peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,458 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

400,458 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-3585 EXP Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confidentiality, integrity, and ava… Patch early 9.0 high 52.1% 2010-10-14
CVE-2008-1898 EXP A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers… Patch early 9.3 high 52% 2008-04-21
CVE-2018-8831 EXP A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of t… Patch early 6.1 medium 52% 2018-04-18
CVE-2010-1622 EXP SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary c… Patch early 6.0 medium 52% 2010-06-21
CVE-2012-3951 EXP The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutin… Patch early 7.5 high 52% 2012-07-31
CVE-2011-4453 EXP The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequences in a… Patch early 7.5 high 52% 2011-12-22
CVE-2015-1487 EXP The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrary… Patch early 5.5 medium 52% 2015-08-01
CVE-2006-6133 EXP Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and… Patch early 7.6 high 52% 2006-11-28
CVE-2007-3034 EXP Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows rem… Patch early 9.3 high 51.9% 2007-08-14
CVE-2019-13068 EXP public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field). Patch early 5.4 medium 51.9% 2019-06-30
CVE-2013-4812 EXP UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (I… Patch early 10.0 high 51.9% 2013-09-16
CVE-2011-4075 EXP The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby para… Patch early 7.5 high 51.9% 2011-11-02
CVE-2013-6129 EXP The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password]… Patch early 7.5 high 51.9% 2013-10-19
CVE-1999-0046 EXP Buffer overflow of rlogin program using TERM environmental variable. Patch early 10.0 high 51.9% 1997-02-06
CVE-2015-4632 EXP Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 all… Patch early 7.5 high 51.8% 2018-10-18
CVE-2005-1018 EXP Buffer overflow in the UniversalAgent for Computer Associates (CA) BrightStor ARCserve Backup allows remote authenticated users to cause a denial of s… Patch early 7.5 high 51.8% 2005-05-02
CVE-2016-3288 EXP Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet Explorer Memory Corruption Vuln… Patch early 7.5 high 51.8% 2016-08-09
CVE-2018-0946 EXP A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine M… Patch early 7.5 high 51.8% 2018-05-09
CVE-2002-2268 EXP Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL. Patch early 9.4 high 51.7% 2002-12-31
CVE-2010-0557 EXP IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging har… Patch early 7.5 high 51.7% 2010-02-05
CVE-2007-4232 EXP PHP remote file inclusion vulnerability in admin/inc/change_action.php in Andreas Robertz PHPNews 0.93 allows remote attackers to execute arbitrary PH… Patch early 6.8 medium 51.7% 2007-08-08
CVE-2022-28171 EXP The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validati… Patch early 7.5 high 51.6% 2022-06-27
CVE-2009-0714 EXP Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before bu… Patch early 7.2 high 51.6% 2009-05-14
CVE-2009-1534 EXP Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3,… Patch early 9.3 high 51.6% 2009-08-12
CVE-2017-8731 EXP Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, d… Patch early 7.5 high 51.6% 2017-09-13
CVE-2011-0522 EXP The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text decoder (modules/codec/subtitles/subsusf.c) in Vide… Patch early 6.8 medium 51.5% 2011-02-07
CVE-2017-8496 EXP Microsoft Edge in Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user when Microso… Patch early 7.5 high 51.5% 2017-06-15
CVE-2013-1847 EXP The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of ser… Patch early 5.0 medium 51.4% 2013-05-02
CVE-2006-1551 EXP Eval injection vulnerability in pajax_call_dispatcher.php in PAJAX 0.5.1 and earlier allows remote attackers to execute arbitrary code via the (1) $me… Patch early 7.5 high 51.4% 2006-04-13
CVE-2018-1418 EXP IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824. Patch early 8.8 high 51.4% 2018-04-26
← previous page 115 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt