peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,646 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

318,578 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-8552 EXP An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with inf… Patch early 7.5 high 51% 2018-11-14
CVE-2000-0869 EXP The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPF… Patch early 5.0 medium 51% 2000-11-14
CVE-2014-0282 EXP Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch early 9.3 high 50.9% 2014-06-11
CVE-2008-0111 EXP Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office 2004 for Mac allows user-assisted remo… Patch early 9.3 high 50.9% 2008-03-11
CVE-2018-8133 EXP A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scri… Patch early 7.5 high 50.9% 2018-05-09
CVE-2010-2309 EXP Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary code via a long GET request. Patch early 7.5 high 50.8% 2010-06-16
CVE-2017-3548 EXP Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions… Patch early 6.5 medium 50.8% 2017-04-24
CVE-2001-0167 EXP Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long… Patch early 7.6 high 50.8% 2001-05-03
CVE-2015-8256 EXP Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras. Patch early 6.1 medium 50.8% 2017-04-17
CVE-2020-15050 EXP An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary files from the server via Direct… Patch early 7.5 high 50.7% 2020-07-13
CVE-2015-5131 EXP Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR S… Patch early 10.0 high 50.7% 2015-08-14
CVE-2015-5132 EXP Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR S… Patch early 10.0 high 50.7% 2015-08-14
CVE-2015-5133 EXP Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR S… Patch early 10.0 high 50.7% 2015-08-14
CVE-2007-4336 EXP Buffer overflow in the Live Picture Corporation DXSurface.LivePicture.FlashPix.1 (DirectTransform FlashPix) ActiveX control in DXTLIPI.DLL 6.0.2.827,… Patch early 4.3 medium 50.7% 2007-08-14
CVE-2008-1562 EXP The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via… Patch early 5.0 medium 50.7% 2008-03-31
CVE-2004-0120 EXP The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a den… Patch early 5.0 medium 50.7% 2004-06-01
CVE-2006-1551 EXP Eval injection vulnerability in pajax_call_dispatcher.php in PAJAX 0.5.1 and earlier allows remote attackers to execute arbitrary code via the (1) $me… Patch early 7.5 high 50.6% 2006-04-13
CVE-2010-0904 EXP Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect integrity via unknown vectors. Patch early 5.0 medium 50.6% 2010-07-13
CVE-2005-0553 EXP Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers… Patch early 5.1 medium 50.6% 2005-05-02
CVE-2011-3639 EXP The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not pro… Patch early 4.3 medium 50.6% 2011-11-30
CVE-2014-9308 EXP Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping Cart) plugin b… Patch early 6.5 medium 50.6% 2015-01-15
CVE-2014-7146 EXP The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field or… Patch early 7.5 high 50.6% 2014-11-18
CVE-2007-1567 EXP Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary co… Patch early 10.0 high 50.5% 2007-03-21
CVE-2001-1410 EXP Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createPopup method, which could allow… Patch early 5.0 medium 50.5% 2003-08-18
CVE-2013-1884 EXP The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault… Patch early 5.0 medium 50.5% 2013-05-02
CVE-2009-4655 EXP The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sessions via… Patch early 7.5 high 50.5% 2010-02-26
CVE-2016-3303 EXP The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Vie… Patch early 7.8 high 50.5% 2016-08-09
CVE-2016-3304 EXP The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Vie… Patch early 7.8 high 50.5% 2016-08-09
CVE-2017-0108 EXP The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meetin… Patch early 7.8 high 50.5% 2017-03-17
CVE-2007-6016 EXP Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Serv… Patch early 9.3 high 50.4% 2008-02-29
← previous page 85 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt