peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,648 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-14696 EXP Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter. Patch early 6.1 medium 15.7% 2019-08-06
CVE-2008-3443 EXP The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows re… Patch early 5.0 medium 15.7% 2008-08-14
CVE-2007-2356 EXP Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attackers to e… Patch early 6.8 medium 15.7% 2007-04-30
CVE-2009-1335 EXP Microsoft Internet Explorer 7 and 8 on Windows XP and Vista allows remote attackers to cause a denial of service (application hang) via a large docume… Patch early 4.3 medium 15.7% 2009-04-17
CVE-2007-5219 EXP Directory traversal vulnerability in the CLAVSetting.CLSetting.1 ActiveX control in CLAVSetting.DLL 1.00.1829 in the CLAVSetting module in CyberLink P… Patch early 6.4 medium 15.7% 2007-10-05
CVE-2014-9119 EXP Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary file… Patch early 5.0 medium 15.7% 2014-12-31
CVE-2009-0991 EXP Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to… Patch early 5.0 medium 15.6% 2009-04-15
CVE-2018-8719 EXP An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not res… Patch early 5.3 medium 15.6% 2018-04-04
CVE-2006-3340 EXP Multiple PHP remote file inclusion vulnerabilities in Pearl For Mambo module 1.6 for Mambo, when register_globals is enabled, allow remote attackers t… Patch early 5.1 medium 15.6% 2006-07-03
CVE-2006-2864 EXP Multiple PHP remote file inclusion vulnerabilities in BlueShoes Framework 4.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1… Patch early 5.1 medium 15.6% 2006-06-06
CVE-2010-0187 EXP Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow remote attackers to cause a denial of service (application crash) via a modi… Patch early 4.3 medium 15.6% 2010-02-15
CVE-2006-6421 EXP Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to i… Patch early 6.0 medium 15.6% 2006-12-10
CVE-2012-0874 EXP The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EW… Patch early 6.8 medium 15.6% 2013-02-05
CVE-2010-1601 EXP Directory traversal vulnerability in the JA Comment (com_jacomment) component for Joomla! allows remote attackers to read arbitrary files via a .. (do… Patch early 5.0 medium 15.6% 2010-04-29
CVE-2008-2138 EXP Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/po… Patch early 5.0 medium 15.5% 2008-05-12
CVE-2019-3778 EXP Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported ver… Patch early 6.5 medium 15.5% 2019-03-07
CVE-2007-0103 EXP The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknown impact, possibly including d… Patch early 6.8 medium 15.5% 2007-01-09
CVE-2020-28978 EXP The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and e… Patch early 5.3 medium 15.4% 2020-11-30
CVE-2020-28977 EXP The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and e… Patch early 5.3 medium 15.4% 2020-11-30
CVE-2014-1778 EXP Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, ak… Patch early 6.8 medium 15.4% 2014-06-11
CVE-2007-2237 EXP Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO fil… Patch early 5.5 medium 15.4% 2007-06-06
CVE-2008-2841 EXP Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary… Patch early 6.8 medium 15.4% 2008-06-24
CVE-2008-6668 EXP Multiple directory traversal vulnerabilities in nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1… Patch early 5.0 medium 15.3% 2009-04-08
CVE-2005-1477 EXP The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute… Patch early 5.1 medium 15.2% 2005-05-09
CVE-2006-5864 EXP Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to exec… Patch early 5.1 medium 15.2% 2006-11-11
CVE-2008-3790 EXP The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (C… Patch early 5.0 medium 15.2% 2008-08-27
CVE-2025-9090 EXP A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet S… Patch early 6.3 medium 15.2% 2025-08-17
CVE-2012-4409 EXP Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to execute ar… Patch early 6.8 medium 15.1% 2012-11-21
CVE-2017-8644 EXP Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that… Patch early 4.3 medium 15.1% 2017-08-08
CVE-2010-4645 EXP strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to… Patch early 5.0 medium 15.1% 2011-01-11
← previous page 37 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt