peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,567 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

320,061 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-0002 EXP The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, W… Patch early 7.2 high 13.8% 2015-01-13
CVE-2009-1675 EXP Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 227 reply to a PASV comma… Patch early 9.3 high 13.8% 2009-05-18
CVE-2017-7478 EXP OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue… Patch early 7.5 high 13.8% 2017-05-15
CVE-2010-4300 EXP Heap-based buffer overflow in the dissect_ldss_transfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector in Wireshark 1.2.0 through 1.2.… Patch early 7.5 high 13.8% 2010-11-26
CVE-2019-6973 EXP Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is conf… Patch early 7.5 high 13.8% 2019-03-21
CVE-2014-9473 EXP Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arb… Patch early 7.5 high 13.8% 2015-01-08
CVE-2022-23409 EXP The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php. Patch early 4.9 medium 13.8% 2022-01-31
CVE-2007-4498 EXP The Grandstream SIP Phone GXV-3000 with firmware 1.0.1.7, Loader 1.0.0.6, and Boot 1.0.0.18 allows remote attackers to force silent call completion, e… Patch early 7.8 high 13.8% 2007-08-23
CVE-2012-5321 EXP tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks… Patch early 5.8 medium 13.8% 2012-10-08
CVE-2018-4237 EXP An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchO… Patch early 7.8 high 13.7% 2018-06-08
CVE-2019-11415 EXP An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. A malformed login request allows remote attackers to cause a denial of service (reboot),… Patch early 7.5 high 13.7% 2019-04-22
CVE-2009-1902 EXP The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request… Patch early 5.0 medium 13.7% 2009-06-03
CVE-2006-3109 EXP Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), al… Patch early 4.3 medium 13.7% 2006-06-21
CVE-2013-3631 EXP NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.php, aka the "Advanced | Execut… Patch early 6.0 medium 13.7% 2013-11-02
CVE-2001-0522 EXP Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in th… Patch early 7.5 high 13.7% 2001-08-14
CVE-2013-3724 EXP The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash and service… Patch early 5.0 medium 13.7% 2013-08-01
CVE-2013-2765 EXP The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process… Patch early 5.0 medium 13.7% 2013-07-15
CVE-2003-0078 EXP ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding… Patch early 5.0 medium 13.7% 2003-03-03
CVE-2005-3684 EXP Multiple buffer overflows in freeFTPd 1.0.8, without logging enabled, allow remote authenticated attackers to cause a denial of service (application c… Patch early 7.5 high 13.7% 2005-11-19
CVE-2010-3146 EXP Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 allow local users to gain privileges via a Trojan horse (1) mso.dll or (2)… Patch early 9.3 high 13.7% 2010-08-27
CVE-2011-0614 EXP Buffer overflow in Adobe Audition 3.0.1 and earlier allows remote attackers to cause a denial of service (memory corruption and application crash) or… Patch early 9.3 high 13.7% 2011-05-16
CVE-2019-6442 EXP An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, rel… Patch early 6.5 medium 13.7% 2019-01-16
CVE-2004-1293 EXP Buffer overflow in the ReadFontTbl function in reader.c for rtf2latex2e 1.0fc2 allows remote attackers to execute arbitrary code via a crafted RTF fil… Patch early 10.0 high 13.7% 2005-01-10
CVE-2010-2918 EXP PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites (com_joomla-visites) component 1.1 RC2 for Joomla! allows re… Patch early 7.5 high 13.7% 2010-07-30
CVE-2002-0814 EXP Buffer overflow in VMware Authorization Service for VMware GSX Server 2.0.0 build-2050 allows remote authenticated users to execute arbitrary code via… Patch early 7.5 high 13.7% 2002-08-12
CVE-2009-1247 EXP SQL injection vulnerability in login.php in Acute Control Panel 1.0.0 allows remote attackers to execute arbitrary SQL commands via the username param… Patch early 7.5 high 13.7% 2009-04-06
CVE-2011-2443 EXP Multiple buffer overflows in Adobe Photoshop Elements 8.0 and earlier allow remote attackers to cause a denial of service (memory corruption and appli… Patch early 9.3 high 13.7% 2011-10-04
CVE-2003-0447 EXP The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via an argument t… Patch early 5.1 medium 13.7% 2003-07-24
CVE-2017-16353 EXP GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file… Patch early 6.5 medium 13.7% 2017-11-01
CVE-2003-0963 EXP Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9 and earlier allow remote HTTP servers to execute arbitrary code via l… Patch early 7.5 high 13.7% 2004-01-05
← previous page 173 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt