peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,317 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

186,529 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-17672 EXP In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circums… Patch early 9.8 critical 15.2% 2017-12-14
CVE-2017-9380 EXP OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context… Patch early 8.8 high 15.2% 2017-06-02
CVE-2006-4253 EXP Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arb… Patch early 7.6 high 15.2% 2006-08-21
CVE-2017-5991 EXP An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function in pdf-op-run.c encounters a NU… Patch early 7.5 high 15.2% 2017-02-15
CVE-2014-2674 EXP Directory traversal vulnerability in the Ajax Pagination (twitter Style) plugin 1.1 for WordPress allows remote attackers to read arbitrary files via… Patch early 7.5 high 15.2% 2018-03-19
CVE-2011-3499 EXP Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execut… Patch early 10.0 high 15.2% 2011-09-16
CVE-2013-6924 EXP Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip… Patch early 9.8 critical 15.2% 2017-10-11
CVE-2014-5091 EXP A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user… Patch early 9.8 critical 15.2% 2020-02-07
CVE-2018-18322 EXP CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_… Patch early 9.8 critical 15.1% 2018-10-15
CVE-2015-2780 EXP Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an execut… Patch early 9.8 critical 15.1% 2017-10-16
CVE-2007-6682 EXP Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary c… Patch early 7.5 high 15.1% 2008-01-17
CVE-2019-8024 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 9.8 critical 15.1% 2019-08-20
CVE-2016-5228 EXP Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11997 and 9.… Patch early 9.8 critical 15.1% 2016-07-03
CVE-2019-1019 EXP A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages. To exploit this vulnerabi… Patch early 8.5 high 15.1% 2019-06-12
CVE-2018-2636 EXP Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security). Supported versions that are af… Patch early 8.1 high 15.1% 2018-01-18
CVE-2010-1533 EXP Directory traversal vulnerability in the TweetLA (com_tweetla) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (d… Patch early 7.5 high 15.1% 2010-04-26
CVE-2010-3150 EXP Untrusted search path vulnerability in Adobe Premier Pro CS4 4.0.0 (314 (MC: 160820)) allows local users, and possibly remote attackers, to execute ar… Patch early 9.3 high 15.1% 2010-08-27
CVE-2010-3151 EXP Untrusted search path vulnerability in Adobe On Location CS4 Build 315 allows local users, and possibly remote attackers, to execute arbitrary code an… Patch early 9.3 high 15.1% 2010-08-27
CVE-2013-1602 EXP An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01,… Patch early 7.5 high 15.1% 2020-01-28
CVE-2008-3795 EXP Buffer overflow in Ipswitch WS_FTP Home client allows remote FTP servers to have an unknown impact via a long "message response." Patch early 10.0 high 15.1% 2008-08-27
CVE-2010-3140 EXP Untrusted search path vulnerability in Microsoft Windows Internet Communication Settings on Windows XP SP3 allows local users, and possibly remote att… Patch early 9.3 high 15.1% 2010-08-27
CVE-2016-3974 EXP XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial… Patch early 9.1 critical 15.1% 2016-04-07
CVE-2002-0163 EXP Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to cause a d… Patch early 7.5 high 15.1% 2002-03-26
CVE-2008-2712 EXP Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize… Patch early 9.3 high 15% 2008-06-16
CVE-2008-1878 EXP Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to… Patch early 7.5 high 15% 2008-04-17
CVE-2002-0723 EXP Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read… Patch early 7.5 high 15% 2002-09-24
CVE-2021-40378 EXP An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from th… Patch early 8.1 high 15% 2021-09-01
CVE-2018-0744 EXP The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows… Patch early 7.0 high 15% 2018-01-04
CVE-2000-0330 EXP The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL… Patch early 7.6 high 15% 1999-11-12
CVE-2010-1688 EXP Stack-based buffer overflow in 2BrightSparks SyncBack Freeware 3.2.20.0, and possibly other versions before 3.2.21, allows user-assisted remote attack… Patch early 9.3 high 15% 2010-05-24
← previous page 164 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt