peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,267 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

319,807 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-1558 EXP Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote attackers to overwrite memory and… Patch early 10.0 high 16.8% 2008-03-31
CVE-2007-6454 EXP Heap-based buffer overflow in the handshakeHTTP function in servhs.cpp in PeerCast 0.1217 and earlier, and SVN 344 and earlier, allows remote attacker… Patch early 10.0 high 16.8% 2007-12-20
CVE-1999-0224 EXP Denial of service in Windows NT messenger service through a long username. Patch early 5.0 medium 16.8% 1999-07-23
CVE-2018-0494 EXP GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line. Patch early 6.5 medium 16.8% 2018-05-06
CVE-2014-4936 EXP The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.1012 and earl… Patch early 9.3 high 16.8% 2014-12-16
CVE-2008-2167 EXP Cross-site scripting (XSS) vulnerability in ZyXEL ZyWALL 100 allows remote attackers to inject arbitrary web script or HTML via the Referer header, wh… Patch early 4.3 medium 16.8% 2008-05-13
CVE-2021-3291 EXP Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting… Patch early 7.2 high 16.8% 2021-01-26
CVE-2019-16758 EXP In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2… Patch early 7.5 high 16.8% 2019-11-21
CVE-2016-5680 EXP Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authentica… Patch early 8.8 high 16.8% 2016-08-31
CVE-2006-0323 EXP Buffer overflow in swfformat.dll in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, Rhapsody 3, and Helix Playe… Patch early 9.3 high 16.7% 2006-03-23
CVE-2009-0263 EXP Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1)… Patch early 10.0 high 16.7% 2009-01-23
CVE-2016-8523 EXP A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found. Patch early 8.8 high 16.7% 2018-02-15
CVE-2009-0065 EXP Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.28-git8 al… Patch early 10.0 high 16.7% 2009-01-07
CVE-2014-2087 EXP Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8… Patch early 9.3 high 16.7% 2014-03-18
CVE-2000-1221 EXP The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the l… Patch early 10.0 high 16.7% 2000-01-08
CVE-2009-3020 EXP win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file… Patch early 7.1 high 16.7% 2009-08-31
CVE-2012-6554 EXP functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute arbitrary PHP code via the me… Patch early 6.5 medium 16.7% 2013-05-23
CVE-2010-1494 EXP Directory traversal vulnerability in the AWDwall (com_awdwall) component 1.5.4 for Joomla! allows remote attackers to read arbitrary files via a .. (d… Patch early 5.0 medium 16.7% 2010-04-23
CVE-2003-1275 EXP Pocket Internet Explorer (PIE) 3.0 allows remote attackers to cause a denial of service (crash) via a Javascript function that uses the object.innerHT… Patch early 5.0 medium 16.7% 2003-12-31
CVE-2005-1476 EXP Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a pre… Patch early 5.1 medium 16.7% 2005-05-09
CVE-2018-15140 EXP Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal t… Patch early 6.5 medium 16.7% 2018-08-13
CVE-2012-3748 EXP Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary code or cause a denial of serv… Patch early 5.1 medium 16.7% 2012-11-03
CVE-2018-1042 EXP Moodle 3.x has Server Side Request Forgery in the filepicker. Patch early 6.5 medium 16.7% 2018-01-22
CVE-2022-2551 EXP The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of th… Patch early 7.5 high 16.7% 2022-08-22
CVE-2012-4412 EXP Integer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denial… Patch early 7.5 high 16.7% 2013-10-09
CVE-2019-14378 EXP ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment… Patch early 8.8 high 16.7% 2019-07-29
CVE-2017-17085 EXP In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissectors/packet-cipsafety.c by val… Patch early 7.5 high 16.7% 2017-12-01
CVE-2010-1280 EXP Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch early 8.8 high 16.6% 2010-05-13
CVE-2009-0490 EXP Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions bef… Patch early 9.3 high 16.6% 2009-02-10
CVE-2020-28337 EXP A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via… Patch early 7.2 high 16.6% 2021-02-15
← previous page 154 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt