peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,355 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-4089 EXP telepark.wiki 2.4.23 and earlier allows remote attackers to bypass authorization and (1) delete arbitrary pages via a modified pageID parameter to aja… Patch early 5.0 medium 6.6% 2009-11-29
CVE-2017-2522 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… Patch early 9.8 critical 6.6% 2017-05-22
CVE-2009-1517 EXP Multiple insecure method vulnerabilities in the Symantec.EasySetup.1 ActiveX control in EasySetupInt.dll 14.0.4.30167 in the EasySetup wizard in Syman… Patch early 4.3 medium 6.6% 2009-05-04
CVE-2009-0071 EXP Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer deref… Patch early 2.6 low 6.6% 2009-01-08
CVE-2005-4316 EXP HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via a "Rose Attack" that involves sending a subset o… Patch early 7.8 high 6.6% 2005-12-17
CVE-2017-0045 EXP Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allo… Patch early 5.5 medium 6.6% 2017-03-17
CVE-2002-2251 EXP Buffer overflow in the changevalue function in libcgi.h for Marcos Luiz Onisto Lib CGI 0.1 allows remote attackers to execute arbitrary code via a lon… Patch early 10.0 high 6.6% 2002-12-31
CVE-2002-1135 EXP modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_prefix para… Patch early 7.5 high 6.6% 2002-10-04
CVE-2005-1222 EXP cat_for_gen.php in Annuaire Netref 4.2 allows remote attackers to execute arbitrary PHP code by setting the ad_direct parameter to reference cat_for_g… Patch early 7.5 high 6.6% 2005-05-02
CVE-2013-1891 EXP In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed. Patch early 6.5 medium 6.6% 2022-06-24
CVE-2009-0113 EXP Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allows remote attackers to list ar… Patch early 5.0 medium 6.6% 2009-01-09
CVE-2009-3787 EXP files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files via the file parameter with "lo… Patch early 5.0 medium 6.6% 2009-10-26
CVE-2015-8282 EXP SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account. Patch early 9.8 critical 6.6% 2017-04-13
CVE-2013-4978 EXP Stack-based buffer overflow in AloahaPDFViewer 5.0.0.7 and earlier in Aloaha PDF Suite FREE allows remote attackers to execute arbitrary code via a cr… Patch early 9.3 high 6.6% 2014-02-05
CVE-2010-0364 EXP Stack-based buffer overflow in VideoLAN VLC Media Player 0.8.6 allows user-assisted remote attackers to execute arbitrary code via an ogg file with a… Patch early 9.3 high 6.6% 2010-01-21
CVE-2004-1441 EXP Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary web script or HTML via the actio… Patch early 9.3 high 6.6% 2004-12-31
CVE-2003-0833 EXP Stack-based buffer overflow in webfs before 1.20 allows attackers to execute arbitrary code by creating directories that result in a long pathname. Patch early 7.5 high 6.6% 2003-11-17
CVE-2000-0038 EXP glFtpD includes a default glftpd user account with a default password and a UID of 0. Patch early 7.5 high 6.6% 1999-12-23
CVE-2014-4154 EXP ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows… Patch early 5.0 medium 6.6% 2014-07-16
CVE-2017-2531 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. Th… Patch early 8.8 high 6.6% 2017-05-22
CVE-2017-6980 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. Th… Patch early 8.8 high 6.6% 2017-05-22
CVE-2004-1540 EXP ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to acce… Patch early 5.0 medium 6.6% 2004-12-31
CVE-1999-0235 EXP Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access. Patch early 10.0 high 6.6% 1995-02-17
CVE-2005-1681 EXP PHP remote file inclusion vulnerability in common.php in phpATM 1.21, and possibly earlier versions, allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 6.6% 2005-05-20
CVE-2006-1504 EXP Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0 (aka Arab Dynamic Portal or ADP) stable allow remote attackers to inject arbitr… Patch early 5.1 medium 6.6% 2006-03-30
CVE-2005-2729 EXP The HTTP proxy in Astaro Security Linux 6.0 does not properly filter HTTP CONNECT requests to localhost, which allows remote attackers to bypass firew… Patch early 7.5 high 6.6% 2005-08-30
CVE-2015-2527 EXP The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R… Patch early 7.2 high 6.6% 2015-09-09
CVE-2017-11552 EXP mpg321.c in mpg321 0.3.2-1 does not properly manage memory for use with libmad 0.15.1b, which allows remote attackers to cause a denial of service (me… Patch early 6.5 medium 6.6% 2017-08-01
CVE-2012-4999 EXP Mercury MR804 Router 8.0 3.8.1 Build 101220 Rel.53006nB allows remote attackers to cause a denial of service (service hang) via a crafted string in HT… Patch early 6.1 medium 6.6% 2012-09-19
CVE-2008-2930 EXP Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 allow remote attackers to cause a denial of ser… Patch early 7.1 high 6.6% 2008-08-29
← previous page 299 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt