peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,590 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

149,905 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-6412 EXP In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310. Patch early 8.1 high 7.5% 2017-03-30
CVE-2019-8558 EXP Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1,… Patch early 8.8 high 7.5% 2019-12-18
CVE-2010-1239 EXP Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Action /S /Launch" sequence, and… Patch early 9.3 high 7.5% 2010-04-05
CVE-2008-1613 EXP SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and 7.0, allows remote attackers t… Patch early 7.5 high 7.5% 2008-04-22
CVE-2009-1807 EXP Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the Se… Patch early 9.3 high 7.5% 2009-05-28
CVE-2008-5753 EXP Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary code via a bookmark file entry… Patch early 9.3 high 7.5% 2008-12-30
CVE-2019-6279 EXP ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnerability via the cgi-bin/webproc… Patch early 8.8 high 7.5% 2019-03-21
CVE-2006-7157 EXP Buffer overflow in Google Earth v4.0.2091 (beta) allows remote user-assisted attackers to cause a denial of service (crash) via a KML or KMZ file with… Patch early 7.1 high 7.5% 2007-03-07
CVE-2006-7128 EXP PHP remote file inclusion vulnerability in forum/forum.php JAF CMS 4.0 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the webs… Patch early 7.5 high 7.5% 2007-03-06
CVE-2017-7037 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 8.8 high 7.5% 2017-07-20
CVE-2022-40946 EXP On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via the sys_token parameter in a cg… Patch early 7.5 high 7.5% 2023-04-16
CVE-2011-4644 EXP Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally does… Patch early 9.3 high 7.5% 2012-01-03
CVE-2011-5002 EXP Multiple stack-based buffer overflows in Final Draft 8 before 8.02 allow remote attackers to execute arbitrary code via a .fdx or .fdxt file with long… Patch early 10.0 high 7.5% 2011-12-25
CVE-2008-5680 EXP Multiple buffer overflows in Opera before 9.63 might allow (1) remote attackers to execute arbitrary code via a crafted text area, or allow (2) user-a… Patch early 9.3 high 7.5% 2008-12-19
CVE-2018-7449 EXP SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an invalid LIST, STOR, or RETR comm… Patch early 7.5 high 7.5% 2018-03-04
CVE-2015-5074 EXP Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM before 5.0.9… Patch early 7.5 high 7.5% 2015-09-29
CVE-2007-2787 EXP Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in LeadTools Raster Thumbnail Object… Patch early 7.5 high 7.5% 2007-05-21
CVE-2009-0259 EXP The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary c… Patch early 9.3 high 7.5% 2009-01-22
CVE-2010-3000 EXP Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows… Patch early 9.3 high 7.5% 2010-08-30
CVE-2016-7098 EXP Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass inte… Patch early 8.1 high 7.5% 2016-09-26
CVE-2007-1029 EXP Stack-based buffer overflow in the Connect method in the IMAP4 component in Quiksoft EasyMail Objects before 6.5 allows remote attackers to execute ar… Patch early 7.6 high 7.5% 2007-02-21
CVE-2018-20735 EXP An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement and escalation… Patch early 7.8 high 7.5% 2019-01-17
CVE-2014-9262 EXP The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files. Patch early 8.2 high 7.5% 2017-08-07
CVE-2007-5248 EXP Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3… Patch early 9.3 high 7.5% 2007-10-06
CVE-2011-4221 EXP Unspecified vulnerability in Investintech.com Able2Doc and Able2Doc Professional allows remote attackers to cause a denial of service (application cra… Patch early 9.3 high 7.5% 2011-11-01
CVE-2011-4222 EXP Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a denial of service (application c… Patch early 9.3 high 7.5% 2011-11-01
CVE-2007-1074 EXP Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long (1) DataPa… Patch early 9.3 high 7.5% 2007-02-22
CVE-2006-7236 EXP The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attacke… Patch early 9.3 high 7.5% 2009-01-02
CVE-2001-0262 EXP Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL. Patch early 7.5 high 7.5% 2001-07-02
CVE-2004-1926 EXP Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4)… Patch early 7.5 high 7.5% 2004-04-11
← previous page 179 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt