peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,157 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

149,067 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-7146 EXP The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field or… Patch early 7.5 high 50.6% 2014-11-18
CVE-2007-1567 EXP Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary co… Patch early 10.0 high 50.5% 2007-03-21
CVE-2009-4655 EXP The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sessions via… Patch early 7.5 high 50.5% 2010-02-26
CVE-2016-3303 EXP The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Vie… Patch early 7.8 high 50.5% 2016-08-09
CVE-2016-3304 EXP The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Vie… Patch early 7.8 high 50.5% 2016-08-09
CVE-2017-0108 EXP The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meetin… Patch early 7.8 high 50.5% 2017-03-17
CVE-2007-6016 EXP Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Serv… Patch early 9.3 high 50.4% 2008-02-29
CVE-2017-8594 EXP Internet Explorer on Microsoft Windows 8.1 and Windows RT 8.1, and Windows Server 2012 R2 allows an attacker to execute arbitrary code in the context… Patch early 7.5 high 50.4% 2017-07-11
CVE-2017-8751 EXP Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsof… Patch early 7.5 high 50.4% 2017-09-13
CVE-2002-0061 EXP Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe… Patch early 7.5 high 50.4% 2002-03-21
CVE-2015-5127 EXP Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199… Patch early 10.0 high 50.3% 2015-08-14
CVE-2015-5130 EXP Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199… Patch early 10.0 high 50.3% 2015-08-14
CVE-2015-5134 EXP Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199… Patch early 10.0 high 50.3% 2015-08-14
CVE-2022-36633 EXP Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by U… Patch early 8.8 high 50.3% 2022-08-24
CVE-2010-0477 EXP The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remot… Patch early 10.0 high 50.2% 2010-04-14
CVE-2017-14535 EXP trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php. Patch early 8.8 high 50.1% 2018-02-16
CVE-2017-11890 EXP Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703… Patch early 7.5 high 50.1% 2017-12-12
CVE-2017-8538 EXP The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… Patch early 7.8 high 50% 2017-05-26
CVE-2007-2386 EXP Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or… Patch early 9.4 high 50% 2007-05-24
CVE-2003-0309 EXP Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document wi… Patch early 7.5 high 50% 2003-06-09
CVE-2007-2864 EXP Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote a… Patch early 9.3 high 49.9% 2007-06-06
CVE-2005-1219 EXP Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC p… Patch early 7.5 high 49.9% 2005-07-12
CVE-2016-3313 EXP Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary c… Patch early 7.8 high 49.8% 2016-08-09
CVE-2002-1217 EXP Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary co… Patch early 7.5 high 49.8% 2002-10-28
CVE-2017-8682 EXP Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows… Patch early 8.8 high 49.8% 2017-09-13
CVE-2026-23918 EXP Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are… Patch early 8.8 high 49.7% 2026-05-04
CVE-2017-11793 EXP Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows… Patch early 7.5 high 49.6% 2017-10-13
CVE-2006-0006 EXP Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000… Patch early 9.3 high 49.6% 2006-02-14
CVE-2013-3563 EXP Stack-based buffer overflow in db_netserver in Lianja SQL Server before 1.0.0RC5.2 allows remote attackers to cause a denial of service (daemon crash)… Patch early 7.5 high 49.5% 2013-07-04
CVE-2001-0876 EXP Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arbitrary code via a NOTIFY direc… Patch early 7.5 high 49.5% 2001-12-20
← previous page 69 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt