peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,095 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

149,750 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-14095 EXP A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution… Patch early 8.1 high 12.5% 2018-01-19
CVE-2022-28213 EXP When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the X… Patch early 8.1 high 12.5% 2022-04-12
CVE-2016-7065 EXP The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and poss… Patch early 8.8 high 12.5% 2016-10-13
CVE-2007-5184 EXP Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute arbitrary code via format strin… Patch early 7.5 high 12.5% 2007-10-03
CVE-2009-3613 EXP The swiotlb functionality in the r8169 driver in drivers/net/r8169.c in the Linux kernel before 2.6.27.22 allows remote attackers to cause a denial of… Patch early 7.8 high 12.5% 2009-10-19
CVE-1999-0178 EXP Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a… Patch early 7.5 high 12.5% 1997-01-01
CVE-2010-1033 EXP Multiple stack-based buffer overflows in a certain Tetradyne ActiveX control in HP Operations Manager 7.5, 8.10, and 8.16 might allow remote attackers… Patch early 9.3 high 12.4% 2010-04-21
CVE-2020-23342 EXP A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users. Patch early 8.8 high 12.4% 2021-01-19
CVE-2015-3796 EXP The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute arbitrary code or cause a deni… Patch early 7.5 high 12.4% 2015-08-17
CVE-2015-3292 EXP The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, whi… Patch early 10.0 high 12.4% 2015-05-31
CVE-2000-0733 EXP Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrar… Patch early 10.0 high 12.4% 2000-10-20
CVE-2008-0234 EXP Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute… Patch early 9.3 high 12.4% 2008-01-11
CVE-2004-1286 EXP Buffer overflow in the auto_filter_extern function in auto.c for NapShare 1.2, with the extern filter enabled, allows remote attackers to execute arbi… Patch early 10.0 high 12.4% 2005-01-10
CVE-2013-0804 EXP The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of ser… Patch early 10.0 high 12.4% 2013-02-24
CVE-2005-1261 EXP Stack-based buffer overflow in the URL parsing function in Gaim before 1.3.0 allows remote attackers to execute arbitrary code via an instant message… Patch early 7.5 high 12.4% 2005-05-11
CVE-2014-2044 EXP Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass int… Patch early 7.5 high 12.4% 2014-10-06
CVE-2007-5740 EXP The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code… Patch early 7.5 high 12.4% 2007-10-31
CVE-2009-1209 EXP Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script tag with a long defer attribu… Patch early 9.3 high 12.4% 2009-04-01
CVE-2018-5319 EXP RAVPower FileHub 2.000.056 allows remote users to steal sensitive information via a crafted HTTP request. Patch early 7.5 high 12.4% 2018-01-24
CVE-2005-1787 EXP setup.php in phpStat 1.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the $check variable. Patch early 7.5 high 12.3% 2005-05-27
CVE-2016-10401 EXP ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account passwor… Patch early 8.8 high 12.3% 2017-07-25
CVE-2007-3148 EXP Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute ar… Patch early 9.3 high 12.3% 2007-06-11
CVE-2020-10386 EXP admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by uploading a .php fil… Patch early 7.2 high 12.3% 2020-03-12
CVE-2013-4975 EXP Hikvision DS-2CD7153-E IP Camera has Privilege Escalation Patch early 8.8 high 12.3% 2019-12-27
CVE-2010-0437 EXP The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving a… Patch early 7.8 high 12.3% 2010-03-24
CVE-2018-15767 EXP The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerability caused by a misconfigura… Patch early 8.8 high 12.3% 2018-11-30
CVE-2023-22629 EXP An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the newPath parameter. An authenti… Patch early 8.8 high 12.3% 2023-02-14
CVE-2019-15029 EXP FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will ins… Patch early 8.8 high 12.3% 2019-09-05
CVE-2018-4192 EXP An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affe… Patch early 7.5 high 12.3% 2018-06-08
CVE-2007-6533 EXP Buffer overflow in Zoom Player 6.00 beta 2 and earlier allows user-assisted remote attackers to execute arbitrary code via an HTTP link to a PLS file… Patch early 7.5 high 12.3% 2007-12-27
← previous page 135 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt