peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,488 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

186,613 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-2027 EXP Use-after-free vulnerability in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary cod… Patch early 9.3 high 13.3% 2012-05-09
CVE-2019-8613 EXP A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote attacker may… Patch early 9.8 critical 13.3% 2019-12-18
CVE-2006-2548 EXP Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url… Patch early 7.5 high 13.3% 2006-05-23
CVE-2019-12828 EXP An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and origin2:// URI schemes, it is poss… Patch early 8.8 high 13.3% 2019-06-14
CVE-2016-1879 EXP The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, when the kernel is configured f… Patch early 7.5 high 13.3% 2016-01-29
CVE-2011-2900 EXP Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server… Patch early 7.5 high 13.3% 2011-08-05
CVE-2020-5330 EXP Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 and older and Dell EMC PowerEd… Patch early 8.1 high 13.3% 2020-04-10
CVE-2004-0722 EXP Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allow… Patch early 10.0 high 13.2% 2004-08-18
CVE-2006-0146 EXP The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) X… Patch early 7.5 high 13.2% 2006-01-09
CVE-2010-4107 EXP The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printers, Color LaserJet MFP printers… Patch early 7.8 high 13.2% 2010-11-17
CVE-2009-2464 EXP The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote atta… Patch early 10.0 high 13.2% 2009-07-22
CVE-2009-0261 EXP Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary code via a Skins\DefaultSkin\D… Patch early 9.3 high 13.2% 2009-01-23
CVE-2010-2036 EXP Directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbit… Patch early 7.5 high 13.2% 2010-05-25
CVE-2004-0416 EXP Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execu… Patch early 10.0 high 13.2% 2004-08-06
CVE-2007-3181 EXP Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p… Patch early 10.0 high 13.2% 2007-06-12
CVE-2019-9792 EXP The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value c… Patch early 9.8 critical 13.2% 2019-04-26
CVE-2018-12604 EXP GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log. Patch early 7.5 high 13.2% 2018-06-20
CVE-2017-15663 EXP In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER… Patch early 7.5 high 13.2% 2018-01-10
CVE-2011-5127 EXP Directory traversal vulnerability in Blue Coat Reporter 9.x before 9.2.4.13, 9.2.5.x before 9.2.5.1, and 9.3 before 9.3.1.2 on Windows allows remote a… Patch early 10.0 high 13.2% 2012-08-26
CVE-2005-2310 EXP Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arbitrary code via an MP3 file wi… Patch early 9.3 high 13.1% 2005-07-19
CVE-2008-1801 EXP Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly exe… Patch early 9.3 high 13.1% 2008-05-12
CVE-2001-0197 EXP Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands. Patch early 10.0 high 13.1% 2001-03-26
CVE-2007-1645 EXP Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on U… Patch early 10.0 high 13.1% 2007-03-24
CVE-2013-4982 EXP AVTECH AVN801 DVR has a security bypass via the administration login captcha Patch early 9.8 critical 13.1% 2019-12-27
CVE-2006-5882 EXP Stack-based buffer overflow in the Broadcom BCMWL5.SYS wireless device driver 3.50.21.10, as used in Cisco Linksys WPC300N Wireless-N Notebook Adapter… Patch early 8.3 high 13.1% 2006-11-14
CVE-2000-0704 EXP Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFO commands. Patch early 10.0 high 13.1% 2000-10-20
CVE-2006-6697 EXP CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary… Patch early 7.5 high 13.1% 2006-12-22
CVE-2018-4121 EXP An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affect… Patch early 8.8 high 13.1% 2018-04-03
CVE-2008-5732 EXP Unrestricted file upload vulnerability in lib/image_upload.php in KafooeyBlog 1.55b allows remote attackers to execute arbitrary code by uploading a f… Patch early 7.5 high 13.1% 2008-12-26
CVE-2006-1959 EXP PHP remote file inclusion vulnerability in direct.php in ActualScripts ActualAnalyzer Lite 2.72 and earlier, Gold 7.63 and earlier, and Server 8.23 an… Patch early 7.5 high 13.1% 2006-04-21
← previous page 175 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt