peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,733 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-1245 EXP An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosu… Patch early 6.5 medium 12.9% 2019-09-11
CVE-2020-29395 EXP The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field. Patch early 6.1 medium 12.9% 2020-11-30
CVE-2011-2505 EXP libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns valu… Patch early 6.4 medium 12.9% 2011-07-14
CVE-2008-5587 EXP Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers… Patch early 4.3 medium 12.9% 2008-12-16
CVE-2003-1505 EXP Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a textarea in… Patch early 4.3 medium 12.9% 2003-12-31
CVE-2002-2073 EXP Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arb… Patch early 4.3 medium 12.9% 2002-12-31
CVE-2021-24926 EXP The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a… Patch early 6.1 medium 12.9% 2022-02-01
CVE-2012-2371 EXP Cross-site scripting (XSS) vulnerability in index.php in the WP-FaceThumb plugin 0.1 for WordPress allows remote attackers to inject arbitrary web scr… Patch early 4.3 medium 12.8% 2012-08-13
CVE-2005-0710 EXP MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restricti… Patch early 4.6 medium 12.8% 2005-05-02
CVE-2000-0156 EXP Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source R… Patch early 5.1 medium 12.8% 2000-02-16
CVE-1999-0281 EXP Denial of service in IIS using long URLs. Patch early 5.0 medium 12.8% 1997-06-01
CVE-2005-2629 EXP Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitr… Patch early 5.1 medium 12.8% 2005-11-18
CVE-2014-6043 EXP ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote a… Patch early 6.5 medium 12.8% 2014-09-11
CVE-2010-4156 EXP The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive inform… Patch early 5.0 medium 12.8% 2010-11-10
CVE-2015-2826 EXP WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information. Patch early 5.3 medium 12.8% 2017-09-20
CVE-2014-8498 EXP SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (… Patch early 6.5 medium 12.7% 2014-11-17
CVE-2005-1163 EXP Multiple buffer overflows in Yager 5.24 and earlier allow remote attackers to execute arbitrary code via (1) a crafted nickname or (2) a packet with a… Patch early 6.4 medium 12.7% 2005-05-02
CVE-2013-1601 EXP An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LIN… Patch early 5.3 medium 12.7% 2020-01-28
CVE-2007-6613 EXP Stack-based buffer overflow in the print_iso9660_recurse function in iso-info (src/iso-info.c) in GNU Compact Disc Input and Control Library (libcdio)… Patch early 5.0 medium 12.7% 2008-01-03
CVE-2011-1467 EXP Unspecified vulnerability in the NumberFormatter::setSymbol (aka numfmt_set_symbol) function in the Intl extension in PHP before 5.3.6 allows context-… Patch early 5.0 medium 12.7% 2011-03-20
CVE-2000-0655 EXP Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing… Patch early 5.0 medium 12.7% 2000-07-25
CVE-2006-0747 EXP Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file with an odd number of blue value… Patch early 5.0 medium 12.7% 2006-05-23
CVE-2006-2426 EXP Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 and earlier, and SDK 1.5.0_6 and earlier allows remote attackers to cause a denial… Patch early 6.4 medium 12.7% 2006-05-17
CVE-2009-2957 EXP Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to… Patch early 6.8 medium 12.7% 2009-09-02
CVE-2019-0948 EXP An information disclosure vulnerability exists in the Windows Event Viewer (eventvwr.msc) when it improperly parses XML input containing a reference t… Patch early 4.7 medium 12.7% 2019-06-12
CVE-2011-4107 EXP The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 a… Patch early 6.5 medium 12.7% 2011-11-17
CVE-2010-2094 EXP Multiple format string vulnerabilities in the phar extension in PHP 5.3 before 5.3.2 allow context-dependent attackers to obtain sensitive information… Patch early 6.8 medium 12.7% 2010-05-27
CVE-2009-0696 EXP The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a… Patch early 4.3 medium 12.6% 2009-07-29
CVE-2008-5692 EXP Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via… Patch early 5.0 medium 12.6% 2008-12-19
CVE-2009-1490 EXP Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrar… Patch early 5.0 medium 12.6% 2009-05-05
← previous page 43 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt