peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,573 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-8722 EXP GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/<… Patch early 7.5 high 14.4% 2017-03-17
CVE-2014-8877 EXP The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress… Patch early 10.0 high 14.4% 2014-12-05
CVE-2010-5323 EXP Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3… Patch early 10.0 high 14.4% 2015-06-07
CVE-2000-0929 EXP Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not cl… Patch early 5.0 medium 14.4% 2000-12-19
CVE-2015-2825 EXP Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPress allows remote attackers to e… Patch early 7.5 high 14.4% 2015-04-21
CVE-2019-13597 EXP _s_/sprm/_s_/dyn/Player_setScriptFile in Sahi Pro 8.0.0 allows command execution. It allows one to run ".sah" scripts via Sahi Launcher. Also, one can… Patch early 9.8 critical 14.3% 2019-07-14
CVE-2007-4567 EXP The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, wh… Patch early 7.8 high 14.3% 2007-12-21
CVE-2018-11742 EXP NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI. Patch early 9.8 critical 14.3% 2018-12-26
CVE-2019-9648 EXP An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command alon… Patch early 5.3 medium 14.3% 2019-03-22
CVE-2011-1071 EXP The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause… Patch early 5.1 medium 14.3% 2011-04-08
CVE-2017-6880 EXP Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other… Patch early 9.8 critical 14.3% 2017-03-17
CVE-2003-0896 EXP The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote… Patch early 7.5 high 14.3% 2003-11-17
CVE-2021-45901 EXP The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists… Patch early 5.3 medium 14.3% 2022-02-10
CVE-2019-15637 EXP Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This… Patch early 8.1 high 14.3% 2019-08-26
CVE-2004-2167 EXP Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary code via (1) the expandmacro f… Patch early 7.5 high 14.3% 2004-12-31
CVE-2002-0976 EXP Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xm… Patch early 6.4 medium 14.3% 2002-09-24
CVE-2011-0917 EXP Buffer overflow in nLDAP.exe in IBM Lotus Domino allows remote attackers to execute arbitrary code via a long string in an LDAP Bind operation, aka SP… Patch early 10.0 high 14.3% 2011-02-08
CVE-2022-29593 EXP relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post requests without the need for authen… Patch early 5.9 medium 14.3% 2022-07-14
CVE-2014-4158 EXP Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a GET request. Patch early 7.5 high 14.3% 2014-06-13
CVE-2015-7246 EXP D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account,… Patch early 9.8 critical 14.3% 2017-04-24
CVE-2012-1502 EXP Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (applicatio… Patch early 7.5 high 14.3% 2012-06-16
CVE-2001-0324 EXP Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP socket… Patch early 2.6 low 14.3% 2001-05-03
CVE-2000-1029 EXP Buffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR query. Patch early 10.0 high 14.3% 2000-12-11
CVE-2008-5220 EXP Unrestricted file upload vulnerability in admin/upload_form.php in wPortfolio 0.3 and earlier allows remote attackers to execute arbitrary code by upl… Patch early 10.0 high 14.3% 2008-11-25
CVE-2015-3112 EXP Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allow attackers to execute arbitrary code or cause a denial of service (… Patch early 10.0 high 14.3% 2015-06-24
CVE-2003-0562 EXP Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long… Patch early 5.0 medium 14.3% 2003-08-27
CVE-2010-2168 EXP Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with… Patch early 9.3 high 14.3% 2010-06-30
CVE-2010-2201 EXP Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with… Patch early 9.3 high 14.3% 2010-06-30
CVE-2000-0699 EXP Format string vulnerability in ftpd in HP-UX 10.20 allows remote attackers to cause a denial of service or execute arbitrary commands via format strin… Patch early 10.0 high 14.3% 2000-10-20
CVE-2006-1905 EXP Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifi… Patch early 7.5 high 14.3% 2006-04-20
← previous page 171 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt