peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,003 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

149,017 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-1579 EXP Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSCRIBE command. Patch early 10.0 high 56.2% 2007-03-21
CVE-2007-0046 EXP Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbi… Patch early 7.5 high 55.9% 2007-01-03
CVE-2008-3704 EXP Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Vis… Patch early 9.3 high 55.9% 2008-08-18
CVE-2006-3280 EXP Cross-domain vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to access restricted information from other domains via an objec… Patch early 7.5 high 55.9% 2006-06-28
CVE-2017-8635 EXP Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold… Patch early 7.5 high 55.9% 2017-08-08
CVE-2019-14322 EXP In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames. Patch early 7.5 high 55.8% 2019-07-28
CVE-2011-3494 EXP WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a… Patch early 10.0 high 55.8% 2011-09-16
CVE-2013-0025 EXP Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers a… Patch early 9.3 high 55.8% 2013-02-13
CVE-2005-2124 EXP Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1, related to "An unchec… Patch early 7.6 high 55.7% 2005-11-29
CVE-2013-3307 EXP Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacter… Patch early 8.3 high 55.7% 2025-07-11
CVE-2013-3520 EXP VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via u… Patch early 7.5 high 55.6% 2013-06-17
CVE-2018-0935 EXP Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 G… Patch early 7.5 high 55.6% 2018-03-14
CVE-2010-1423 EXP Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versio… Patch early 9.3 high 55.6% 2010-04-15
CVE-2007-4818 EXP Multiple PHP remote file inclusion vulnerabilities in Txx CMS 0.2 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root param… Patch early 7.5 high 55.5% 2007-09-11
CVE-2023-0159 EXP The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when… Patch early 7.5 high 55.5% 2023-02-13
CVE-2006-1388 EXP Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors. Patch early 7.5 high 55.5% 2006-03-24
CVE-2002-0186 EXP Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a l… Patch early 7.5 high 55.5% 2002-07-03
CVE-2007-2931 EXP Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbit… Patch early 9.3 high 55.5% 2007-08-31
CVE-2005-2551 EXP Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain acces… Patch early 7.5 high 55.4% 2005-08-12
CVE-2014-7228 EXP Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professio… Patch early 7.5 high 55.4% 2014-11-03
CVE-2023-22809 EXP In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISU… Patch early 7.8 high 55.4% 2023-01-18
CVE-2022-24124 EXP The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organiz… Patch early 7.5 high 55.3% 2022-01-29
CVE-2017-3730 EXP In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attem… Patch early 7.5 high 55.3% 2017-05-04
CVE-2010-0266 EXP Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value o… Patch early 9.3 high 55.3% 2010-07-15
CVE-2010-4335 EXP The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the i… Patch early 7.5 high 55.2% 2011-01-14
CVE-2007-6509 EXP Unspecified vulnerability in Appian Enterprise Business Process Management (BPM) Suite 5.6 SP1 allows remote attackers to cause a denial of service vi… Patch early 7.8 high 55.2% 2007-12-21
CVE-2015-2993 EXP SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator acc… Patch early 7.5 high 55.1% 2015-06-08
CVE-2009-1430 EXP Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management System 2 (AMS2), as used in Symant… Patch early 9.3 high 55.1% 2009-04-29
CVE-2018-9205 EXP Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path. Patch early 7.5 high 55.1% 2018-04-04
CVE-2006-4948 EXP Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cau… Patch early 7.5 high 55% 2006-09-23
← previous page 64 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt