peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,672 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

148,940 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-3548 EXP The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for th… Patch early 7.5 high 79% 2009-11-12
CVE-2018-17553 EXP An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 allows authent… Patch early 8.8 high 79% 2018-10-03
CVE-2009-3843 EXP HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduc… Patch early 10.0 high 79% 2009-11-24
CVE-2015-7709 EXP The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execu… Patch early 10.0 high 79% 2015-10-05
CVE-2018-0769 EXP Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the… Patch early 7.5 high 79% 2018-01-04
CVE-2006-4691 EXP Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allo… Patch early 10.0 high 78.9% 2006-11-14
CVE-2017-17692 EXP Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript cod… Patch early 7.5 high 78.8% 2017-12-21
CVE-2013-2730 EXP Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code v… Patch early 10.0 high 78.8% 2013-05-16
CVE-2014-3791 EXP Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code via a long string in a cookie… Patch early 10.0 high 78.7% 2014-05-20
CVE-2012-5088 EXP Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect c… Patch early 10.0 high 78.7% 2012-10-16
CVE-2006-3677 EXP Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the… Patch early 7.5 high 78.7% 2006-07-27
CVE-2000-0917 EXP Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands. Patch early 10.0 high 78.7% 2000-12-19
CVE-2020-5791 EXP Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating sy… Patch early 7.2 high 78.6% 2020-10-20
CVE-2014-7205 EXP Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for N… Patch early 10.0 high 78.6% 2014-10-08
CVE-2013-4786 EXP The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password… Patch early 7.5 high 78.6% 2013-07-08
CVE-2010-2063 EXP Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote… Patch early 7.5 high 78.6% 2010-06-17
CVE-2017-0070 EXP A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft brows… Patch early 7.5 high 78.5% 2017-03-17
CVE-2009-4189 EXP HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code via a sess… Patch early 10.0 high 78.5% 2009-12-03
CVE-2018-0777 EXP Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the… Patch early 7.5 high 78.4% 2018-01-04
CVE-2018-0776 EXP Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the… Patch early 7.5 high 78.4% 2018-01-04
CVE-2018-0770 EXP Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the… Patch early 7.5 high 78.4% 2018-01-04
CVE-2014-5301 EXP Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4. Patch early 8.8 high 78.4% 2017-08-28
CVE-2001-0098 EXP Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." stri… Patch early 10.0 high 78.4% 2001-02-12
CVE-2003-0780 EXP Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to ex… Patch early 9.0 high 78.4% 2003-09-22
CVE-2018-10583 EXP An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB con… Patch early 7.5 high 78.3% 2018-05-01
CVE-2017-17215 EXP Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 3… Patch early 8.8 high 78.3% 2018-03-20
CVE-2020-11108 EXP The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution b… Patch early 8.8 high 78.3% 2020-05-11
CVE-2009-3068 EXP Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute a… Patch early 9.3 high 78.2% 2009-09-04
CVE-2011-3587 EXP Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to exec… Patch early 9.3 high 78.1% 2011-10-10
CVE-2007-2139 EXP Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightS… Patch early 10.0 high 78% 2007-04-25
← previous page 39 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt