peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,074 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

401,074 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2011-3490 EXP Multiple stack-based buffer overflows in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to cause a denial of service (cr… Patch early 10.0 high 36.4% 2011-09-16
CVE-2008-5790 EXP Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla! allow remote attackers to ex… Patch early 7.5 high 36.4% 2008-12-31
CVE-2014-8499 EXP Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition bef… Patch early 6.5 medium 36.4% 2014-11-17
CVE-2015-2461 EXP ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Wind… Patch early 9.3 high 36.4% 2015-08-15
CVE-2012-4924 EXP Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 allows remote attackers to execut… Patch early 9.3 high 36.3% 2012-09-15
CVE-2009-1831 EXP The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted… Patch early 9.3 high 36.3% 2009-05-29
CVE-2012-0393 EXP The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to cr… Patch early 6.4 medium 36.3% 2012-01-08
CVE-2012-0284 EXP Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.ocx on the Cisco WVC200 Wireles… Patch early 9.3 high 36.3% 2012-07-19
CVE-2009-0215 EXP Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo comp… Patch early 9.3 high 36.3% 2009-03-25
CVE-2018-6580 EXP Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request. Patch early 9.8 critical 36.3% 2018-02-02
CVE-2014-6036 EXP Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0, and IT360 10.3… Patch early 6.4 medium 36.3% 2014-12-04
CVE-2022-26965 EXP In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution. Patch early 7.2 high 36.3% 2022-03-18
CVE-2008-5664 EXP Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows remote attackers to execute a… Patch early 9.3 high 36.2% 2008-12-19
CVE-2008-3878 EXP Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows r… Patch early 9.3 high 36.2% 2008-09-02
CVE-2007-2581 EXP Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server… Patch early 4.3 medium 36.2% 2007-05-09
CVE-2007-2884 EXP Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption)… Patch early 9.3 high 36.2% 2007-05-30
CVE-2002-0659 EXP The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encoding… Patch early 5.0 medium 36.2% 2002-08-12
CVE-2003-0231 EXP Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a… Patch early 5.0 medium 36.2% 2003-08-27
CVE-2015-6835 EXP The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow… Patch early 9.8 critical 36.2% 2016-05-16
CVE-2011-2763 EXP The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitrary commands via a modified req… Patch early 7.5 high 36.1% 2011-09-02
CVE-2021-42697 EXP Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to… Patch early 7.5 high 36.1% 2021-11-02
CVE-2013-4976 EXP Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials Patch early 9.8 critical 36.1% 2019-12-27
CVE-2007-3410 EXP Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPlayer 10, 10.1, and possibly 10.… Patch early 9.3 high 36.1% 2007-06-26
CVE-2012-3752 EXP Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a denial of service (application c… Patch early 9.3 high 36% 2012-11-09
CVE-2010-1527 EXP Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a long call-back-url parameter i… Patch early 9.3 high 36% 2010-08-23
CVE-2008-5518 EXP Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allo… Patch early 9.4 high 35.9% 2009-04-17
CVE-1999-1412 EXP A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flo… Patch early 5.0 medium 35.9% 1999-06-03
CVE-2006-5162 EXP wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a denial of service (unhandled exception and crash) vi… Patch early 5.0 medium 35.9% 2006-10-05
CVE-2014-0784 EXP Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a cr… Patch early 8.3 high 35.9% 2014-03-14
CVE-2014-8998 EXP lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a crafted HTTP header to index.ph… Patch early 6.5 medium 35.9% 2014-11-20
← previous page 141 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt