peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,436 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-26

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2020-14181 EXP Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerabilit… Patch early 5.3 medium 99.6% 2020-09-17
CVE-2020-16040 EXP Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a craft… Patch early 6.5 medium 99.6% 2021-01-08
CVE-2014-0094 EXP The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is p… Patch early 5.0 medium 99.6% 2014-03-11
CVE-2021-34429 EXP For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of th… Patch early 5.3 medium 99.3% 2021-07-15
CVE-2020-11022 EXP In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation… Patch early 6.9 medium 99.2% 2020-04-29
CVE-2020-9496 EXP XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03 Patch early 6.1 medium 98.9% 2020-07-15
CVE-2018-15473 EXP OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet… Patch early 5.3 medium 98.6% 2018-08-17
CVE-2018-11409 EXP Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by… Patch early 5.3 medium 98.3% 2018-06-08
CVE-2012-3153 EXP Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attacke… Patch early 6.4 medium 98.2% 2012-10-16
CVE-2014-5445 EXP Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote attackers or remot… Patch early 5.0 medium 98% 2014-12-04
CVE-2018-11784 EXP When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. r… Patch early 4.3 medium 97.7% 2018-10-04
CVE-2013-5211 EXP The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via f… Patch early 5.0 medium 97.5% 2014-01-02
CVE-2012-0392 EXP The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute ar… Patch early 6.8 medium 97.5% 2012-01-08
CVE-2012-2122 EXP sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12,… Patch early 5.1 medium 96.5% 2012-06-26
CVE-1999-0016 EXP Land IP denial of service. Patch early 5.0 medium 95.7% 1997-12-01
CVE-2011-0049 EXP Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers to read ar… Patch early 5.0 medium 95.4% 2011-02-04
CVE-2008-1447 EXP The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, a… Patch early 6.8 medium 95.2% 2008-07-08
CVE-2006-3918 EXP http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, an… Patch early 4.3 medium 95.1% 2006-07-28
CVE-2002-0840 EXP Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off"… Patch early 6.8 medium 95.1% 2002-10-11
CVE-2015-5531 EXP Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to sna… Patch early 5.0 medium 94.8% 2015-08-17
CVE-2013-2248 EXP Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and condu… Patch early 5.8 medium 94.7% 2013-07-20
CVE-2009-0580 EXP Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enume… Patch early 4.3 medium 94.4% 2009-06-05
CVE-2017-5753 EXP Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wit… Patch early 5.6 medium 93.8% 2018-01-04
CVE-2020-2096 EXP Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability. Patch early 6.1 medium 92.8% 2020-01-15
CVE-2019-8943 EXP WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an a… Patch early 6.5 medium 92.6% 2019-02-20
CVE-2016-0492 EXP Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows rem… Patch early 6.4 medium 92.1% 2016-01-21
CVE-2010-1870 EXP The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly oth… Patch early 5.0 medium 92% 2010-08-17
CVE-2007-0450 EXP Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_prox… Patch early 5.0 medium 90.8% 2007-03-16
CVE-2011-3368 EXP The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with us… Patch early 5.0 medium 90.7% 2011-10-05
CVE-2022-44268 EXP ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded t… Patch early 6.5 medium 89.9% 2023-02-06
← previous page 2 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt