peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,436 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-26

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-7358 EXP ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerability, whi… Patch early 6.5 medium 89.6% 2018-11-14
CVE-2006-0026 EXP Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary cod… Patch early 6.5 medium 89.3% 2006-07-11
CVE-2016-2107 EXP The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which a… Patch early 5.9 medium 89.1% 2016-05-05
CVE-2016-6210 EXP sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username doe… Patch early 5.9 medium 88.9% 2017-02-13
CVE-2004-1520 EXP Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command. Patch early 4.6 medium 88.5% 2004-12-31
CVE-2003-0718 EXP The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and… Patch early 5.0 medium 87.9% 2004-11-03
CVE-2018-7357 EXP ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerability, whi… Patch early 6.5 medium 87.9% 2018-11-14
CVE-2017-5487 EXP wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restr… Patch early 5.3 medium 87.3% 2017-01-15
CVE-2000-0778 EXP IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "… Patch early 5.0 medium 87.3% 2000-10-20
CVE-2019-11358 EXP jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollutio… Patch early 6.1 medium 87.2% 2019-04-20
CVE-2003-0132 EXP A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed char… Patch early 5.0 medium 86.7% 2003-04-11
CVE-2013-7091 EXP Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows rem… Patch early 5.0 medium 86.3% 2013-12-13
CVE-2014-0226 EXP Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffe… Patch early 6.8 medium 85.7% 2014-07-20
CVE-2011-0063 EXP The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct directory traversal attacks and… Patch early 5.0 medium 85.5% 2011-03-15
CVE-2019-3799 EXP Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions a… Patch early 6.5 medium 85.3% 2019-05-06
CVE-2006-4847 EXP Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC,… Patch early 6.5 medium 85.3% 2006-09-19
CVE-2009-2335 EXP WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allo… Patch early 5.0 medium 85% 2009-07-10
CVE-2004-0493 EXP The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an… Patch early 6.4 medium 84.8% 2004-08-06
CVE-2019-8449 EXP The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosur… Patch early 5.3 medium 84.8% 2019-09-11
CVE-2007-3925 EXP Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute a… Patch early 6.5 medium 84.7% 2007-07-21
CVE-2015-1830 EXP Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows a… Patch early 5.0 medium 84.4% 2015-08-19
CVE-2012-4940 EXP Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbit… Patch early 6.4 medium 83.6% 2012-10-31
CVE-2023-22232 EXP Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Secu… Patch early 5.3 medium 83.4% 2023-02-17
CVE-2009-3733 EXP Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMw… Patch early 5.0 medium 83.4% 2009-11-02
CVE-2011-4885 EXP PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote… Patch early 5.0 medium 83.4% 2011-12-30
CVE-2019-14470 EXP cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php… Patch early 6.1 medium 83% 2019-09-04
CVE-2005-0356 EXP Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to caus… Patch early 5.0 medium 82.8% 2005-05-31
CVE-2020-2230 EXP Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting… Patch early 5.4 medium 82.7% 2020-08-12
CVE-2014-9034 EXP wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause… Patch early 5.0 medium 82.7% 2014-11-25
CVE-2006-0003 EXP Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Acc… Patch early 5.1 medium 82.5% 2006-04-12
← previous page 3 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt