peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,200 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

149,784 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2013-3429 EXP Multiple directory traversal vulnerabilities in Cisco Video Surveillance Manager (VSM) before 7.0.0 allow remote attackers to read system files via a… Patch early 7.8 high 10.2% 2013-07-25
CVE-2007-1866 EXP Stack-based buffer overflow in the dns_decode_reverse_name function in dns_decode.c in dproxy-nexgen allows remote attackers to execute arbitrary code… Patch early 10.0 high 10.2% 2007-04-04
CVE-2009-2934 EXP Multiple stack-based buffer overflows in xaudio.dll in Programmed Integration PIPL 2.5.0 and 2.5.0D allow remote attackers to execute arbitrary code v… Patch early 9.3 high 10.2% 2009-08-21
CVE-2007-0646 EXP Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a de… Patch early 7.1 high 10.2% 2007-02-01
CVE-2012-3755 EXP Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via… Patch early 9.3 high 10.2% 2012-11-09
CVE-2006-6287 EXP Stack-based buffer overflow in AtomixMP3 2.3 and earlier allows remote attackers to execute arbitrary code via a long pathname in an M3U file. Patch early 7.5 high 10.2% 2006-12-04
CVE-2008-1116 EXP Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner allows remote attackers to force… Patch early 9.3 high 10.2% 2008-03-03
CVE-2017-15048 EXP Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrar… Patch early 8.8 high 10.2% 2017-12-19
CVE-1999-0875 EXP DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes. Patch early 7.5 high 10.2% 1999-08-11
CVE-2022-47875 EXP A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code. Patch early 8.8 high 10.2% 2023-05-02
CVE-2000-0474 EXP Real Networks RealServer 7.x allows remote attackers to cause a denial of service via a malformed request for a page in the viewsource directory. Patch early 7.8 high 10.2% 2000-06-01
CVE-2011-0920 EXP The Remote Console in IBM Lotus Domino, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to byp… Patch early 9.3 high 10.2% 2011-02-08
CVE-2009-1314 EXP body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the savefile action with a file par… Patch early 10.0 high 10.1% 2009-04-17
CVE-1999-0562 EXP The registry in Windows NT can be accessed remotely by users who are not administrators. Patch early 7.5 high 10.1% 1997-01-01
CVE-2016-4340 EXP The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4… Patch early 8.8 high 10.1% 2017-01-23
CVE-2009-0450 EXP Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code via a long string in a playlis… Patch early 9.3 high 10.1% 2009-02-10
CVE-2007-2458 EXP Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in t… Patch early 7.5 high 10.1% 2007-05-02
CVE-2017-14084 EXP A potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to execute arbitrary code on vulne… Patch early 8.1 high 10.1% 2017-10-06
CVE-2016-9091 EXP Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command injec… Patch early 7.2 high 10.1% 2017-04-05
CVE-2006-3668 EXP Heap-based buffer overflow in the it_read_envelope function in Dynamic Universal Music Bibliotheque (DUMB) 0.9.3 and earlier and current CVS as of 200… Patch early 7.6 high 10.1% 2006-07-18
CVE-2010-3179 EXP Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and… Patch early 9.3 high 10.1% 2010-10-21
CVE-2002-0128 EXP cgitest.exe in Sambar Server 5.1 before Beta 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long a… Patch early 7.5 high 10.1% 2002-03-25
CVE-2008-4652 EXP Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execute arbitr… Patch early 9.3 high 10.1% 2008-10-22
CVE-2007-2156 EXP Multiple PHP remote file inclusion vulnerabilities in Rezervi Generic 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the root p… Patch early 7.5 high 10.1% 2007-04-19
CVE-2007-2597 EXP Multiple PHP remote file inclusion vulnerabilities in telltarget CMS 1.3.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) o… Patch early 7.5 high 10.1% 2007-05-11
CVE-2007-3217 EXP Multiple PHP remote file inclusion vulnerabilities in Prototype of an PHP application 0.1 allow remote attackers to execute arbitrary PHP code via a U… Patch early 7.5 high 10.1% 2007-06-14
CVE-2007-0561 EXP Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root… Patch early 7.5 high 10.1% 2007-01-30
CVE-2008-2693 EXP Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to… Patch early 9.3 high 10.1% 2008-06-13
CVE-2009-2364 EXP Stack-based buffer overflow in Mp3-Nator 2.0 allows remote attackers to execute arbitrary code via (1) a long string in a .plf file and (2) a long str… Patch early 9.3 high 10.1% 2009-07-08
CVE-2006-5058 EXP Buffer overflow in (1) Call of Duty 1.5b and earlier, (2) Call of Duty United Offensive 1.51b and earlier, and (3) Call of Duty 2 1.3 and earlier allo… Patch early 7.5 high 10.1% 2006-09-28
← previous page 150 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt