peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,436 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-2447 EXP SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafte… Patch early 5.1 medium 75.8% 2006-06-06
CVE-2004-2086 EXP Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (c… Patch early 5.0 medium 75.5% 2004-02-06
CVE-2001-0925 EXP The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP requ… Patch early 5.0 medium 75.2% 2001-03-12
CVE-2014-4977 EXP Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via the… Patch early 6.5 medium 74.9% 2014-07-16
CVE-2025-30208 EXP Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies acce… Patch early 5.3 medium 74.8% 2025-03-24
CVE-2018-17128 EXP A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode. Patch early 5.4 medium 74.8% 2018-09-17
CVE-2004-2466 EXP chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a… Patch early 5.0 medium 74.7% 2004-12-31
CVE-2004-1060 EXP Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network t… Patch early 5.0 medium 74.7% 2004-04-12
CVE-2023-5222 EXP A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the function isValidUser of the f… Patch early 6.3 medium 74.5% 2023-09-27
CVE-1999-0128 EXP Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death. Patch early 5.0 medium 74.5% 1996-12-18
CVE-2013-3336 EXP Unspecified vulnerability in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to read arbitrary files via unknown vectors. Patch early 5.0 medium 74.3% 2013-05-09
CVE-2005-2297 EXP Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a la… Patch early 4.6 medium 74.2% 2005-07-19
CVE-2017-5715 EXP Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an att… Patch early 5.6 medium 74% 2018-01-04
CVE-2019-10098 EXP In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newl… Patch early 6.1 medium 74% 2019-09-25
CVE-2011-0762 EXP The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption… Patch early 4.0 medium 73.9% 2011-03-02
CVE-2013-1814 EXP The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all… Patch early 4.0 medium 73.8% 2013-03-14
CVE-2005-2428 EXP Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows… Patch early 5.0 medium 73% 2005-08-03
CVE-2012-0394 EXP The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands… Patch early 6.8 medium 72.9% 2012-01-08
CVE-2008-6505 EXP Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary file… Patch early 5.0 medium 72.7% 2009-03-23
CVE-2004-0751 EXP The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a d… Patch early 5.0 medium 72.3% 2004-10-20
CVE-2006-7196 EXP Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through… Patch early 4.3 medium 72.2% 2007-05-10
CVE-2009-0478 EXP Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an inv… Patch early 5.0 medium 72% 2009-02-08
CVE-2010-2263 EXP nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary… Patch early 5.0 medium 71.9% 2010-06-15
CVE-1999-1551 EXP Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a lo… Patch early 5.0 medium 71.8% 1999-03-02
CVE-2021-39327 EXP The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~… Patch early 5.3 medium 71.7% 2021-09-17
CVE-2011-3011 EXP BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently… Patch early 5.0 medium 71.6% 2011-08-15
CVE-2019-19985 EXP The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclo… Patch early 5.3 medium 71.4% 2019-12-26
CVE-2006-0295 EXP Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code… Patch early 5.1 medium 71.3% 2006-02-02
CVE-2013-2641 EXP Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id pa… Patch early 5.0 medium 71% 2014-03-18
CVE-1999-0513 EXP ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service. Patch early 5.0 medium 70.9% 1998-01-05
← previous page 5 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt