peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,553 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

320,595 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-27826 EXP SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. which allows attackers… Patch early 8.8 high 11.8% 2023-04-12
CVE-2007-2285 EXP Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote attackers to read arbitrary f… Patch early 7.8 high 11.8% 2007-04-26
CVE-2018-8468 EXP An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." This affec… Patch early 4.7 medium 11.8% 2018-09-13
CVE-2013-1605 EXP Buffer overflow in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to execute arbitrary code via a long filename in… Patch early 7.5 high 11.8% 2014-03-25
CVE-2004-1192 EXP Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitrary code via format string… Patch early 10.0 high 11.7% 2005-01-10
CVE-2012-6083 EXP Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet. Patch early 7.5 high 11.7% 2020-01-23
CVE-2008-1912 EXP Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause a denial of service (applicat… Patch early 9.3 high 11.7% 2008-04-22
CVE-2013-6021 EXP Buffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code via a long sessionid value in… Patch early 9.3 high 11.7% 2013-10-19
CVE-2005-4573 EXP PHP remote file include vulnerability in plog-admin-functions.php in Plogger Beta 2 allows remote attackers to execute arbitrary code via a URL in the… Patch early 7.5 high 11.7% 2005-12-29
CVE-2014-7884 EXP Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated attack vectors. Patch early 9.0 high 11.7% 2015-03-14
CVE-2010-1029 EXP Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS… Patch early 5.0 medium 11.7% 2010-03-19
CVE-2000-0256 EXP Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise av… Patch early 7.5 high 11.7% 2000-04-19
CVE-2019-12744 EXP SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-2018… Patch early 7.5 high 11.7% 2019-06-20
CVE-2007-5722 EXP Stack-based buffer overflow in a certain ActiveX control in GLChat.ocx 2.5.1.32 in GlobalLink 2.7.0.8, as used in Ourgame GLWorld and possibly other p… Patch early 7.5 high 11.7% 2007-10-30
CVE-2013-4295 EXP The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an external… Patch early 5.0 medium 11.7% 2013-10-24
CVE-2019-9768 EXP Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timestamp, which makes it easier for… Patch early 7.5 high 11.7% 2019-03-14
CVE-2009-0174 EXP Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in the HREF attribute of a REF elem… Patch early 9.3 high 11.7% 2009-01-20
CVE-2010-3631 EXP Array index error in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Mac OS X allows attackers to execute arbitrary code via unspecifi… Patch early 9.3 high 11.7% 2010-10-06
CVE-2000-0245 EXP Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts. Patch early 10.0 high 11.7% 2000-03-27
CVE-2006-3228 EXP Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary code via a crafted .mid (MIDI)… Patch early 9.3 high 11.7% 2006-06-26
CVE-2006-1206 EXP Matt Johnston Dropbear SSH server 0.47 and earlier, as used in embedded Linux devices and on general-purpose operating systems, allows remote attacker… Patch early 5.0 medium 11.7% 2006-03-14
CVE-2005-2792 EXP Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in… Patch early 5.0 medium 11.7% 2005-09-02
CVE-2007-5604 EXP Buffer overflow in the ExtractCab function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0… Patch early 7.5 high 11.7% 2008-06-04
CVE-2010-2122 EXP Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows remote attackers to include and… Patch early 6.8 medium 11.7% 2010-06-01
CVE-1999-1520 EXP A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, whi… Patch early 5.0 medium 11.7% 1999-05-11
CVE-2008-0333 EXP Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read a… Patch early 5.0 medium 11.7% 2008-01-17
CVE-2012-4512 EXP The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memo… Patch early 8.8 high 11.7% 2020-02-08
CVE-2014-3976 EXP Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a… Patch early 5.0 medium 11.6% 2014-06-05
CVE-2001-0311 EXP Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client. Patch early 4.6 medium 11.6% 2001-06-02
CVE-2010-0050 EXP Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (ap… Patch early 8.8 high 11.6% 2010-03-15
← previous page 190 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt