peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,553 CVEs 1,726 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-1465 EXP Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause a denial of service (applicat… Patch early 4.3 medium 27.1% 2012-03-19
CVE-2013-3522 EXP SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authenticated u… Patch early 6.5 medium 27.1% 2013-05-10
CVE-2002-1567 EXP Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with… Patch early 6.8 medium 27.1% 2003-10-06
CVE-2017-18357 EXP Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backen… Patch early 6.5 medium 27.1% 2019-01-15
CVE-2018-14665 EXP A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server all… Patch early 6.6 medium 27% 2018-10-25
CVE-2013-6719 EXP delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows re… Patch early 6.0 medium 27% 2014-03-06
CVE-2006-5296 EXP PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assi… Patch early 4.3 medium 27% 2006-10-16
CVE-2010-4804 EXP The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActi… Patch early 4.3 medium 27% 2011-06-09
CVE-2003-1025 EXP Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain po… Patch early 4.3 medium 26.9% 2004-01-20
CVE-2000-0653 EXP Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka… Patch early 5.0 medium 26.9% 2000-07-20
CVE-2004-0558 EXP The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a ce… Patch early 5.0 medium 26.8% 2004-09-28
CVE-2009-0026 EXP Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 26.8% 2009-01-21
CVE-2015-2166 EXP Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attacker… Patch early 5.0 medium 26.8% 2015-04-06
CVE-2008-4029 EXP Cross-domain vulnerability in Microsoft XML Core Services 3.0 and 4.0, as used in Internet Explorer, allows remote attackers to obtain sensitive infor… Patch early 4.3 medium 26.7% 2008-11-12
CVE-2011-4535 EXP Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC ModbusTagServer 4.1.1.81 and earli… Patch early 6.8 medium 26.7% 2012-04-03
CVE-2017-8295 EXP WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitr… Patch early 5.9 medium 26.7% 2017-05-04
CVE-2011-4044 EXP An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to modify fil… Patch early 5.8 medium 26.7% 2012-04-03
CVE-2013-0108 EXP An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R410.2; SymmetrE R310, R410.1,… Patch early 6.8 medium 26.6% 2013-02-24
CVE-2008-1776 EXP PHP remote file inclusion vulnerability in modules/basicfog/basicfogfactory.class.php in PhpBlock A8.4 allows remote attackers to execute arbitrary PH… Patch early 6.8 medium 26.6% 2008-04-14
CVE-2008-1773 EXP PHP remote file inclusion vulnerability in includes/header.inc.php in Dragoon 0.1 allows remote attackers to execute arbitrary PHP code via a URL in t… Patch early 6.8 medium 26.6% 2008-04-14
CVE-2008-1682 EXP PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1.0.2 component for Joomla! all… Patch early 6.8 medium 26.6% 2008-04-04
CVE-2007-3763 EXP The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appli… Patch early 5.0 medium 26.6% 2007-07-18
CVE-2006-6311 EXP Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service via a style attribute in an HTML table tag with a width… Patch early 5.0 medium 26.5% 2006-12-06
CVE-2008-6938 EXP Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to… Patch early 4.3 medium 26.5% 2009-08-11
CVE-2010-4598 EXP Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the… Patch early 5.0 medium 26.5% 2010-12-23
CVE-2011-4518 EXP Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to read arbitrary… Patch early 5.0 medium 26.4% 2013-05-23
CVE-2021-24563 EXP The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to up… Patch early 6.1 medium 26.4% 2021-10-11
CVE-2006-3591 EXP Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the URL property of a TriEditDocum… Patch early 5.0 medium 26.2% 2006-07-18
CVE-2015-2998 EXP SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensitive information, as demonstra… Patch early 5.0 medium 26.2% 2015-06-08
CVE-2014-2314 EXP Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via u… Patch early 4.3 medium 26.2% 2014-03-09
← previous page 23 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt