peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,486 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

318,497 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-2280 EXP Stack-based buffer overflow in OmniInet.exe (aka the backup client service daemon) in the Application Recovery Manager component in HP OpenView Storag… Patch early 10.0 high 60.3% 2009-12-18
CVE-2015-8399 EXP Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdef… Patch early 4.3 medium 60.2% 2016-04-11
CVE-2010-2333 EXP LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a… Patch early 5.0 medium 60.2% 2010-06-18
CVE-2011-0257 EXP Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application cra… Patch early 9.3 high 60.1% 2011-08-15
CVE-2007-4744 EXP PHP remote file inclusion vulnerability in environment.php in AnyInventory 1.9.1 and 2.0, when register_globals is enabled, allows remote attackers to… Patch early 6.8 medium 60.1% 2007-09-06
CVE-2005-0595 EXP Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand parameter. Patch early 7.5 high 60.1% 2005-05-02
CVE-2013-0810 EXP Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, and Windows Server 2008 SP2 allow remote attackers to execute arbitrary… Patch early 8.1 high 59.9% 2013-09-11
CVE-2024-31621 EXP An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component. Patch early 7.6 high 59.9% 2024-04-29
CVE-2014-100002 EXP Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot… Patch early 5.0 medium 59.9% 2015-01-13
CVE-2013-3763 EXP Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to aff… Patch early 5.5 medium 59.8% 2013-07-17
CVE-2005-0053 EXP Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability." Patch early 7.5 high 59.8% 2005-05-02
CVE-2007-6019 EXP Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified… Patch early 9.3 high 59.8% 2008-04-09
CVE-2021-46417 EXP Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems… Patch early 7.5 high 59.8% 2022-04-07
CVE-2011-4404 EXP The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Up… Patch early 5.0 medium 59.7% 2011-11-19
CVE-2011-2595 EXP Multiple stack-based buffer overflows in ACDSee FotoSlate 4.0 Build 146 allow remote attackers to execute arbitrary code via a long id parameter in a… Patch early 10.0 high 59.7% 2011-09-14
CVE-2008-5159 EXP Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote attackers to… Patch early 10.0 high 59.7% 2008-11-18
CVE-2017-11840 EXP ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to g… Patch early 7.5 high 59.6% 2017-11-15
CVE-2017-11841 EXP ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to g… Patch early 7.5 high 59.6% 2017-11-15
CVE-2017-11870 EXP ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the same user rights as the curren… Patch early 7.5 high 59.6% 2017-11-15
CVE-2014-8424 EXP ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication. Patch early 7.8 high 59.6% 2014-11-28
CVE-2021-33393 EXP lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It might be owned by an unprivil… Patch early 8.8 high 59.6% 2021-06-09
CVE-2011-4317 EXP The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch i… Patch early 4.3 medium 59.6% 2011-11-30
CVE-2012-4333 EXP Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls in Samsung N… Patch early 10.0 high 59.6% 2012-08-14
CVE-2013-5880 EXP Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.0, 12.2.1, and 12.2.2 allows r… Patch early 5.0 medium 59.6% 2014-01-15
CVE-2013-7108 EXP Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote au… Patch early 5.5 medium 59.5% 2014-01-15
CVE-2005-0768 EXP Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions before 5.0.7, allows remote attacke… Patch early 10.0 high 59.5% 2005-05-02
CVE-2013-5795 EXP Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 1… Patch early 5.0 medium 59.5% 2014-01-15
CVE-2007-3813 EXP PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitrary PHP c… Patch early 4.3 medium 59.4% 2007-07-17
CVE-2022-47075 EXP An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to Expo… Patch early 7.5 high 59.4% 2023-02-28
CVE-2017-16249 EXP The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to ha… Patch early 7.5 high 59.4% 2017-11-10
← previous page 74 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt