peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,696 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2020-5752 EXP Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands w… Patch early 7.8 high 8.6% 2020-05-21
CVE-2008-7124 EXP zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain ad… Patch early 7.5 high 8.6% 2009-08-31
CVE-2009-1549 EXP AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto." Patch early 7.5 high 8.6% 2009-05-06
CVE-2010-3039 EXP /usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated… Patch early 6.8 medium 8.6% 2010-11-09
CVE-1999-0953 EXP WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers. Patch early 10.0 high 8.6% 1999-09-16
CVE-2003-0143 EXP The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authentic… Patch early 10.0 high 8.6% 2003-03-18
CVE-2000-0977 EXP mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" paramet… Patch early 5.0 medium 8.6% 2000-12-19
CVE-2010-2307 EXP Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHP… Patch early 5.0 medium 8.6% 2010-06-16
CVE-2003-1148 EXP Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and po… Patch early 7.5 high 8.6% 2003-10-25
CVE-2007-0614 EXP The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a… Patch early 7.8 high 8.6% 2007-01-31
CVE-2008-6953 EXP Buffer overflow in oovoo.exe in ooVoo 1.7.1.35, and possibly other versions before 1.7.1.59, allows remote attackers to cause a denial of service (cra… Patch early 9.3 high 8.6% 2009-08-12
CVE-2007-0817 EXP Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Ag… Patch early 4.3 medium 8.6% 2007-02-07
CVE-2002-0962 EXP Cross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via (1) the url variable in the L… Patch early 7.5 high 8.6% 2002-10-04
CVE-2005-4559 EXP mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly ini… Patch early 5.0 medium 8.6% 2005-12-28
CVE-2007-2482 EXP Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allo… Patch early 6.8 medium 8.6% 2007-05-03
CVE-2008-4323 EXP Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application crash) via a crafted .ZIP file. Patch early 4.3 medium 8.6% 2008-09-29
CVE-2016-3963 EXP Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 443. Patch early 5.3 medium 8.6% 2016-04-08
CVE-2011-1143 EXP epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (NULL pointer… Patch early 4.3 medium 8.6% 2011-03-03
CVE-2000-0508 EXP rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request. Patch early 5.0 medium 8.6% 1994-12-19
CVE-2003-0651 EXP Buffer overflow in the mylo_log logging function for mod_mylo 0.2.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET… Patch early 7.5 high 8.6% 2003-08-27
CVE-2006-4877 EXP Variable overwrite vulnerability in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to overwrite arbitrary program variables via… Patch early 5.0 medium 8.6% 2006-09-19
CVE-2018-4200 EXP An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud before 7.5 on Windows is affe… Patch early 8.8 high 8.6% 2018-06-08
CVE-2017-17110 EXP Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request. Patch early 9.8 critical 8.6% 2017-12-11
CVE-2018-11736 EXP An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the… Patch early 9.8 critical 8.6% 2018-06-05
CVE-2023-27290 EXP Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require… Patch early 9.1 critical 8.6% 2023-03-03
CVE-2009-1830 EXP Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long search query. Patch early 10.0 high 8.6% 2009-05-29
CVE-2010-1176 EXP Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… Patch early 9.3 high 8.6% 2010-03-29
CVE-2019-3999 EXP Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to exe… Patch early 7.8 high 8.6% 2020-02-25
CVE-2008-0127 EXP The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute ar… Patch early 8.8 high 8.6% 2008-01-10
CVE-2014-6389 EXP backup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the d parameter. Patch early 7.5 high 8.6% 2014-10-06
← previous page 242 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt