peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,941 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-02

186,404 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-26609 EXP ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field. Patch early 7.2 high 38.7% 2023-02-27
CVE-2015-2562 EXP Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allow remote attackers to execute… Patch early 7.5 high 38.7% 2015-03-20
CVE-2003-0209 EXP Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large s… Patch early 10.0 high 38.6% 2003-05-05
CVE-2005-0048 EXP Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service… Patch early 7.5 high 38.6% 2005-05-02
CVE-2018-7658 EXP NTSServerSvc.exe in the server in Softros Network Time System 2.3.4 allows remote attackers to cause a denial of service (daemon crash) by sending exa… Patch early 7.5 high 38.5% 2018-03-26
CVE-2012-0267 EXP The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a crafted lModule parameter that… Patch early 9.3 high 38.5% 2012-01-15
CVE-2018-17440 EXP An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has… Patch early 9.8 critical 38.5% 2018-10-08
CVE-2016-10034 EXP The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before… Patch early 9.8 critical 38.4% 2016-12-30
CVE-2021-27928 EXP A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona… Patch early 7.2 high 38.4% 2021-03-19
CVE-2014-3996 EXP SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MS… Patch early 7.5 high 38.4% 2014-12-05
CVE-2021-3817 EXP wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command Patch early 9.8 critical 38.4% 2021-12-09
CVE-2006-0005 EXP Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the de… Patch early 9.3 high 38.4% 2006-02-14
CVE-2007-0515 EXP Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of servic… Patch early 9.3 high 38.4% 2007-01-26
CVE-2000-0305 EXP Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a la… Patch early 7.8 high 38.4% 2000-05-19
CVE-2011-3142 EXP Stack-based buffer overflow in an ActiveX control in KVWebSvr.dll in WellinTech KingView 6.52 and 6.53 allows remote attackers to execute arbitrary co… Patch early 10.0 high 38.4% 2011-08-16
CVE-2011-2089 EXP Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0 in the WebHMI subsystem in ICO… Patch early 9.3 high 38.3% 2011-05-13
CVE-2002-0764 EXP Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies… Patch early 7.5 high 38.3% 2002-08-12
CVE-2021-24750 EXP The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX acti… Patch early 8.8 high 38.3% 2021-12-21
CVE-2012-2174 EXP The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted notes:// URL. Patch early 9.3 high 38.3% 2012-06-20
CVE-2012-0163 EXP Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attacke… Patch early 9.3 high 38.3% 2012-04-10
CVE-2013-0090 EXP Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that… Patch early 8.8 high 38.2% 2013-03-13
CVE-2018-2791 EXP Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected ar… Patch early 8.2 high 38.2% 2018-04-19
CVE-2004-0695 EXP Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbitrary code via a long FTP comma… Patch early 7.5 high 38.2% 2004-07-27
CVE-2018-8474 EXP A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for Mac 2011 Se… Patch early 7.5 high 38.2% 2018-09-13
CVE-2015-5544 EXP Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… Patch early 10.0 high 38.2% 2015-08-14
CVE-2015-5545 EXP Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… Patch early 10.0 high 38.2% 2015-08-14
CVE-2015-5546 EXP Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… Patch early 10.0 high 38.2% 2015-08-14
CVE-2015-5547 EXP Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… Patch early 10.0 high 38.2% 2015-08-14
CVE-2015-5548 EXP Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… Patch early 10.0 high 38.2% 2015-08-14
CVE-2015-5549 EXP Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… Patch early 10.0 high 38.2% 2015-08-14
← previous page 114 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt