peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,534 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

318,513 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-1318 EXP Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11… Patch early 10.0 high 58.1% 2010-04-20
CVE-2012-4177 EXP The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -orbit_exe_path command line ar… Patch early 10.0 high 58% 2012-08-07
CVE-2000-0408 EXP IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions… Patch early 5.0 medium 58% 2000-05-11
CVE-2007-4712 EXP PHP remote file inclusion vulnerability in index.php in eNetman 1 allows remote attackers to execute arbitrary PHP code via a URL in the page paramete… Patch early 7.5 high 57.9% 2007-09-05
CVE-2005-0554 EXP Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and… Patch early 7.5 high 57.9% 2005-05-02
CVE-2016-7194 EXP The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via… Patch early 7.5 high 57.9% 2016-10-14
CVE-2019-10475 EXP A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages… Patch early 6.1 medium 57.7% 2019-10-23
CVE-2014-2850 EXP The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary command… Patch early 8.5 high 57.7% 2014-04-11
CVE-2015-1503 EXP Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot)… Patch early 7.5 high 57.6% 2018-05-08
CVE-2006-1188 EXP Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads… Patch early 7.5 high 57.6% 2006-04-11
CVE-2008-4654 EXP Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows re… Patch early 9.3 high 57.5% 2008-10-22
CVE-2006-5854 EXP Multiple buffer overflows in the Spooler service (nwspool.dll) in Novell Netware Client 4.91 through 4.91 SP2 allow remote attackers to execute arbitr… Patch early 7.5 high 57.5% 2006-12-03
CVE-2014-5377 EXP ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct… Patch early 5.0 medium 57.5% 2014-09-04
CVE-2004-0209 EXP Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attacker… Patch early 10.0 high 57.4% 2004-11-03
CVE-2014-100015 EXP Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write to arbitrary files via a .. (do… Patch early 6.4 medium 57.4% 2015-01-13
CVE-2005-1218 EXP The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of servic… Patch early 5.0 medium 57.3% 2005-08-10
CVE-2017-0089 EXP Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via… Patch early 8.8 high 57.3% 2017-03-17
CVE-2006-3440 EXP Buffer overflow in the Winsock API in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary cod… Patch early 10.0 high 57.3% 2006-08-09
CVE-2006-4364 EXP Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attackers to cause a denial of service… Patch early 5.0 medium 57.3% 2006-08-27
CVE-2010-1899 EXP Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attack… Patch early 4.3 medium 57.2% 2010-09-15
CVE-2016-0100 EXP Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle library loading, which allows local users to gain privileges via a crafted application, aka… Patch early 8.4 high 57.2% 2016-03-09
CVE-2008-0532 EXP Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for… Patch early 10.0 high 57.1% 2008-03-14
CVE-2013-3632 EXP The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands… Patch early 8.8 high 57.1% 2014-09-29
CVE-2011-3497 EXP service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related… Patch early 10.0 high 57.1% 2011-09-16
CVE-2008-1083 EXP Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and S… Patch early 8.1 high 57.1% 2008-04-08
CVE-2019-12276 EXP A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attac… Patch early 7.5 high 57.1% 2019-06-05
CVE-2008-1358 EXP Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary code via a F… Patch early 6.5 medium 57.1% 2008-03-17
CVE-2005-1009 EXP Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a modified computer name and length… Patch early 10.0 high 57% 2005-05-02
CVE-2015-2997 EXP SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getAgentLogFil… Patch early 5.0 medium 57% 2015-06-08
CVE-2022-28080 EXP Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter. Patch early 8.8 high 56.9% 2022-05-05
← previous page 77 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt