peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

149,742 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2003-0870 EXP Heap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a large number of escaped charact… Patch early 7.5 high 15.4% 2003-11-17
CVE-2003-0845 EXP Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remo… Patch early 7.5 high 15.4% 2003-11-17
CVE-2012-3575 EXP Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitrary code b… Patch early 10.0 high 15.4% 2012-06-16
CVE-2018-8463 EXP An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser,… Patch early 7.4 high 15.4% 2018-09-13
CVE-2018-8469 EXP An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser,… Patch early 7.4 high 15.4% 2018-09-13
CVE-2022-1565 EXP The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions… Patch early 7.2 high 15.4% 2022-07-18
CVE-2017-9414 EXP Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the authentica… Patch early 8.8 high 15.4% 2018-02-05
CVE-2010-4719 EXP Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to read arbitrary files via direct… Patch early 7.5 high 15.4% 2011-02-01
CVE-2018-20220 EXP An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it can be inte… Patch early 7.5 high 15.4% 2019-03-21
CVE-2012-0677 EXP Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application c… Patch early 9.3 high 15.4% 2012-06-12
CVE-2010-3141 EXP Untrusted search path vulnerability in Microsoft PowerPoint 2010 allows local users, and possibly remote attackers, to execute arbitrary code and cond… Patch early 9.3 high 15.4% 2010-08-27
CVE-2007-1785 EXP The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute arbitrary code via crafted xdr… Patch early 7.1 high 15.4% 2007-03-31
CVE-2009-3170 EXP Stack-based buffer overflow in AIMP2 Audio Converter 2.53 (build 330) and earlier allows remote attackers to cause a denial of service (crash) or poss… Patch early 9.3 high 15.4% 2009-09-11
CVE-2012-4886 EXP Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to execute arbitrary code via a long… Patch early 10.0 high 15.3% 2014-03-24
CVE-2017-1084 EXP In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections afforded by the guard-page. Thi… Patch early 7.5 high 15.3% 2018-09-12
CVE-2005-2943 EXP Stack-based buffer overflow in sendmail in XMail before 1.22 allows remote attackers to execute arbitrary code via a long -t command line option. Patch early 7.5 high 15.3% 2005-10-13
CVE-2010-1535 EXP Directory traversal vulnerability in the TRAVELbook (com_travelbook) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files and p… Patch early 7.5 high 15.3% 2010-04-26
CVE-2007-1777 EXP Integer overflow in the zip_read_entry function in PHP 4 before 4.4.5 allows remote attackers to execute arbitrary code via a ZIP archive that contain… Patch early 7.5 high 15.3% 2007-03-30
CVE-2007-4566 EXP Multiple buffer overflows in the login mechanism in sidvault in Alpha Centauri Software SIDVault LDAP Server before 2.0f allow remote attackers to exe… Patch early 10.0 high 15.3% 2007-08-28
CVE-2014-2913 EXP Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary com… Patch early 7.5 high 15.3% 2014-05-07
CVE-2007-2031 EXP Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote attackers to execute arbitrary… Patch early 10.0 high 15.3% 2007-04-16
CVE-2019-13605 EXP In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveragin… Patch early 8.8 high 15.3% 2019-07-16
CVE-2008-0984 EXP The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrar… Patch early 9.3 high 15.3% 2008-02-26
CVE-2015-3456 EXP The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-boun… Patch early 7.7 high 15.3% 2015-05-13
CVE-2018-5234 EXP The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in which the goal is execution of arb… Patch early 8.0 high 15.3% 2018-04-30
CVE-2005-2665 EXP Stack-based buffer overflow in expires.c in Elm 2.5 PL5 through PL7, and possibly other versions, allows remote attackers to execute arbitrary code vi… Patch early 7.5 high 15.3% 2005-08-23
CVE-2025-27210 EXP An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vuln… Patch early 7.5 high 15.3% 2025-07-18
CVE-2004-2532 EXP Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands b… Patch early 10.0 high 15.3% 2004-12-31
CVE-2010-4977 EXP SQL injection vulnerability in menu.php in the Canteen (com_canteen) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL comman… Patch early 7.5 high 15.3% 2011-11-01
CVE-2010-0759 EXP Directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Design Scriptegrator plugin 1.4.1… Patch early 7.5 high 15.2% 2010-02-27
← previous page 120 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt