peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,488 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

186,613 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-3153 EXP Untrusted search path vulnerability in Adobe InDesign CS4 6.0, InDesign CS5 7.0.2 and earlier, Adobe InDesign Server CS5 7.0.2 and earlier, and Adobe… Patch early 9.3 high 13.6% 2010-08-27
CVE-2008-4310 EXP httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CP… Patch early 7.8 high 13.6% 2008-12-09
CVE-2004-2425 EXP Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and poss… Patch early 7.5 high 13.5% 2004-12-31
CVE-2007-1357 EXP The atalk_sum_skb function in AppleTalk for Linux kernel 2.6.x before 2.6.21, and possibly 2.4.x, allows remote attackers to cause a denial of service… Patch early 7.8 high 13.5% 2007-04-11
CVE-2007-1685 EXP Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a de… Patch early 10.0 high 13.5% 2007-06-08
CVE-2007-5467 EXP Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long… Patch early 10.0 high 13.5% 2007-10-15
CVE-2002-1048 EXP HP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet services via an SNMP request to the… Patch early 7.5 high 13.5% 2002-10-04
CVE-2019-8565 EXP A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A malicious application may be able… Patch early 7.0 high 13.5% 2019-12-18
CVE-2008-0964 EXP Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote… Patch early 9.3 high 13.5% 2008-08-08
CVE-2010-0972 EXP Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrar… Patch early 7.5 high 13.5% 2010-03-16
CVE-2018-6383 EXP Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extensio… Patch early 8.8 high 13.5% 2018-01-29
CVE-2019-6967 EXP AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF. Patch early 8.8 high 13.5% 2019-03-21
CVE-2006-1618 EXP Format string vulnerability in the (1) Con_message and (2) conPrintf functions in con_main.c in Doomsday engine 1.8.6 allows remote attackers to execu… Patch early 7.5 high 13.5% 2006-04-05
CVE-2019-9581 EXP phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP… Patch early 8.8 high 13.5% 2019-03-06
CVE-2017-6444 EXP The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows r… Patch early 7.5 high 13.5% 2017-03-12
CVE-2015-7241 EXP XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01. Patch early 9.8 critical 13.5% 2017-09-06
CVE-2017-16934 EXP The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content… Patch early 9.8 critical 13.5% 2017-11-24
CVE-2000-0941 EXP Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter. Patch early 10.0 high 13.5% 2000-12-19
CVE-2001-0021 EXP MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter. Patch early 10.0 high 13.5% 2001-02-16
CVE-2007-1536 EXP Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file th… Patch early 9.3 high 13.5% 2007-03-20
CVE-2017-3064 EXP Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a shape outline. Successful exploi… Patch early 7.8 high 13.5% 2017-04-12
CVE-2019-8647 EXP A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.4, tvOS 12.4, watchOS 5.3. A remote attacker may b… Patch early 9.8 critical 13.5% 2019-12-18
CVE-2018-0709 EXP Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitra… Patch early 8.8 high 13.4% 2018-07-17
CVE-2008-3956 EXP orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute… Patch early 9.3 high 13.4% 2008-09-11
CVE-2008-3732 EXP Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (applicat… Patch early 9.3 high 13.4% 2008-08-20
CVE-2011-1944 EXP Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers… Patch early 9.3 high 13.4% 2011-09-02
CVE-2019-17424 EXP A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewa… Patch early 7.8 high 13.4% 2019-10-22
CVE-2016-2278 EXP Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administ… Patch early 7.2 high 13.4% 2016-03-02
CVE-2013-4787 EXP Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitrar… Patch early 9.3 high 13.4% 2013-07-09
CVE-2016-9269 EXP Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_B… Patch early 9.9 critical 13.4% 2017-02-21
← previous page 173 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt