peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,529 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-0376 EXP PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL i… Patch early 6.8 medium 31.5% 2008-01-22
CVE-2012-3137 EXP The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain… Patch early 6.4 medium 31.4% 2012-09-21
CVE-2014-1683 EXP The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is… Patch early 6.8 medium 31.4% 2014-01-29
CVE-1999-0678 EXP A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the e… Patch early 5.0 medium 31.4% 1999-01-17
CVE-1999-0077 EXP Predictable TCP sequence numbers allow spoofing. Patch early 5.0 medium 31.4% 1995-01-01
CVE-2007-5363 EXP PHP remote file inclusion vulnerability in admin.panoramic.php in the Panoramic Picture Viewer (com_panoramic) mambot (plugin) 1.0 for Joomla! allows… Patch early 6.8 medium 31.4% 2007-10-11
CVE-2007-5841 EXP PHP remote file inclusion vulnerability in admin/index.php in nuBoard 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the site… Patch early 6.8 medium 31.4% 2007-11-06
CVE-2007-5451 EXP PHP remote file inclusion vulnerability in admin.color.php in the com_colorlab (aka com_color) 1.0 component for Joomla! allows remote attackers to ex… Patch early 6.8 medium 31.2% 2007-10-14
CVE-2014-2268 EXP views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-ins… Patch early 5.0 medium 31.2% 2014-11-16
CVE-2023-4708 EXP A vulnerability was found in Infosoftbd Clcknshop 1.0.0. It has been rated as critical. This issue affects some unknown processing of the file /collec… Patch early 6.3 medium 31.2% 2023-09-01
CVE-2012-5002 EXP Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows… Patch early 6.8 medium 31.2% 2012-09-19
CVE-2010-2731 EXP Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 on Windows XP SP3, when directory-based Basic Authentication is enabled… Patch early 6.8 medium 31.1% 2010-09-15
CVE-2005-4131 EXP Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to… Patch early 6.8 medium 31.1% 2005-12-09
CVE-2004-1546 EXP Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a long (1) SAML, SOML, SEND, or… Patch early 5.0 medium 31.1% 2004-12-31
CVE-2015-7855 EXP The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion… Patch early 6.5 medium 31.1% 2017-08-07
CVE-2007-4891 EXP A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3)… Patch early 6.8 medium 31% 2007-09-14
CVE-2009-2255 EXP Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which allows remote attackers to exec… Patch early 6.8 medium 31% 2009-06-30
CVE-2007-4466 EXP Multiple stack-based buffer overflows in Electronic Arts (EA) SnoopyCtrl ActiveX control (NPSnpy.dll) allow remote attackers to execute arbitrary code… Patch early 6.8 medium 30.9% 2007-10-09
CVE-2011-2755 EXP Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read arbitrary… Patch early 5.0 medium 30.9% 2011-07-17
CVE-2006-6665 EXP Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute arbitrary code via a long file… Patch early 6.8 medium 30.9% 2006-12-20
CVE-2003-1172 EXP Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access ar… Patch early 5.0 medium 30.8% 2003-12-31
CVE-2004-1602 EXP ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to ident… Patch early 5.0 medium 30.7% 2004-10-15
CVE-2002-2006 EXP The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sens… Patch early 5.0 medium 30.7% 2002-12-31
CVE-2024-55963 EXP An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causi… Patch early 6.5 medium 30.7% 2025-03-26
CVE-2011-3976 EXP Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long filename in a response to a LIST c… Patch early 6.8 medium 30.6% 2011-10-04
CVE-1999-1375 EXP FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file… Patch early 5.0 medium 30.5% 1999-02-11
CVE-2021-25158 EXP A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.… Patch early 5.9 medium 30.5% 2021-03-30
CVE-2011-0419 EXP Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apach… Patch early 4.3 medium 30.4% 2011-05-16
CVE-2007-3872 EXP Multiple stack-based buffer overflows in the Shared Trace Service (OVTrace) service for HP OpenView Operations A.07.50 for Windows, and possibly earli… Patch early 6.8 medium 30.3% 2007-08-09
CVE-2025-50154 EXP Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network… Patch early 6.5 medium 30.2% 2025-08-12
← previous page 20 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt