peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,955 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-1089 EXP rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers… Patch early 5.0 medium 5.4% 2002-10-04
CVE-2008-3821 EXP Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 11.0 through 12.4 allow remote attackers to inject arbitrary web s… Patch early 4.3 medium 5.4% 2009-01-16
CVE-2007-3844 EXP Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) at… Patch early 4.3 medium 5.4% 2007-08-08
CVE-2011-2641 EXP Opera 11.11 allows remote attackers to cause a denial of service (application crash) by setting the FACE attribute of a FONT element within an IFRAME… Patch early 5.0 medium 5.4% 2011-07-01
CVE-2003-1138 EXP The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexi… Patch early 5.0 medium 5.4% 2003-10-27
CVE-2007-6321 EXP Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versions, when using Internet Explorer, allows remote at… Patch early 4.3 medium 5.4% 2007-12-12
CVE-2007-5914 EXP Direct static code injection vulnerability in dirsys/modules/config/post.php in JBC Explorer 7.20 RC1 and earlier allows remote authenticated administ… Patch early 6.8 medium 5.4% 2007-11-10
CVE-2021-24610 EXP The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' functio… Patch early 4.8 medium 5.4% 2021-09-27
CVE-2015-1059 EXP Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute arbitrary PHP code by uploadi… Patch early 6.5 medium 5.4% 2015-01-16
CVE-2014-8391 EXP The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive information fr… Patch early 4.0 medium 5.4% 2015-06-02
CVE-2013-5573 EXP Cross-site scripting (XSS) vulnerability in the default markup formatter in Jenkins 1.523 allows remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 5.4% 2013-12-31
CVE-2004-2523 EXP Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to exe… Patch early 6.5 medium 5.4% 2004-12-31
CVE-2008-3303 EXP admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication and obtain administrative acces… Patch early 6.8 medium 5.4% 2008-07-25
CVE-2019-14339 EXP The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly restrict canon.ij.printer.capabil… Patch early 5.5 medium 5.4% 2019-09-05
CVE-2006-2465 EXP Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. NOTE: if mp3info is not installed setui… Patch early 5.1 medium 5.4% 2006-05-19
CVE-2011-4880 EXP Directory traversal vulnerability in the web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to read arbitrary file… Patch early 5.0 medium 5.4% 2012-04-13
CVE-2011-4074 EXP Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 5.4% 2011-11-02
CVE-2007-4517 EXP Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remote authenticated users to execute arbitrary code v… Patch early 6.0 medium 5.4% 2007-11-08
CVE-2007-6623 EXP Absolute path traversal vulnerability in ZeusCMS 0.3 and earlier might allow remote attackers to list arbitrary directories via a full pathname in the… Patch early 5.0 medium 5.4% 2008-01-04
CVE-2008-5266 EXP Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Applic… Patch early 4.3 medium 5.4% 2008-11-28
CVE-2002-0886 EXP Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a large… Patch early 5.0 medium 5.4% 2002-10-04
CVE-2022-22836 EXP CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request. Patch early 6.5 medium 5.4% 2022-01-10
CVE-2001-1064 EXP Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the route… Patch early 5.0 medium 5.4% 2001-08-31
CVE-2007-5410 EXP PHP remote file inclusion vulnerability in admin.wmtrssreader.php in the webmaster-tips.net Flash RSS Reader (com_wmtrssreader) 1.0 component for Joom… Patch early 6.8 medium 5.4% 2007-10-12
CVE-2004-2736 EXP Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cookie. Patch early 5.0 medium 5.4% 2004-12-31
CVE-2015-2678 EXP Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 5.4% 2015-03-23
CVE-2000-0278 EXP The SalesLogix Eviewer allows remote attackers to cause a denial of service by accessing the URL for the slxweb.dll administration program, which does… Patch early 5.0 medium 5.4% 2000-08-03
CVE-2009-0162 EXP Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7 and Windows allows remote att… Patch early 4.3 medium 5.4% 2009-05-13
CVE-2000-0212 EXP InterAccess TelnetD Server 4.0 allows remote attackers to conduct a denial of service via malformed terminal client configuration information. Patch early 5.0 medium 5.4% 2000-02-24
CVE-2000-0451 EXP The Intel express 8100 ISDN router allows remote attackers to cause a denial of service via oversized or fragmented ICMP packets. Patch early 5.0 medium 5.4% 2000-05-19
← previous page 106 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt