peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,573 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-42165 EXP MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &… Patch early 8.8 high 14.1% 2022-05-03
CVE-2016-9838 EXP An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored… Patch early 7.5 high 14.1% 2016-12-16
CVE-2003-1228 EXP Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions, allows remote attackers to c… Patch early 7.5 high 14.1% 2003-12-31
CVE-2017-0211 EXP An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Se… Patch early 5.5 medium 14.1% 2017-04-12
CVE-2023-32749 EXP Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when crea… Patch early 8.8 high 14.1% 2023-06-08
CVE-2008-3655 EXP Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to critical variab… Patch early 7.5 high 14.1% 2008-08-13
CVE-2018-6409 EXP An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the… Patch early 5.3 medium 14.1% 2018-05-26
CVE-2019-6445 EXP An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can cause a NULL pointer dereference and ntpd crash in ntp_control.c, relate… Patch early 6.5 medium 14.1% 2019-01-16
CVE-2007-6731 EXP Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses… Patch early 10.0 high 14.1% 2009-09-13
CVE-2015-9098 EXP In Redgate SQL Monitor before 3.10 and 4.x before 4.2, a remote attacker can gain unauthenticated access to the Base Monitor, resulting in the ability… Patch early 9.8 critical 14.1% 2017-06-22
CVE-2015-2099 EXP Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vectors to the (1) GetRecFileInfo… Patch early 8.8 high 14.1% 2021-07-22
CVE-2004-2501 EXP Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute arbitrary c… Patch early 7.5 high 14.1% 2004-12-31
CVE-2022-22832 EXP An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request. Patch early 9.8 critical 14.1% 2022-02-06
CVE-2018-0710 EXP Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrar… Patch early 8.8 high 14.1% 2018-07-17
CVE-2008-6668 EXP Multiple directory traversal vulnerabilities in nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1… Patch early 5.0 medium 14% 2009-04-08
CVE-2010-0944 EXP Directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to read arbitrary files via a ..… Patch early 5.0 medium 14% 2010-03-08
CVE-2010-1304 EXP Directory traversal vulnerability in userstatus.php in the User Status (com_userstatus) component 1.21.16 for Joomla! allows remote attackers to read… Patch early 5.0 medium 14% 2010-04-08
CVE-2015-2068 EXP Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to injec… Patch early 4.3 medium 14% 2015-02-24
CVE-2010-3132 EXP Untrusted search path vulnerability in Adobe Dreamweaver CS5 11.0 build 4916, build 4909, and probably other versions, allows local users, and possibl… Patch early 9.3 high 14% 2010-08-26
CVE-2010-2891 EXP Buffer overflow in the smiGetNode function in lib/smi.c in libsmi 0.4.8 allows context-dependent attackers to execute arbitrary code via an Object Ide… Patch early 7.5 high 14% 2010-10-28
CVE-2018-4404 EXP In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improved memory handling. Patch early 8.8 high 14% 2019-01-11
CVE-2015-2094 EXP Stack-based buffer overflow in the WESPPlayback.WESPPlaybackCtrl.1 control in WebGate WinRDS allows remote attackers to execute arbitrary code via uns… Patch early 7.5 high 14% 2015-03-09
CVE-2017-9353 EXP In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by validating an IPv6 address. Patch early 7.5 high 14% 2017-06-02
CVE-2015-6176 EXP Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism… Patch early 4.3 medium 14% 2015-12-09
CVE-2010-1308 EXP Directory traversal vulnerability in the SVMap (com_svmap) component 1.1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot d… Patch early 5.0 medium 14% 2010-04-08
CVE-2006-2557 EXP PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newsportal (TRanx rebuilded), allows… Patch early 6.4 medium 14% 2006-05-24
CVE-2008-5551 EXP The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by inj… Patch early 4.3 medium 14% 2008-12-12
CVE-2009-1437 EXP Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows remote attackers to execute arbit… Patch early 9.3 high 14% 2009-04-27
CVE-2004-1456 EXP filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo. Patch early 7.5 high 14% 2004-12-31
CVE-2007-4459 EXP Cisco IP Phone 7940 and 7960 with P0S3-08-6-00 firmware, and other SIP firmware before 8.7(0), allows remote attackers to cause a denial of service (d… Patch early 7.1 high 14% 2007-08-21
← previous page 173 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt