b… Patch early 10.0 high 17.4% 2010-02-10
CVE-2021-24786 EXP The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statemen… Patch early 7.2 high 17.3% 2022-01-03
CVE-2019-12185 EXP eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in remote command execu… Patch early 8.8 high 17.3% 2019-05-20
CVE-2018-19908 EXP An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to constru… Patch early 8.8 high 17.3% 2018-12-06
CVE-2007-6681 EXP Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle i… Patch early 7.5 high 17.3% 2008-01-17
CVE-2003-1030 EXP Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long pre-authentication request to… Patch early 7.5 high 17.3% 2004-02-17
← previous page 112 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt