peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,603 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-5112 EXP The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a failed bind attempt depending… Patch early 5.0 medium 17.4% 2008-11-17
CVE-2013-5045 EXP Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by lever… Patch early 6.2 medium 17.4% 2013-12-11
CVE-2008-0236 EXP An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary commands by invoking the DoCmd meth… Patch early 5.8 medium 17.4% 2008-01-11
CVE-2009-3019 EXP Microsoft Internet Explorer 6 on Windows XP SP2 and SP3, and Internet Explorer 7 on Vista, allows remote attackers to cause a denial of service (appli… Patch early 5.0 medium 17.4% 2009-08-31
CVE-2013-4660 EXP The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to e… Patch early 6.8 medium 17.3% 2013-06-28
CVE-2007-1377 EXP AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspeci… Patch early 5.0 medium 17.3% 2007-03-10
CVE-2004-0526 EXP Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "al… Patch early 5.0 medium 17.2% 2004-08-06
CVE-2010-3609 EXP The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol daemon (SL… Patch early 5.0 medium 17.2% 2011-03-11
CVE-2006-4075 EXP Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and earlier allow remote attackers to… Patch early 5.1 medium 17.2% 2006-08-11
CVE-2001-0348 EXP Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace. Patch early 5.0 medium 17.2% 2001-07-21
CVE-2020-26567 EXP An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any ac… Patch early 5.5 medium 17.2% 2020-10-08
CVE-2011-3829 EXP ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the file name, w… Patch early 4.0 medium 17.1% 2012-01-29
CVE-2017-2361 EXP An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Help Viewer" component, which allows XSS… Patch early 6.1 medium 17.1% 2017-02-20
CVE-2005-1191 EXP The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe ("'") in the author name in… Patch early 5.0 medium 17.1% 2005-05-02
CVE-2006-3317 EXP PHP remote file inclusion vulnerability in phpRaid 3.0.6 allows remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (… Patch early 5.1 medium 17.1% 2006-06-29
CVE-2006-3354 EXP Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter property of an ADODB.Recordset Active… Patch early 5.0 medium 17.1% 2006-07-06
CVE-2006-3910 EXP Internet Explorer 6 on Windows XP SP2, when Outlook is installed, allows remote attackers to cause a denial of service (crash) by calling the NewDefau… Patch early 5.0 medium 17.1% 2006-07-28
CVE-2016-8581 EXP A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker t… Patch early 6.1 medium 17.1% 2016-10-28
CVE-2002-1634 EXP Novell NetWare 5.1 installs sample applications that allow remote attackers to obtain sensitive information via (1) ndsobj.nlm, (2) allfield.jse, (3)… Patch early 5.0 medium 17% 2002-12-31
CVE-2015-3440 EXP Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 16.9% 2015-08-03
CVE-2010-1345 EXP Directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to read arbitrary fil… Patch early 5.0 medium 16.9% 2010-04-09
CVE-2006-3772 EXP PHP-Post 0.21 and 1.0, and possibly earlier versions, when auto-login is enabled, allows remote attackers to bypass security restrictions and obtain a… Patch early 5.1 medium 16.8% 2006-07-24
CVE-2017-8536 EXP The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… Patch early 5.5 medium 16.8% 2017-05-26
CVE-2017-8537 EXP The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… Patch early 5.5 medium 16.8% 2017-05-26
CVE-2017-8535 EXP The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… Patch early 5.5 medium 16.8% 2017-05-26
CVE-1999-0224 EXP Denial of service in Windows NT messenger service through a long username. Patch early 5.0 medium 16.8% 1999-07-23
CVE-2018-0494 EXP GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line. Patch early 6.5 medium 16.8% 2018-05-06
CVE-2008-2167 EXP Cross-site scripting (XSS) vulnerability in ZyXEL ZyWALL 100 allows remote attackers to inject arbitrary web script or HTML via the Referer header, wh… Patch early 4.3 medium 16.8% 2008-05-13
CVE-2008-4546 EXP Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows remote web servers to cause a denial of servi… Patch early 4.3 medium 16.8% 2008-10-14
CVE-2012-6554 EXP functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute arbitrary PHP code via the me… Patch early 6.5 medium 16.7% 2013-05-23
← previous page 34 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt