peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,436 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-28164 EXP In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to ac… Patch early 5.3 medium 82.4% 2021-04-01
CVE-2009-2521 EXP Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users… Patch early 5.0 medium 82.3% 2009-09-04
CVE-2014-9016 EXP The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote… Patch early 5.0 medium 82.2% 2014-11-24
CVE-2012-0053 EXP protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) e… Patch early 4.3 medium 82.2% 2012-01-28
CVE-2017-0038 EXP gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S… Patch early 5.5 medium 82.1% 2017-02-20
CVE-2019-10092 EXP In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the… Patch early 6.1 medium 81.5% 2019-09-26
CVE-2013-4212 EXP Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via… Patch early 6.8 medium 81.1% 2013-12-07
CVE-2007-6203 EXP Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request… Patch early 4.3 medium 80.7% 2007-12-03
CVE-2013-4123 EXP client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port num… Patch early 5.0 medium 80.5% 2013-09-16
CVE-2004-0230 EXP TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to… Patch early 5.0 medium 80.3% 2004-08-18
CVE-2009-1386 EXP ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS Chan… Patch early 5.0 medium 80.1% 2009-06-04
CVE-2004-0790 EXP Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages,… Patch early 5.0 medium 80.1% 2005-04-12
CVE-2000-0246 EXP IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to… Patch early 5.0 medium 80% 2000-03-30
CVE-2016-0491 EXP Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows rem… Patch early 6.4 medium 79.9% 2016-01-21
CVE-2011-4858 EXP Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trig… Patch early 5.0 medium 79.7% 2012-01-05
CVE-2023-2745 EXP WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated at… Patch early 5.4 medium 79.5% 2023-05-17
CVE-2014-6034 EXP Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in ZOHO ManageEngine OpManager 8.8… Patch early 5.0 medium 79% 2014-12-04
CVE-2019-1622 EXP A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to r… Patch early 5.3 medium 78.9% 2019-06-27
CVE-2000-0302 EXP Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument t… Patch early 5.0 medium 78.6% 2000-03-31
CVE-2006-3392 EXP Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary fi… Patch early 5.0 medium 78.3% 2006-07-06
CVE-2010-1587 EXP The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash s… Patch early 5.0 medium 78% 2010-04-28
CVE-2007-2449 EXP Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 t… Patch early 4.3 medium 77.4% 2007-06-14
CVE-2024-23334 EXP aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it i… Patch early 5.9 medium 76.9% 2024-01-29
CVE-2003-0190 EXP OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows re… Patch early 5.0 medium 76.8% 2003-05-12
CVE-2017-9554 EXP An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumera… Patch early 5.3 medium 76.7% 2017-07-24
CVE-2005-3081 EXP wzdftpd 0.5.4 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the SITE command. Patch early 4.6 medium 76.6% 2005-09-27
CVE-2022-44267 EXP ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for… Patch early 6.5 medium 76.6% 2023-02-06
CVE-2010-2156 EXP ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID. Patch early 5.0 medium 76.4% 2010-06-07
CVE-2021-22145 EXP A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary querie… Patch early 6.5 medium 76.2% 2021-07-21
CVE-2008-1232 EXP Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers… Patch early 4.3 medium 75.9% 2008-08-04
← previous page 4 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt