peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,133 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-6605 EXP Buffer overflow in a certain ActiveX control in SkyFexClient.ocx 1.0.2.77 in SkyFex Client 1.0 allows remote attackers to execute arbitrary code via l… Patch early 5.8 medium 3.7% 2007-12-31
CVE-2017-8462 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 3.7% 2017-06-15
CVE-2017-8478 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 3.7% 2017-06-15
CVE-2017-8482 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 3.7% 2017-06-15
CVE-2017-8484 EXP Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,… Patch early 5.0 medium 3.7% 2017-06-15
CVE-2017-8488 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 3.7% 2017-06-15
CVE-2017-8492 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 3.7% 2017-06-15
CVE-2014-1836 EXP Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arb… Patch early 6.4 medium 3.7% 2015-07-01
CVE-2015-4631 EXP Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.2… Patch early 5.4 medium 3.7% 2018-10-18
CVE-2004-0072 EXP Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \.. (backslash .., "%5c%2… Patch early 5.0 medium 3.7% 2004-02-17
CVE-2004-1927 EXP Directory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to de… Patch early 5.0 medium 3.7% 2004-04-11
CVE-2007-5699 EXP Stack-based buffer overflow in eIQNetworks Enterprise Security Analyzer (ESA) 2.5 allows remote attackers to execute arbitrary code via certain data o… Patch early 6.8 medium 3.7% 2007-10-29
CVE-2021-44916 EXP Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routin… Patch early 6.1 medium 3.7% 2021-12-20
CVE-2019-9554 EXP In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new U… Patch early 6.1 medium 3.7% 2019-12-31
CVE-2007-0298 EXP PHP remote file inclusion vulnerability in show.php in LunarPoll, when register_globals is enabled, allows remote attackers to execute arbitrary PHP c… Patch early 6.8 medium 3.7% 2007-01-17
CVE-2007-6752 EXP Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for… Patch early 6.8 medium 3.7% 2012-03-28
CVE-2013-2684 EXP Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecifie… Patch early 6.1 medium 3.7% 2020-02-06
CVE-2006-2410 EXP raydium_network_netcall_exec function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to cause a denial of service (appli… Patch early 5.0 medium 3.7% 2006-05-16
CVE-2006-2412 EXP The raydium_network_read function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to cause a denial of service (applicati… Patch early 5.0 medium 3.7% 2006-05-16
CVE-2007-1149 EXP Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the step paramete… Patch early 5.0 medium 3.7% 2007-03-02
CVE-2018-20418 EXP index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab. Patch early 4.8 medium 3.7% 2018-12-24
CVE-2005-1480 EXP Directory traversal vulnerability in RaidenFTPD before 2.4.2241 allows remote attackers to read arbitrary files via a "..\\" (dot dot backslash) in th… Patch early 5.0 medium 3.7% 2005-05-11
CVE-2019-6209 EXP An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixe… Patch early 5.5 medium 3.7% 2019-03-05
CVE-2005-2479 EXP Quick 'n Easy FTP Server 3.0 allows remote attackers to cause a denial of service (application crash or CPU consumption) via a long USER command. Patch early 5.0 medium 3.7% 2005-08-05
CVE-2009-1067 EXP Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web script or HTML via the x para… Patch early 4.3 medium 3.7% 2009-03-26
CVE-2011-2841 EXP Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, which allows remote attackers t… Patch early 6.8 medium 3.7% 2011-09-19
CVE-2007-6553 EXP Multiple PHP remote file inclusion vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to execute arbitrary PHP code via a URL i… Patch early 6.8 medium 3.7% 2007-12-28
CVE-2015-2275 EXP Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 3.7% 2015-03-12
CVE-2003-0749 EXP Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbi… Patch early 6.8 medium 3.7% 2003-10-20
CVE-2012-2917 EXP Cross-site scripting (XSS) vulnerability in the Share and Follow plugin 1.80.3 for WordPress allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 3.7% 2012-05-21
← previous page 143 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt