peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,941 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-02

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2013-2182 EXP The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a crafted URI, as d… Patch early 5.8 medium 5.6% 2014-06-13
CVE-2007-1280 EXP Cross-site scripting (XSS) vulnerability in Adobe RoboHelp X5, 6, and Server 6 allows remote attackers to inject arbitrary web script or HTML via a UR… Patch early 4.3 medium 5.6% 2007-05-10
CVE-2007-4734 EXP Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a long file path in an m3u file. Patch early 4.3 medium 5.6% 2007-09-06
CVE-2018-5756 EXP The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev2… Patch early 4.3 medium 5.6% 2018-06-16
CVE-2006-6062 EXP Unspecified vulnerability in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a ma… Patch early 5.1 medium 5.6% 2006-11-22
CVE-2016-6186 EXP Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.j… Patch early 6.1 medium 5.6% 2016-08-05
CVE-2005-3955 EXP Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, al… Patch early 4.3 medium 5.6% 2005-12-01
CVE-2007-4850 EXP curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir rest… Patch early 5.0 medium 5.6% 2008-01-25
CVE-2006-5045 EXP Unspecified vulnerability in PollXT component (com_pollxt) 1.22.07 and earlier for Joomla! has unspecified impact and attack vectors, probably related… Patch early 6.8 medium 5.6% 2006-09-27
CVE-2011-3483 EXP Wireshark 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (application crash) via a malformed capture file that leads to an in… Patch early 4.3 medium 5.6% 2011-09-20
CVE-2008-1410 EXP Directory traversal vulnerability in the PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to read arbitra… Patch early 4.3 medium 5.6% 2008-03-20
CVE-2003-1165 EXP Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via… Patch early 5.0 medium 5.6% 2003-12-31
CVE-2005-1086 EXP Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long Us… Patch early 6.4 medium 5.6% 2005-05-02
CVE-2005-1162 EXP Multiple cross-site scripting (XSS) vulnerabilities in OneWorldStore allow remote attackers to inject arbitrary web script or HTML via the (1) sEmail… Patch early 5.8 medium 5.6% 2005-05-02
CVE-2009-1312 EXP Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to… Patch early 4.3 medium 5.6% 2009-04-22
CVE-2009-2379 EXP Directory traversal vulnerability in public/index.php in BIGACE Web CMS 2.6 allows remote attackers to include and execute arbitrary local files via a… Patch early 6.8 medium 5.6% 2009-07-08
CVE-2010-4399 EXP Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote attackers to rea… Patch early 4.3 medium 5.6% 2010-12-06
CVE-2019-7400 EXP Rukovoditel before 2.4.1 allows XSS. Patch early 6.1 medium 5.6% 2019-02-05
CVE-2020-15716 EXP RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script. A remote attacker could exp… Patch early 6.1 medium 5.6% 2020-07-15
CVE-2007-4725 EXP Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assist… Patch early 6.8 medium 5.6% 2007-09-05
CVE-2009-0251 EXP Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into… Patch early 6.5 medium 5.6% 2009-01-22
CVE-2013-4034 EXP IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1… Patch early 4.0 medium 5.6% 2013-11-18
CVE-2005-2041 EXP Buffer overflow in addschup in HAURI ViRobot 2.0, and possibly other products, allows remote attackers to execute arbitrary code via a long ViRobot_ID… Patch early 5.0 medium 5.5% 2005-06-15
CVE-2014-5094 EXP Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.php, which calls the phpinfo fu… Patch early 5.0 medium 5.5% 2014-10-20
CVE-2017-0167 EXP An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016 when the Wi… Patch early 5.5 medium 5.5% 2017-04-12
CVE-2007-6648 EXP Directory traversal vulnerability in index.php in SanyBee Gallery 0.1.0 and 0.1.1 allows remote attackers to include and execute arbitrary local files… Patch early 5.0 medium 5.5% 2008-01-04
CVE-2015-7249 EXP ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access restrictions via a modified req… Patch early 4.9 medium 5.5% 2015-12-30
CVE-2007-4010 EXP The win32std extension in PHP 5.2.3 does not follow safe_mode and disable_functions restrictions, which allows remote attackers to execute arbitrary c… Patch early 6.8 medium 5.5% 2007-07-26
CVE-2006-5301 EXP PHP remote file inclusion vulnerability in includes/antispam.php in the SpamBlockerMODv 1.0.2 and earlier module for phpBB allows remote attackers to… Patch early 6.8 medium 5.5% 2006-10-17
CVE-2007-1263 EXP GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP… Patch early 5.0 medium 5.5% 2007-03-06
← previous page 104 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt