peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,011 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

321,002 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2013-2416 EXP Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier allows remote attackers to affect… Patch early 4.3 medium 8.8% 2013-04-17
CVE-2010-2482 EXP LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to cause a denial of service (NUL… Patch early 4.3 medium 8.8% 2010-07-06
CVE-2007-3487 EXP Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote attackers to… Patch early 6.4 medium 8.8% 2007-06-29
CVE-2014-0372 EXP Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 1… Patch early 5.5 medium 8.8% 2014-01-15
CVE-2012-4878 EXP Absolute path traversal vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 allows remote administrators to read arbitrary files via a full… Patch early 5.0 medium 8.8% 2012-09-06
CVE-2007-2983 EXP Multiple buffer overflows in the British Telecommunications Consumer webhelper ActiveX control before 2.0.0.8 in btwebcontrol.dll allow remote attacke… Patch early 9.3 high 8.8% 2007-10-25
CVE-2015-8258 EXP AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script E… Patch early 7.5 high 8.8% 2017-04-10
CVE-2013-3539 EXP Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC… Patch early 6.8 medium 8.8% 2013-10-01
CVE-2006-2665 EXP PHP remote file inclusion vulnerability in includes/mailaccess/pop3/core.php in V-Webmail 1.3 allows remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 8.8% 2006-05-30
CVE-2014-4643 EXP Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a denial of service (application cr… Patch early 5.0 medium 8.8% 2014-06-25
CVE-2013-3239 EXP phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary… Patch early 4.6 medium 8.8% 2013-04-26
CVE-2018-18759 EXP Modbus Slave 7.0.0 in modbus tools has a Buffer Overflow. Patch early 7.5 high 8.8% 2018-11-16
CVE-2014-10079 EXP In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML sou… Patch early 5.3 medium 8.7% 2019-02-23
CVE-2003-1260 EXP Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command. Patch early 7.6 high 8.7% 2003-12-31
CVE-2007-1998 EXP Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP code via the Email field, whic… Patch early 7.5 high 8.7% 2007-04-12
CVE-2009-0885 EXP Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a denial of service (application… Patch early 9.3 high 8.7% 2009-03-12
CVE-2011-3489 EXP RnaUtility.dll in RsvcHost.exe 2.30.0.23 in Rockwell RSLogix 19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted… Patch early 5.0 medium 8.7% 2011-09-16
CVE-2007-0886 EXP Heap-based buffer underflow in axigen 1.2.6 through 2.0.0b1 allows remote attackers to cause a denial of service (application crash) and possibly exec… Patch early 10.0 high 8.7% 2007-02-12
CVE-2017-15271 EXP A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729. This issue could be triggered prior to authentica… Patch early 5.9 medium 8.7% 2017-11-15
CVE-2008-2684 EXP The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via long s… Patch early 9.3 high 8.7% 2008-06-12
CVE-2005-3523 EXP Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (direction) field. Patch early 7.5 high 8.7% 2005-11-07
CVE-2002-0316 EXP Cross-site scripting vulnerability in eXtreme message board (XMB) 1.6x and earlier allows remote attackers to execute script as other XMB users by ins… Patch early 7.5 high 8.7% 2002-06-25
CVE-2009-1963 EXP Unspecified vulnerability in the Network Foundation component in Oracle Database 11.1.0.6 allows remote authenticated users to affect integrity and av… Patch early 7.5 high 8.7% 2009-07-14
CVE-2018-11505 EXP The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output. Patch early 7.5 high 8.7% 2018-05-26
CVE-2013-2680 EXP Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive information. Patch early 7.5 high 8.7% 2020-02-05
CVE-1999-0750 EXP Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account. Patch early 5.1 medium 8.7% 1999-09-13
CVE-2001-1199 EXP Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to execute Javascript… Patch early 7.5 high 8.7% 2001-12-17
CVE-2018-10751 EXP A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml p… Patch early 5.3 medium 8.7% 2018-05-29
CVE-2019-15943 EXP vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by creating a… Patch early 8.8 high 8.7% 2019-09-19
CVE-2014-8826 EXP LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypass the Gatekeeper protection me… Patch early 5.0 medium 8.7% 2015-01-30
← previous page 231 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt