peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

401,061 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-5002 EXP Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allo… Patch early 9.3 high 40.7% 2008-11-10
CVE-2019-8050 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 9.8 critical 40.6% 2019-08-20
CVE-2015-4455 EXP Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allows… Patch early 9.8 critical 40.6% 2017-05-23
CVE-2021-45092 EXP Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter. Patch early 9.8 critical 40.6% 2021-12-16
CVE-2012-5223 EXP The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert… Patch early 7.5 high 40.5% 2012-10-01
CVE-2007-2938 EXP Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6, when Internet Explorer 6 is us… Patch early 10.0 high 40.5% 2007-05-31
CVE-2009-0565 EXP Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Conver… Patch early 9.3 high 40.5% 2009-06-10
CVE-2013-1412 EXP DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a… Patch early 7.5 high 40.5% 2014-06-02
CVE-2011-0517 EXP Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows remote attackers to cause a de… Patch early 9.3 high 40.5% 2011-01-20
CVE-2006-1992 EXP mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags… Patch early 2.6 low 40.4% 2006-04-25
CVE-2015-3118 EXP Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.4… Patch early 10.0 high 40.4% 2015-07-09
CVE-2006-3493 EXP Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office… Patch early 5.1 medium 40.4% 2006-07-10
CVE-2007-3147 EXP Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute ar… Patch early 9.3 high 40.4% 2007-06-11
CVE-2014-0980 EXP Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI file. Patch early 9.3 high 40.4% 2014-02-11
CVE-2013-1599 EXP A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01,… Patch early 9.8 critical 40.4% 2020-01-28
CVE-2013-0136 EXP Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to… Patch early 8.5 high 40.3% 2013-06-01
CVE-2006-2111 EXP A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections wit… Patch early 4.3 medium 40.3% 2006-05-01
CVE-2007-4475 EXP Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Level 9 allows remote attackers to… Patch early 9.3 high 40.3% 2009-04-01
CVE-2020-24217 EXP An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentic… Patch early 9.8 critical 40.3% 2020-10-06
CVE-2006-2383 EXP Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpec… Patch early 9.3 high 40.3% 2006-06-13
CVE-2005-2852 EXP Unknown vulnerability in CIFS.NLM in Novell Netware 6.5 SP2 and SP3, 5.1, and 6.0 allows remote attackers to cause a denial of service (ABEND) via an… Patch early 5.0 medium 40.3% 2005-09-08
CVE-2007-5641 EXP Multiple PHP remote file inclusion vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to execute arbitrary PHP code v… Patch early 6.8 medium 40.3% 2007-10-23
CVE-2015-6000 EXP Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.ph… Patch early 8.8 high 40.2% 2020-02-06
CVE-2007-5407 EXP Multiple PHP remote file inclusion vulnerabilities in the JContentSubscription (com_jcs) 1.5.8 component for Joomla! allow remote attackers to execute… Patch early 6.8 medium 40.2% 2007-10-12
CVE-2012-3579 EXP Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier for remote attackers to obtain p… Patch early 7.9 high 40.2% 2012-08-29
CVE-2009-2011 EXP Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not r… Patch early 9.3 high 40.2% 2009-06-16
CVE-2013-1710 EXP The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.… Patch early 10.0 high 40.1% 2013-08-07
CVE-2007-2481 EXP PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled… Patch early 6.8 medium 40.1% 2007-05-03
CVE-2014-8586 EXP SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands vi… Patch early 7.5 high 40.1% 2014-11-04
CVE-2009-1968 EXP Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknow… Patch early 4.3 medium 40.1% 2009-07-14
← previous page 132 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt