peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,359 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2011-1956 EXP The bytes_repr_len function in Wireshark 1.4.5 uses an incorrect pointer argument, which allows remote attackers to cause a denial of service (NULL po… Patch early 4.3 medium 5.9% 2011-06-06
CVE-2007-1690 EXP Multiple stack-based buffer overflows in Second Sight Software ActiveGS ActiveX control (ActiveGS.ocx) allow remote attackers to execute arbitrary cod… Patch early 6.8 medium 5.9% 2007-04-19
CVE-2007-1691 EXP Stack-based buffer overflow in Second Sight Software ActiveMod ActiveX control (ActiveMod.ocx) allows remote attackers to execute arbitrary code via u… Patch early 6.8 medium 5.9% 2007-04-19
CVE-2008-7216 EXP Peter's Math Anti-Spam Spinoff plugin for WordPress generates audio CAPTCHA clips by concatenating static audio files without any additional distortio… Patch early 4.3 medium 5.8% 2009-09-11
CVE-2012-5470 EXP libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted PNG file. Patch early 4.3 medium 5.8% 2012-10-26
CVE-2006-1584 EXP Unspecified vulnerability in index.php in Warcraft III Replay Parser for PHP 1.8c allows remote attackers to inject arbitrary web script or HTML via t… Patch early 6.4 medium 5.8% 2006-04-02
CVE-1999-0215 EXP Routed allows attackers to append data to files. Patch early 6.4 medium 5.8% 1998-10-26
CVE-2014-3439 EXP ConsoleServlet in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to write to arbitrary files via unspecified vect… Patch early 6.1 medium 5.8% 2014-11-07
CVE-2005-3189 EXP Directory traversal vulnerability in Qualcomm WorldMail IMAP Server allows remote attackers to read arbitrary email messages via ".." sequences in the… Patch early 5.0 medium 5.8% 2005-11-18
CVE-2015-3898 EXP Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arbitrary web sites and conduct p… Patch early 6.1 medium 5.8% 2018-02-28
CVE-2003-1521 EXP Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache… Patch early 6.4 medium 5.8% 2003-12-31
CVE-2000-0054 EXP search.cgi in the SolutionScripts Home Free package allows remote attackers to view directories via a .. (dot dot) attack. Patch early 5.0 medium 5.8% 1999-01-03
CVE-2002-0874 EXP Vulnerability in Interchange 4.8.6, 4.8.3, and other versions, when running in INET mode, allows remote attackers to read arbitrary files. Patch early 5.0 medium 5.8% 2002-09-05
CVE-2008-0240 EXP /idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web… Patch early 4.3 medium 5.8% 2008-01-11
CVE-2005-1105 EXP Directory traversal vulnerability in the MimeBodyPart.getFileName method in JavaMail 1.3.2 allows remote attackers to write arbitrary files via a .. (… Patch early 5.0 medium 5.8% 2005-05-02
CVE-2010-1944 EXP Multiple PHP remote file inclusion vulnerabilities in openMairie openCimetiere 2.01, when register_globals is enabled, allow remote attackers to execu… Patch early 6.8 medium 5.8% 2010-05-19
CVE-2010-1946 EXP Multiple PHP remote file inclusion vulnerabilities in openMairie Openregistrecil 1.02, when register_globals is enabled, allow remote attackers to exe… Patch early 6.8 medium 5.8% 2010-05-19
CVE-2021-42565 EXP myfactory.FMS before 7.1-912 allows XSS via the UID parameter. Patch early 6.1 medium 5.8% 2021-10-18
CVE-2021-42566 EXP myfactory.FMS before 7.1-912 allows XSS via the Error parameter. Patch early 6.1 medium 5.8% 2021-10-18
CVE-2006-4000 EXP Directory traversal vulnerability in cgi-bin/preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote authentica… Patch early 4.0 medium 5.8% 2006-08-05
CVE-2007-4507 EXP Multiple buffer overflows in the php_ntuser component for PHP 5.2.3 allow context-dependent attackers to cause a denial of service or execute arbitrar… Patch early 6.8 medium 5.8% 2007-08-23
CVE-1999-0844 EXP Denial of service in MDaemon WorldClient and WebConfig services via a long URL. Patch early 5.0 medium 5.8% 1999-11-24
CVE-2010-4480 EXP error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a cr… Patch early 4.3 medium 5.8% 2010-12-08
CVE-2014-2341 EXP Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter. Patch early 6.8 medium 5.8% 2014-04-22
CVE-2018-10832 EXP ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files,… Patch early 5.5 medium 5.8% 2018-05-11
CVE-2009-2108 EXP git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request contain… Patch early 5.0 medium 5.8% 2009-06-18
CVE-2019-10887 EXP A reflected HTML injection vulnerability on Salicru SLC-20-cube3(5) devices running firmware version cs121-SNMP v4.54.82.130611 allows remote attacker… Patch early 6.1 medium 5.8% 2019-04-05
CVE-2006-3750 EXP PHP remote file inclusion vulnerability in server.php in the Hashcash Component (com_hashcash) 1.2.1 for Joomla! allows remote attackers to execute ar… Patch early 6.8 medium 5.8% 2006-07-21
CVE-2006-4195 EXP PHP remote file inclusion vulnerability in param.peoplebook.php in the Peoplebook Component for Mambo (com_peoplebook) 1.0 and earlier, and possibly 1… Patch early 6.8 medium 5.8% 2006-08-17
CVE-2006-4288 EXP PHP remote file inclusion vulnerability in admin.a6mambocredits.php in the a6mambocredits component (com_a6mambocredits) 2.0.0 and earlier for Mambo a… Patch early 6.8 medium 5.8% 2006-08-22
← previous page 100 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt