peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,964 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2013-4982 EXP AVTECH AVN801 DVR has a security bypass via the administration login captcha Patch early 9.8 critical 13.1% 2019-12-27
CVE-1999-0981 EXP Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local fi… Patch early 5.1 medium 13.1% 1999-12-08
CVE-2006-5882 EXP Stack-based buffer overflow in the Broadcom BCMWL5.SYS wireless device driver 3.50.21.10, as used in Cisco Linksys WPC300N Wireless-N Notebook Adapter… Patch early 8.3 high 13.1% 2006-11-14
CVE-2000-0704 EXP Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFO commands. Patch early 10.0 high 13.1% 2000-10-20
CVE-2006-6697 EXP CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary… Patch early 7.5 high 13.1% 2006-12-22
CVE-2018-4121 EXP An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affect… Patch early 8.8 high 13.1% 2018-04-03
CVE-2008-5732 EXP Unrestricted file upload vulnerability in lib/image_upload.php in KafooeyBlog 1.55b allows remote attackers to execute arbitrary code by uploading a f… Patch early 7.5 high 13.1% 2008-12-26
CVE-2007-2926 EXP ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY… Patch early 4.3 medium 13.1% 2007-07-24
CVE-2006-1959 EXP PHP remote file inclusion vulnerability in direct.php in ActualScripts ActualAnalyzer Lite 2.72 and earlier, Gold 7.63 and earlier, and Server 8.23 an… Patch early 7.5 high 13.1% 2006-04-21
CVE-2010-2050 EXP Directory traversal vulnerability in the Moron Solutions MS Comment (com_mscomment) component 0.8.0b for Joomla! allows remote attackers to read arbit… Patch early 7.5 high 13.1% 2010-05-25
CVE-2014-3805 EXP The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2)… Patch early 10.0 high 13.1% 2014-06-13
CVE-2013-2748 EXP Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system. Patch early 9.8 critical 13.1% 2020-01-28
CVE-2016-0049 EXP Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows… Patch early 6.2 medium 13.1% 2016-02-10
CVE-2015-2842 EXP Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAutoDial GoAdmin CE 3.x before 3… Patch early 10.0 high 13.1% 2015-05-12
CVE-2006-0147 EXP Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis,… Patch early 7.5 high 13.1% 2006-01-09
CVE-2007-2645 EXP Integer overflow in the exif_data_load_data_entry function in exif-data.c in libexif before 0.6.14 allows user-assisted remote attackers to cause a de… Patch early 9.3 high 13.1% 2007-05-14
CVE-2006-6863 EXP PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote attackers to execute arbitrary PH… Patch early 9.8 critical 13.1% 2006-12-31
CVE-2019-1144 EXP A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who succes… Patch early 8.8 high 13.1% 2019-08-14
CVE-2019-1145 EXP A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who succes… Patch early 8.8 high 13.1% 2019-08-14
CVE-2019-1152 EXP A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who succes… Patch early 8.8 high 13.1% 2019-08-14
CVE-2011-3597 EXP Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arbitrary commands via the new co… Patch early 7.5 high 13.1% 2012-01-13
CVE-2014-3997 EXP SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Provide… Patch early 7.5 high 13.1% 2014-12-05
CVE-2014-7192 EXP Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer an… Patch early 10.0 high 13% 2014-12-11
CVE-2021-20031 EXP A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains… Patch early 6.1 medium 13% 2021-10-12
CVE-2008-1709 EXP Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with… Patch early 9.3 high 13% 2008-04-09
CVE-2006-2860 EXP PHP remote file inclusion vulnerability in Webspotblogging 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter… Patch early 6.4 medium 13% 2006-06-06
CVE-2015-1365 EXP Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to write to arbi… Patch early 5.0 medium 13% 2015-01-27
CVE-2002-0263 EXP Buffer overflow in EasyBoard 2000 1.27 (aka EZboard) allows remote attackers to execute arbitrary code via a long boundary value in a multipart Conten… Patch early 7.5 high 13% 2002-05-29
CVE-2010-2866 EXP Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cause a denial of service (memory… Patch early 9.3 high 13% 2010-08-26
CVE-2010-2204 EXP Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows attackers to cause a deni… Patch early 9.3 high 13% 2010-06-30
← previous page 182 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt