peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,105 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

149,034 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-1663 EXP The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy… Patch early 10.0 high 54.1% 2010-05-03
CVE-2006-2379 EXP Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers t… Patch early 9.3 high 54.1% 2006-06-13
CVE-2008-1610 EXP Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service or execute arbitrary code via a… Patch early 7.5 high 53.9% 2008-04-01
CVE-2007-3896 EXP The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attack… Patch early 9.3 high 53.8% 2007-10-11
CVE-2008-0550 EXP Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a c… Patch early 10.0 high 53.8% 2008-02-01
CVE-2016-5676 EXP cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows r… Patch early 7.5 high 53.7% 2016-08-31
CVE-2008-4255 EXP Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0,… Patch early 9.3 high 53.7% 2008-12-10
CVE-2006-3459 EXP Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow context-depe… Patch early 7.5 high 53.7% 2006-08-03
CVE-2017-7310 EXP A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskS… Patch early 7.8 high 53.7% 2017-03-29
CVE-2002-1254 EXP Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other… Patch early 7.5 high 53.5% 2002-12-11
CVE-2021-23017 EXP A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte… Patch early 7.7 high 53.5% 2021-06-01
CVE-2011-0104 EXP Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbi… Patch early 9.3 high 53.4% 2011-04-13
CVE-2005-1978 EXP COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code… Patch early 7.5 high 53.4% 2005-10-12
CVE-2005-2847 EXP img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary commands via shell metacharacters in… Patch early 7.5 high 53.4% 2005-09-08
CVE-2014-9118 EXP The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters… Patch early 8.8 high 53.4% 2017-10-17
CVE-2014-0644 EXP EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external e… Patch early 7.8 high 53.3% 2014-04-17
CVE-2015-7007 EXP Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement for AppleScript execution via u… Patch early 7.5 high 53.3% 2015-10-23
CVE-1999-0502 EXP A Unix account has a default, null, blank, or missing password. Patch early 7.5 high 53.3% 1998-03-01
CVE-2018-4233 EXP An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affe… Patch early 8.8 high 53.3% 2018-06-08
CVE-2009-0043 EXP The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, which a… Patch early 10.0 high 53.3% 2009-01-08
CVE-2008-3922 EXP awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which… Patch early 9.3 high 53.2% 2008-09-04
CVE-2010-0248 EXP Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by… Patch early 8.1 high 53.1% 2010-01-22
CVE-2018-0840 EXP Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Exp… Patch early 7.5 high 53.1% 2018-02-15
CVE-2009-1955 EXP The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in th… Patch early 7.5 high 53% 2009-06-08
CVE-2007-5099 EXP PHP remote file inclusion vulnerability in show.php in David Watters Helplink 0.1.0 allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 53% 2007-09-26
CVE-2023-24078 EXP Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/. Patch early 8.8 high 53% 2023-02-17
CVE-2016-7434 EXP The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query. Patch early 7.5 high 52.9% 2017-01-13
CVE-2021-41381 EXP Payara Micro Community 5.2021.6 and below allows Directory Traversal. Patch early 7.5 high 52.9% 2021-09-23
CVE-2007-5348 EXP Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Offic… Patch early 9.3 high 52.9% 2008-09-11
CVE-2005-3589 EXP Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal crash) via a long USER ftp comma… Patch early 7.8 high 52.9% 2005-11-16
← previous page 66 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt