peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,831 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

148,982 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-8467 EXP A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scri… Patch early 7.5 high 69% 2018-09-13
CVE-2018-8466 EXP A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scri… Patch early 7.5 high 69% 2018-09-13
CVE-2018-8288 EXP A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Me… Patch early 7.5 high 69% 2018-07-11
CVE-2018-8291 EXP A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Me… Patch early 7.5 high 69% 2018-07-11
CVE-2005-0043 EXP Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files. Patch early 7.5 high 69% 2005-05-02
CVE-2008-1661 EXP Stack-based buffer overflow in DoubleTake.exe in HP StorageWorks Storage Mirroring (SWSM) before 4.5 SP2 allows remote attackers to execute arbitrary… Patch early 10.0 high 69% 2008-06-04
CVE-2001-0506 EXP Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long fil… Patch early 7.2 high 68.9% 2001-09-20
CVE-2013-2367 EXP Multiple unspecified vulnerabilities in HP SiteScope 11.20 and 11.21, when SOAP is used, allow remote attackers to execute arbitrary code via unknown… Patch early 10.0 high 68.9% 2013-07-31
CVE-2009-0695 EXP hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access… Patch early 7.5 high 68.9% 2012-06-19
CVE-2016-7287 EXP The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of servi… Patch early 7.5 high 68.9% 2016-12-20
CVE-2016-7286 EXP The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafte… Patch early 7.5 high 68.9% 2016-12-20
CVE-2019-10867 EXP An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will m… Patch early 8.8 high 68.9% 2019-04-04
CVE-2003-0050 EXP parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary… Patch early 7.5 high 68.9% 2003-03-07
CVE-2005-0308 EXP Buffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code via a large import or export fu… Patch early 7.5 high 68.9% 2005-01-24
CVE-2007-0785 EXP PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote attackers to execute arbitrary… Patch early 7.5 high 68.8% 2007-02-06
CVE-2008-0960 EXP SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Ses… Patch early 10.0 high 68.8% 2008-06-10
CVE-2014-6039 EXP ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000. Patch early 7.5 high 68.8% 2020-01-13
CVE-2006-1255 EXP Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause a denial of service (applicat… Patch early 10.0 high 68.8% 2006-03-19
CVE-2007-2545 EXP Multiple PHP remote file inclusion vulnerabilities in Persism CMS 0.9.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 68.8% 2007-05-09
CVE-2000-0886 EXP IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating sys… Patch early 7.5 high 68.7% 2000-12-19
CVE-2017-8670 EXP Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current… Patch early 7.5 high 68.7% 2017-08-08
CVE-2012-5687 EXP Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and… Patch early 7.8 high 68.7% 2012-11-01
CVE-2004-0567 EXP The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows S… Patch early 7.5 high 68.7% 2004-12-31
CVE-2009-2990 EXP Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitr… Patch early 9.3 high 68.7% 2009-10-19
CVE-2015-7611 EXP Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified ve… Patch early 8.1 high 68.6% 2016-06-07
CVE-2009-2227 EXP Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrary code via a crafted request t… Patch early 10.0 high 68.6% 2009-06-26
CVE-2019-9053 EXP An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-ba… Patch early 8.1 high 68.6% 2019-03-26
CVE-2020-13951 EXP Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack. Patch early 7.5 high 68.6% 2020-09-30
CVE-2018-11646 EXP webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKit, as use… Patch early 7.5 high 68.6% 2018-06-01
CVE-2005-0684 EXP Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET reque… Patch early 10.0 high 68.5% 2005-04-25
← previous page 50 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt