peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,157 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

399,157 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-0244 EXP SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo a… Patch early 10.0 high 80.3% 2008-01-12
CVE-2004-0230 EXP TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to… Patch early 5.0 medium 80.3% 2004-08-18
CVE-2003-0349 EXP Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Ser… Patch early 7.5 high 80.3% 2003-07-24
CVE-2007-5365 EXP Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based… Patch early 7.2 high 80.3% 2007-10-11
CVE-2014-3829 EXP displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitra… Patch early 10.0 high 80.2% 2014-10-23
CVE-2014-9583 EXP common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other router… Patch early 10.0 high 80.2% 2015-01-08
CVE-2002-1359 EXP Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service… Patch early 10.0 high 80.2% 2002-12-23
CVE-2015-7387 EXP ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL com… Patch early 7.5 high 80.2% 2015-09-28
CVE-2009-1386 EXP ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS Chan… Patch early 5.0 medium 80.1% 2009-06-04
CVE-2019-0567 EXP A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scri… Patch early 7.5 high 80.1% 2019-01-08
CVE-2004-0790 EXP Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages,… Patch early 5.0 medium 80.1% 2005-04-12
CVE-2018-12465 EXP An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authe… Patch early 9.1 critical 80% 2018-06-29
CVE-2013-5743 EXP Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7. Patch early 9.8 critical 80% 2019-12-11
CVE-2000-0246 EXP IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to… Patch early 5.0 medium 80% 2000-03-30
CVE-2019-11600 EXP A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id… Patch early 8.1 high 80% 2019-05-13
CVE-2016-0491 EXP Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows rem… Patch early 6.4 medium 79.9% 2016-01-21
CVE-2019-4279 EXP IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence o… Patch early 9.8 critical 79.9% 2019-05-17
CVE-2013-6829 EXP admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacharacters in the pinghost parame… Patch early 7.5 high 79.9% 2013-11-20
CVE-2021-42362 EXP The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src… Patch early 8.8 high 79.8% 2021-11-17
CVE-2017-12557 EXP A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found. Patch early 9.8 critical 79.8% 2018-02-15
CVE-2004-1080 EXP The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbit… Patch early 10.0 high 79.8% 2005-01-10
CVE-2006-4777 EXP Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, o… Patch early 7.6 high 79.8% 2006-09-14
CVE-2012-1495 EXP install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter. Patch early 9.8 critical 79.8% 2020-01-27
CVE-2014-7866 EXP Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0… Patch early 7.5 high 79.8% 2014-12-10
CVE-2016-6563 EXP Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulnera… Patch early 9.8 critical 79.7% 2018-07-13
CVE-2011-4858 EXP Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trig… Patch early 5.0 medium 79.7% 2012-01-05
CVE-2016-2555 EXP SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the sea… Patch early 9.8 critical 79.6% 2017-04-13
CVE-2006-5614 EXP Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to caus… Patch early 2.6 low 79.6% 2006-10-31
CVE-2006-5143 EXP Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r11; BrightS… Patch early 7.5 high 79.5% 2006-10-10
CVE-2018-10662 EXP An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface. Patch early 9.8 critical 79.5% 2018-06-26
← previous page 73 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt