peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,237 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-0315 EXP WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a sp… Patch early 5.0 medium 6.9% 2010-01-14
CVE-2018-6064 EXP Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploi… Patch early 8.8 high 6.9% 2018-11-14
CVE-2006-4858 EXP PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier component for Mambo allows remo… Patch early 6.8 medium 6.9% 2006-09-19
CVE-2010-0166 EXP The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when t… Patch early 5.1 medium 6.9% 2010-03-25
CVE-2013-4093 EXP The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to obtain sensitive information vi… Patch early 5.0 medium 6.9% 2013-06-28
CVE-2005-0731 EXP PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to Fi… Patch early 5.0 medium 6.9% 2005-03-10
CVE-2002-0098 EXP Buffer overflow in index.cgi administration interface for Boozt! Standard 0.9.8 allows local users to execute arbitrary code via a long name field whe… Patch early 7.5 high 6.9% 2002-03-25
CVE-2004-1381 EXP Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported… Patch early 5.0 medium 6.9% 2004-10-20
CVE-2003-0766 EXP Multiple heap-based buffer overflows in FTP Desktop client 3.5, and possibly earlier versions, allow remote malicious servers to execute arbitrary cod… Patch early 7.5 high 6.9% 2003-09-17
CVE-2014-8604 EXP The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which a… Patch early 5.0 medium 6.9% 2015-06-10
CVE-2014-8605 EXP The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient… Patch early 5.0 medium 6.9% 2015-06-10
CVE-2016-0075 EXP The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain p… Patch early 5.5 medium 6.9% 2016-10-14
CVE-2016-5309 EXP The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud;… Patch early 5.5 medium 6.9% 2017-04-14
CVE-2006-6808 EXP Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML v… Patch early 6.8 medium 6.9% 2006-12-28
CVE-2000-0396 EXP The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to… Patch early 5.0 medium 6.9% 2000-05-24
CVE-2012-0242 EXP Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers… Patch early 10.0 high 6.9% 2012-02-21
CVE-2015-4683 EXP Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by levera… Patch early 9.8 critical 6.9% 2017-09-19
CVE-2013-4103 EXP Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input Patch early 9.8 critical 6.9% 2019-11-04
CVE-2009-1670 EXP user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin accounts via unspecified vector… Patch early 7.5 high 6.9% 2009-05-18
CVE-2006-3672 EXP KDE Konqueror 3.5.1 and earlier allows remote attackers to cause a denial of service (application crash) by calling the replaceChild method on a DOM o… Patch early 2.6 low 6.9% 2006-07-18
CVE-2008-3667 EXP Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTTP header. Patch early 6.8 medium 6.9% 2008-08-13
CVE-2010-4437 EXP Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.4, 10.0.2, 10.3.2, and 10.3.3 allows remot… Patch early 5.8 medium 6.9% 2011-01-19
CVE-2003-0863 EXP The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is n… Patch early 7.5 high 6.9% 2003-11-17
CVE-2017-6192 EXP Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arbitrary code via a crafted imag… Patch early 5.5 medium 6.9% 2018-02-20
CVE-2002-1813 EXP Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8.2790 allows remote attackers to execute arbitrary programs by specifying the prog… Patch early 2.6 low 6.9% 2002-12-31
CVE-1999-0414 EXP In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the conne… Patch early 5.0 medium 6.9% 1999-03-01
CVE-2000-0208 EXP The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters… Patch early 5.0 medium 6.9% 2000-02-29
CVE-2016-8580 EXP PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PH… Patch early 9.8 critical 6.9% 2016-10-28
CVE-2008-2390 EXP Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows remote attackers to execute ar… Patch early 6.8 medium 6.9% 2008-05-21
CVE-2002-0730 EXP Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields… Patch early 7.5 high 6.9% 2002-08-12
← previous page 291 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt