peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,932 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-43116 EXP An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and th… Patch early 8.8 high 7.5% 2022-07-05
CVE-2017-0220 EXP The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gold allows authenticated attackers to obtain sensiti… Patch early 4.7 medium 7.5% 2017-05-12
CVE-1999-0347 EXP Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which caus… Patch early 10.0 high 7.5% 1999-01-26
CVE-2005-2033 EXP Directory traversal vulnerability in folderview.asp for Blue-Collar Productions i-Gallery 3.3 allows remote attackers to read arbitrary files and dire… Patch early 5.0 medium 7.5% 2005-06-20
CVE-2010-0655 EXP Use-after-free vulnerability in Google Chrome before 4.0.249.78 allows user-assisted remote attackers to cause a denial of service (application crash)… Patch early 9.3 high 7.5% 2010-02-18
CVE-2007-1842 EXP Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a ..… Patch early 7.5 high 7.5% 2007-04-03
CVE-2014-5370 EXP Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDragon before 7.1.1.18527 allows… Patch early 7.5 high 7.5% 2015-04-21
CVE-2002-1991 EXP PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php. Patch early 7.5 high 7.5% 2002-12-31
CVE-2001-0780 EXP Directory traversal vulnerability in cosmicpro.cgi in Cosmicperl Directory Pro 2.0 allows remote attackers to gain sensitive information via a .. (dot… Patch early 5.0 medium 7.5% 2001-10-18
CVE-2014-8555 EXP Directory traversal vulnerability in report/reportViewAction.jsp in Progress Software OpenEdge 11.2 allows remote attackers to read arbitrary files vi… Patch early 5.0 medium 7.5% 2014-11-12
CVE-2004-1206 EXP Directory traversal vulnerability in codebrowserpntm.php in pnTresMailer 6.0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in t… Patch early 5.0 medium 7.5% 2005-01-10
CVE-2012-0282 EXP Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitra… Patch early 6.8 medium 7.5% 2012-07-17
CVE-2007-1471 EXP admin/default.asp in Orion-Blog 2.0 allows remote attackers to bypass authentication controls and gain privileges via a direct URL request for admin/A… Patch early 7.5 high 7.4% 2007-03-16
CVE-2009-1391 EXP Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly oth… Patch early 6.8 medium 7.4% 2009-06-16
CVE-2005-0635 EXP Buffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command. Patch early 10.0 high 7.4% 2005-05-02
CVE-2025-3605 EXP The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and… Patch early 9.8 critical 7.4% 2025-05-09
CVE-2007-3222 EXP PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 7.4% 2007-06-14
CVE-2008-0680 EXP SNMPd in MikroTik RouterOS 3.2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP SET request. Patch early 7.8 high 7.4% 2008-02-12
CVE-2009-2256 EXP The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial of service (web outage) via an… Patch early 7.8 high 7.4% 2009-06-30
CVE-2007-1010 EXP Multiple PHP remote file inclusion vulnerabilities in ZebraFeeds 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PH… Patch early 6.8 medium 7.4% 2007-02-21
CVE-2006-3670 EXP Stack-based buffer overflow in Winlpd 1.26 allows remote attackers to execute arbitrary code via a long string in a request to TCP port 515. Patch early 7.5 high 7.4% 2006-07-18
CVE-2007-5298 EXP Multiple PHP remote file inclusion vulnerabilities in CMS Creamotion allow remote attackers to execute arbitrary PHP code via a URL in the cfg[documen… Patch early 6.4 medium 7.4% 2007-10-09
CVE-2014-2072 EXP Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks Patch early 9.8 critical 7.4% 2020-01-08
CVE-2005-3483 EXP Buffer overflow in GO-Global for Windows 3.1.0.3270 and earlier allows remote attackers to execute arbitrary code via a data block that is longer than… Patch early 7.5 high 7.4% 2005-11-03
CVE-2011-3487 EXP Directory traversal vulnerability in CarelDataServer.exe in Carel PlantVisor 2.4.4 and earlier allows remote attackers to read arbitrary files via a .… Patch early 5.0 medium 7.4% 2011-09-16
CVE-2009-1022 EXP Heap-based buffer overflow in the Preview/ Set Segment function in Gretech GOMlab GOM Encoder 1.0.0.11 and earlier allows user-assisted remote attacke… Patch early 9.3 high 7.4% 2009-03-20
CVE-2015-5754 EXP Race condition in runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 allows attackers to execute arbit… Patch early 9.3 high 7.4% 2015-08-17
CVE-2006-1346 EXP Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to include and execute arbitr… Patch early 6.4 medium 7.4% 2006-03-22
CVE-2011-4043 EXP Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote att… Patch early 9.3 high 7.4% 2012-04-03
CVE-2019-15501 EXP Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter. Patch early 6.1 medium 7.4% 2019-08-26
← previous page 272 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt