peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,157 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

149,067 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-2268 EXP Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL. Patch early 9.4 high 51.7% 2002-12-31
CVE-2010-0557 EXP IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging har… Patch early 7.5 high 51.7% 2010-02-05
CVE-2022-28171 EXP The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validati… Patch early 7.5 high 51.6% 2022-06-27
CVE-2009-0714 EXP Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before bu… Patch early 7.2 high 51.6% 2009-05-14
CVE-2009-1534 EXP Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3,… Patch early 9.3 high 51.6% 2009-08-12
CVE-2017-8731 EXP Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, d… Patch early 7.5 high 51.6% 2017-09-13
CVE-2017-8496 EXP Microsoft Edge in Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user when Microso… Patch early 7.5 high 51.5% 2017-06-15
CVE-2018-1418 EXP IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824. Patch early 8.8 high 51.4% 2018-04-26
CVE-2017-13772 EXP Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary cod… Patch early 8.8 high 51.4% 2017-10-23
CVE-2013-0753 EXP Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer component in Mozilla Firefox before 18.0, Firefox ESR 10.x b… Patch early 9.3 high 51.3% 2013-01-13
CVE-2022-0557 EXP OS Command Injection in Packagist microweber/microweber prior to 1.2.11. Patch early 7.2 high 51.2% 2022-02-11
CVE-2005-2733 EXP upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to e… Patch early 7.5 high 51.2% 2005-08-30
CVE-2016-0956 EXP The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sens… Patch early 7.5 high 51.2% 2016-02-10
CVE-2002-0013 EXP Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain p… Patch early 10.0 high 51.1% 2002-02-13
CVE-2017-1000083 EXP backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via… Patch early 7.8 high 51.1% 2017-09-05
CVE-2010-0033 EXP Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint documen… Patch early 9.3 high 51.1% 2010-02-10
CVE-2016-0199 EXP Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch early 8.8 high 51% 2016-06-16
CVE-2018-8552 EXP An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with inf… Patch early 7.5 high 51% 2018-11-14
CVE-2014-0282 EXP Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch early 9.3 high 50.9% 2014-06-11
CVE-2008-0111 EXP Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office 2004 for Mac allows user-assisted remo… Patch early 9.3 high 50.9% 2008-03-11
CVE-2018-8133 EXP A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scri… Patch early 7.5 high 50.9% 2018-05-09
CVE-2010-2309 EXP Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary code via a long GET request. Patch early 7.5 high 50.8% 2010-06-16
CVE-2001-0167 EXP Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long… Patch early 7.6 high 50.8% 2001-05-03
CVE-2020-15050 EXP An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary files from the server via Direct… Patch early 7.5 high 50.7% 2020-07-13
CVE-2015-5131 EXP Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR S… Patch early 10.0 high 50.7% 2015-08-14
CVE-2015-5132 EXP Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR S… Patch early 10.0 high 50.7% 2015-08-14
CVE-2015-5133 EXP Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR S… Patch early 10.0 high 50.7% 2015-08-14
CVE-2006-1551 EXP Eval injection vulnerability in pajax_call_dispatcher.php in PAJAX 0.5.1 and earlier allows remote attackers to execute arbitrary code via the (1) $me… Patch early 7.5 high 50.6% 2006-04-13
CVE-2014-7146 EXP The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field or… Patch early 7.5 high 50.6% 2014-11-18
CVE-2007-1567 EXP Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary co… Patch early 10.0 high 50.5% 2007-03-21
← previous page 68 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt