peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,014 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

186,431 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-30075 EXP In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to imprope… Patch early 8.8 high 33.8% 2022-06-09
CVE-2012-5946 EXP Buffer overflow in the c1sizer ActiveX control in C1sizer.ocx in IBM SPSS SamplePower 3.0 before FP1 allows remote attackers to execute arbitrary code… Patch early 9.3 high 33.8% 2013-04-30
CVE-2017-5375 EXP JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thun… Patch early 9.8 critical 33.8% 2018-06-11
CVE-2007-2919 EXP Multiple stack-based buffer overflows in the FViewerLoading ActiveX control (FlipViewerX.dll) in E-Book Systems FlipViewer before 4.1 allow remote att… Patch early 9.3 high 33.7% 2007-06-06
CVE-2022-27226 EXP A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration pan… Patch early 8.8 high 33.7% 2022-03-19
CVE-2010-1799 EXP Stack-based buffer overflow in the error-logging functionality in Apple QuickTime before 7.6.7 on Windows allows remote attackers to execute arbitrary… Patch early 9.3 high 33.7% 2010-08-16
CVE-2017-5815 EXP A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. Patch early 9.8 critical 33.7% 2018-02-15
CVE-2002-1847 EXP Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a lon… Patch early 7.5 high 33.6% 2002-12-31
CVE-2017-7588 EXP On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affecte… Patch early 9.8 critical 33.6% 2017-04-12
CVE-2021-31761 EXP Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature. Patch early 9.6 critical 33.6% 2021-04-25
CVE-2015-2444 EXP Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch early 9.3 high 33.6% 2015-08-14
CVE-2009-0076 EXP Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the zoom style directive in conju… Patch early 9.3 high 33.5% 2009-02-10
CVE-2013-3111 EXP Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch early 9.3 high 33.5% 2013-06-12
CVE-2000-0711 EXP Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to creat… Patch early 7.5 high 33.5% 2000-10-20
CVE-2022-48194 EXP TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploa… Patch early 8.8 high 33.5% 2022-12-30
CVE-2016-0971 EXP Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on… Patch early 8.8 high 33.5% 2016-02-10
CVE-2015-0050 EXP Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted w… Patch early 9.3 high 33.5% 2015-02-11
CVE-2017-16885 EXP Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Chang… Patch early 9.8 critical 33.5% 2018-01-12
CVE-2008-2069 EXP Buffer overflow in Novell GroupWise 7 allows remote attackers to cause a denial of service or execute arbitrary code via a long argument in a mailto:… Patch early 9.3 high 33.4% 2008-05-02
CVE-2013-1306 EXP Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers a… Patch early 9.3 high 33.4% 2013-05-15
CVE-2015-3124 EXP Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.4… Patch early 10.0 high 33.4% 2015-07-09
CVE-2018-11094 EXP An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasic… Patch early 9.8 critical 33.4% 2018-05-15
CVE-2014-8682 EXP Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow remote attackers to execute arb… Patch early 7.5 high 33.4% 2014-11-21
CVE-2008-0117 EXP Unspecified vulnerability in Microsoft Excel 2000 SP3 and 2002 SP2, and Office 2004 and 2008 for Mac, allows user-assisted remote attackers to execute… Patch early 9.3 high 33.4% 2008-03-11
CVE-2002-0193 EXP Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fi… Patch early 7.5 high 33.3% 2002-05-29
CVE-2014-1766 EXP Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch early 9.3 high 33.3% 2014-04-27
CVE-2009-1394 EXP Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code by sending a long malformed st… Patch early 9.3 high 33.3% 2009-06-26
CVE-2009-1612 EXP Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary… Patch early 9.3 high 33.3% 2009-05-11
CVE-2025-1097 EXP A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be… Patch early 8.8 high 33.2% 2025-03-25
CVE-2019-15813 EXP Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary code via a webshell. Patch early 8.8 high 33.2% 2019-09-04
← previous page 121 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt