peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,573 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

320,066 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-3064 EXP Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a shape outline. Successful exploi… Patch early 7.8 high 13.5% 2017-04-12
CVE-2018-0709 EXP Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitra… Patch early 8.8 high 13.4% 2018-07-17
CVE-2008-3956 EXP orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute… Patch early 9.3 high 13.4% 2008-09-11
CVE-2008-3732 EXP Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (applicat… Patch early 9.3 high 13.4% 2008-08-20
CVE-2011-1944 EXP Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers… Patch early 9.3 high 13.4% 2011-09-02
CVE-2005-0815 EXP Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corr… Patch early 6.4 medium 13.4% 2005-05-02
CVE-2019-17424 EXP A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewa… Patch early 7.8 high 13.4% 2019-10-22
CVE-2016-2278 EXP Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administ… Patch early 7.2 high 13.4% 2016-03-02
CVE-2013-4787 EXP Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitrar… Patch early 9.3 high 13.4% 2013-07-09
CVE-2005-3737 EXP Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute arbitrary code via a SVG file… Patch early 5.1 medium 13.4% 2005-11-22
CVE-2019-10863 EXP A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file wit… Patch early 7.2 high 13.4% 2019-04-04
CVE-1999-0196 EXP websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variabl… Patch early 5.0 medium 13.4% 1997-07-08
CVE-2019-8043 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 7.5 high 13.4% 2019-08-20
CVE-2011-2628 EXP Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary code or cause a denial of service… Patch early 10.0 high 13.4% 2011-07-01
CVE-2017-1000373 EXP The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort()… Patch early 6.5 medium 13.4% 2017-06-19
CVE-2013-2683 EXP Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresse… Patch early 5.3 medium 13.4% 2020-02-06
CVE-2017-10661 EXP Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption… Patch early 7.0 high 13.4% 2017-08-19
CVE-2010-1653 EXP Directory traversal vulnerability in graphics.php in the Graphics (com_graphics) component 1.0.6 and 1.5.0 for Joomla! allows remote attackers to incl… Patch early 7.5 high 13.4% 2010-05-03
CVE-2018-1000001 EXP In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading t… Patch early 7.8 high 13.4% 2018-01-31
CVE-2004-1437 EXP Multiple buffer overflows in the digest authentication functionality in Pavuk 0.9.28-r2 and earlier allow remote attackers to execute arbitrary code. Patch early 7.5 high 13.4% 2004-12-31
CVE-2010-1470 EXP Directory traversal vulnerability in the Web TV (com_webtv) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly hav… Patch early 7.5 high 13.4% 2010-04-19
CVE-2010-1472 EXP Directory traversal vulnerability in the Daily Horoscope (com_horoscope) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files v… Patch early 7.5 high 13.4% 2010-04-19
CVE-2012-4329 EXP The Samsung D6000 TV and possibly other products allow remote attackers to cause a denial of service (continuous restart) via a crafted controller nam… Patch early 7.8 high 13.3% 2012-08-14
CVE-2002-2062 EXP Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP si… Patch early 4.3 medium 13.3% 2002-12-31
CVE-2010-0985 EXP Directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla! allows remote attackers to include and execute a… Patch early 7.5 high 13.3% 2010-03-16
CVE-2002-0495 EXP csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, whi… Patch early 10.0 high 13.3% 2002-08-12
CVE-2001-0099 EXP bsguest.cgi guestbook script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address. Patch early 10.0 high 13.3% 2001-02-12
CVE-2009-0388 EXP Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap… Patch early 10.0 high 13.3% 2009-02-04
CVE-2010-3709 EXP The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of… Patch early 4.3 medium 13.3% 2010-11-09
CVE-2015-3798 EXP The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute arbitrary code or cause a deni… Patch early 7.5 high 13.3% 2015-08-17
← previous page 176 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt