peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,461 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2001-0748 EXP Acme.Serve 1.7, as used in Cisco Secure ACS Unix and possibly other products, allows remote attackers to read arbitrary files by prepending several /… Patch early 5.0 medium 9.2% 2001-10-18
CVE-2006-2901 EXP The web server for D-Link Wireless Access-Point (DWL-2100ap) firmware 2.10na and earlier allows remote attackers to obtain sensitive system informatio… Patch early 5.0 medium 9.2% 2006-06-07
CVE-2006-0053 EXP Imager (libimager-perl) before 0.50 allows user-assisted attackers to cause a denial of service (segmentation fault) by writing a 2- or 4-channel JPEG… Patch early 2.6 low 9.2% 2006-04-10
CVE-2008-0778 EXP Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow remote attackers to cause a de… Patch early 7.5 high 9.2% 2008-02-14
CVE-2016-8023 EXP Authentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote un… Patch early 8.1 high 9.2% 2017-03-14
CVE-2000-0787 EXP IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which XC… Patch early 7.5 high 9.2% 2000-10-20
CVE-2011-0678 EXP Unrestricted file upload vulnerability in the EasyEdit module in Lomtec ActiveWeb Professional 3.0 allows remote attackers to execute arbitrary code b… Patch early 6.8 medium 9.2% 2011-01-28
CVE-2008-5183 EXP cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large numbe… Patch early 7.5 high 9.2% 2008-11-21
CVE-2011-4898 EXP wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbnam… Patch early 5.0 medium 9.2% 2012-01-30
CVE-2008-4101 EXP Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands b… Patch early 9.3 high 9.2% 2008-09-18
CVE-2015-5895 EXP Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors. Patch early 10.0 high 9.2% 2015-09-18
CVE-2013-2287 EXP Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject ar… Patch early 4.3 medium 9.2% 2014-04-04
CVE-2007-1381 EXP The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and fixed on 20070304, calls strl… Patch early 7.6 high 9.2% 2007-03-10
CVE-2011-1519 EXP The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specif… Patch early 10.0 high 9.2% 2011-03-25
CVE-2006-3372 EXP Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) via a DHTML setAttributeNode function call with zero… Patch early 5.0 medium 9.2% 2006-07-06
CVE-2012-0991 EXP Multiple directory traversal vulnerabilities in OpenEMR 4.1.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the formn… Patch early 3.5 low 9.2% 2012-02-07
CVE-2006-4006 EXP The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_p… Patch early 5.0 medium 9.2% 2006-08-07
CVE-2018-6092 EXP An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code insid… Patch early 8.8 high 9.2% 2018-12-04
CVE-2022-26982 EXP SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because… Patch early 7.2 high 9.2% 2022-04-05
CVE-2014-7226 EXP The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with… Patch early 7.5 high 9.2% 2014-10-10
CVE-2007-1542 EXP Unspecified vulnerability in the Cisco IP Phone 7940 and 7960 running firmware before POS8-6-0 allows remote attackers to cause a denial of service vi… Patch early 5.0 medium 9.2% 2007-03-20
CVE-2021-46360 EXP Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrary code via uploading a PHP she… Patch early 8.8 high 9.2% 2022-02-09
CVE-2011-2194 EXP Integer overflow in the XSPF playlist parser in VideoLAN VLC media player 0.8.5 through 1.1.9 allows remote attackers to cause a denial of service (cr… Patch early 9.3 high 9.2% 2011-06-24
CVE-2000-0613 EXP Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to force the firewall to close legi… Patch early 5.0 medium 9.2% 2000-03-20
CVE-2008-6976 EXP MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (NMS) settings via a crafted SNM… Patch early 6.4 medium 9.2% 2009-08-19
CVE-2005-0828 EXP highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote at… Patch early 5.0 medium 9.2% 2005-05-02
CVE-2014-5112 EXP maint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacharacters in the lang parameter. Patch early 7.5 high 9.2% 2014-07-28
CVE-2007-6318 EXP SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the… Patch early 6.8 medium 9.2% 2007-12-12
CVE-2011-5219 EXP Directory traversal vulnerability in examples/show_code.php in mPDF 5.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 5.0 medium 9.2% 2012-10-25
CVE-2007-4816 EXP Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown impact via a long (1) URL, (2) ba… Patch early 7.5 high 9.2% 2007-09-11
← previous page 230 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt