peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,810 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

318,746 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-8544 EXP A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code E… Patch early 8.8 high 47.6% 2018-11-14
CVE-2009-2514 EXP win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of… Patch early 9.3 high 47.5% 2009-11-11
CVE-2021-40875 EXP Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5… Patch early 7.5 high 47.5% 2021-09-22
CVE-2006-4193 EXP Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a denial of service and possibly execute arbitrary co… Patch early 7.5 high 47.5% 2006-08-17
CVE-2005-0688 EXP Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP pac… Patch early 5.0 medium 47.4% 2005-03-05
CVE-2017-11155 EXP An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensitiv… Patch early 7.5 high 47.4% 2017-08-08
CVE-2014-2424 EXP Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote authenticated users to affect… Patch early 4.0 medium 47.4% 2014-04-16
CVE-2014-2299 EXP Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote… Patch early 9.3 high 47.4% 2014-03-11
CVE-2006-5085 EXP Static code injection vulnerability in config.php in Blog Pixel Motion 2.1.1 allows remote attackers to execute arbitrary PHP code via the nom_blog pa… Patch early 7.5 high 47.3% 2006-09-29
CVE-2007-4983 EXP Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic and 7.0.3.3016 allows remote att… Patch early 10.0 high 47.3% 2007-09-19
CVE-2016-3316 EXP Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Offic… Patch early 7.8 high 47.2% 2016-08-09
CVE-2018-15812 EXP DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy. Patch early 7.5 high 47.2% 2019-07-03
CVE-2005-1815 EXP Multiple buffer overflows in Hummingbird Connectivity inetD 10.0.0.1 and 9.0.0.4 allows attackers to cause a denial of service and possibly execute ar… Patch early 5.0 medium 47.2% 2005-06-01
CVE-2014-2962 EXP Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attack… Patch early 7.8 high 47.1% 2014-06-19
CVE-2008-5405 EXP Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier, allows remote attackers to ex… Patch early 9.3 high 47% 2008-12-10
CVE-2004-0214 EXP Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious ser… Patch early 10.0 high 47% 2004-11-03
CVE-2014-9013 EXP The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbi… Patch early 8.8 high 46.9% 2019-11-06
CVE-2008-2551 EXP The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution of… Patch early 9.3 high 46.9% 2008-06-04
CVE-2019-15984 EXP Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker… Patch early 7.2 high 46.9% 2020-01-06
CVE-2007-2199 EXP PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Librar… Patch early 6.8 medium 46.9% 2007-04-24
CVE-2018-7719 EXP Acrolinx Server before 5.2.5 on Windows allows Directory Traversal. Patch early 7.5 high 46.9% 2018-03-25
CVE-2012-6274 EXP BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under… Patch early 5.0 medium 46.9% 2013-02-24
CVE-2017-11903 EXP Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 G… Patch early 7.5 high 46.8% 2017-12-12
CVE-2007-5186 EXP PHP remote file inclusion vulnerability in index.php in Segue CMS 1.8.4 and earlier, when register_globals is disabled, allows remote attackers to exe… Patch early 6.8 medium 46.8% 2007-10-03
CVE-2011-0096 EXP The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2,… Patch early 6.1 medium 46.8% 2011-01-31
CVE-2022-29298 EXP SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal. Patch early 7.5 high 46.8% 2022-05-12
CVE-2010-2590 EXP Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Reports 2008 SP… Patch early 9.3 high 46.8% 2010-12-22
CVE-2000-0505 EXP The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of… Patch early 5.0 medium 46.7% 2000-05-31
CVE-2006-5028 EXP Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows allows remote attacker… Patch early 5.0 medium 46.6% 2006-09-27
CVE-2002-0597 EXP LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malformed data t… Patch early 5.0 medium 46.6% 2002-06-18
← previous page 89 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt