peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,851 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

402,851 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-1878 EXP Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to… Patch early 7.5 high 15% 2008-04-17
CVE-2002-0723 EXP Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read… Patch early 7.5 high 15% 2002-09-24
CVE-2002-1187 EXP Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system v… Patch early 6.8 medium 15% 2002-12-11
CVE-2009-1765 EXP Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute arbitrary… Patch early 6.8 medium 15% 2009-05-22
CVE-2021-40378 EXP An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from th… Patch early 8.1 high 15% 2021-09-01
CVE-2018-0744 EXP The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows… Patch early 7.0 high 15% 2018-01-04
CVE-2000-0330 EXP The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL… Patch early 7.6 high 15% 1999-11-12
CVE-2010-1688 EXP Stack-based buffer overflow in 2BrightSparks SyncBack Freeware 3.2.20.0, and possibly other versions before 3.2.21, allows user-assisted remote attack… Patch early 9.3 high 15% 2010-05-24
CVE-2007-5158 EXP The focus handling for the onkeydown event in Microsoft Internet Explorer 6.0 allows remote attackers to change field focus and copy keystrokes via a… Patch early 4.3 medium 15% 2007-10-01
CVE-2012-0780 EXP Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di… Patch early 10.0 high 15% 2012-05-09
CVE-2008-2950 EXP The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constru… Patch early 7.5 high 15% 2008-07-07
CVE-2018-11586 EXP XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct… Patch early 9.8 critical 15% 2018-06-05
CVE-2025-5548 EXP A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component NOOP Comman… Patch early 7.3 high 15% 2025-06-04
CVE-2008-1307 EXP Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 2007.12.29.29… Patch early 10.0 high 15% 2008-03-12
CVE-2006-6602 EXP explorer.exe in Windows Explorer 6.00.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a c… Patch early 4.3 medium 15% 2006-12-15
CVE-2006-1664 EXP Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, allows remote attackers to exec… Patch early 7.5 high 15% 2006-04-07
CVE-2008-0225 EXP Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arb… Patch early 6.4 medium 15% 2008-01-10
CVE-2009-1068 EXP Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote attackers to cause a denial o… Patch early 9.3 high 15% 2009-03-26
CVE-2001-0555 EXP ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot dot) attack through (1) the SITE… Patch early 10.0 high 15% 2001-08-14
CVE-2006-4159 EXP Multiple PHP remote file inclusion vulnerabilities in Chaussette 080706 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 15% 2006-08-16
CVE-2002-0974 EXP Help and Support Center for Windows XP allows remote attackers to delete arbitrary files via a link to the hcp: protocol that accesses uplddrvinfo.htm… Patch early 5.0 medium 15% 2002-09-24
CVE-2013-4775 EXP NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, GS… Patch early 7.8 high 15% 2013-12-19
CVE-2018-18557 EXP LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0… Patch early 8.8 high 15% 2018-10-22
CVE-1999-0755 EXP Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option. Patch early 5.0 medium 15% 1999-05-27
CVE-2019-1347 EXP A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID… Patch early 6.5 medium 14.9% 2019-10-10
CVE-1999-0146 EXP The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in… Patch early 7.5 high 14.9% 1997-07-15
CVE-2014-5210 EXP The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2… Patch early 10.0 high 14.9% 2014-08-21
CVE-2002-0448 EXP Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many "C:/" sequ… Patch early 5.0 medium 14.9% 2002-07-26
CVE-2004-2262 EXP ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uplo… Patch early 7.5 high 14.9% 2004-12-31
CVE-2008-0782 EXP Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the MOIN_ID… Patch early 5.0 medium 14.9% 2008-02-14
← previous page 209 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt