peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,831 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

318,116 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-4189 EXP HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code via a sess… Patch early 10.0 high 78.5% 2009-12-03
CVE-2018-0770 EXP Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the… Patch early 7.5 high 78.4% 2018-01-04
CVE-2018-0777 EXP Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the… Patch early 7.5 high 78.4% 2018-01-04
CVE-2018-0776 EXP Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the… Patch early 7.5 high 78.4% 2018-01-04
CVE-2014-5301 EXP Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4. Patch early 8.8 high 78.4% 2017-08-28
CVE-2001-0098 EXP Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." stri… Patch early 10.0 high 78.4% 2001-02-12
CVE-2003-0780 EXP Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to ex… Patch early 9.0 high 78.4% 2003-09-22
CVE-2018-10583 EXP An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB con… Patch early 7.5 high 78.3% 2018-05-01
CVE-2006-3392 EXP Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary fi… Patch early 5.0 medium 78.3% 2006-07-06
CVE-2017-17215 EXP Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 3… Patch early 8.8 high 78.3% 2018-03-20
CVE-2020-11108 EXP The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution b… Patch early 8.8 high 78.3% 2020-05-11
CVE-2009-3068 EXP Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute a… Patch early 9.3 high 78.2% 2009-09-04
CVE-2011-3587 EXP Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to exec… Patch early 9.3 high 78.1% 2011-10-10
CVE-2010-1587 EXP The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash s… Patch early 5.0 medium 78% 2010-04-28
CVE-2007-2139 EXP Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightS… Patch early 10.0 high 78% 2007-04-25
CVE-2019-16113 EXP Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PH… Patch early 8.8 high 78% 2019-09-08
CVE-2021-39312 EXP The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed vi… Patch early 7.5 high 77.9% 2021-12-14
CVE-2013-6221 EXP Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoPass license server is enabled,… Patch early 10.0 high 77.9% 2014-06-18
CVE-2004-1561 EXP Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a large number of headers. Patch early 7.5 high 77.9% 2004-12-31
CVE-2014-5005 EXP Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via… Patch early 7.5 high 77.8% 2014-10-21
CVE-2015-2797 EXP Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 5021 DSL modems with firmware 1.0… Patch early 10.0 high 77.8% 2015-06-19
CVE-2019-12840 EXP In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data paramete… Patch early 8.8 high 77.8% 2019-06-15
CVE-2014-0113 EXP CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method,… Patch early 7.5 high 77.8% 2014-04-29
CVE-2022-24734 EXP MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correctl… Patch early 7.2 high 77.8% 2022-03-09
CVE-2017-1000117 EXP A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that e… Patch early 8.8 high 77.8% 2017-10-05
CVE-2010-0842 EXP Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows rem… Patch early 7.5 high 77.7% 2010-04-01
CVE-2008-2639 EXP Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows remote attackers to execute arbit… Patch early 7.6 high 77.7% 2008-06-16
CVE-2002-1123 EXP Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execu… Patch early 7.5 high 77.7% 2002-09-24
CVE-2018-10823 EXP An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DW… Patch early 8.8 high 77.7% 2018-10-17
CVE-2007-1748 EXP Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP… Patch early 10.0 high 77.7% 2007-04-13
← previous page 49 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt