peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,903 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-1280 EXP The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of… Patch early 5.0 medium 10.2% 2005-05-02
CVE-2008-4582 EXP Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify t… Patch early 4.3 medium 10.2% 2008-10-15
CVE-2009-0819 EXP sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XP… Patch early 4.0 medium 10.2% 2009-03-05
CVE-2011-1398 EXP The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return charac… Patch early 4.3 medium 10.2% 2012-08-30
CVE-2025-10327 EXP A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdoc… Patch early 6.3 medium 10.2% 2025-09-12
CVE-2010-1307 EXP Directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers to read arbitrary files via a… Patch early 5.0 medium 10.2% 2010-04-08
CVE-2019-12922 EXP A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page. Patch early 6.5 medium 10.1% 2019-09-13
CVE-2008-1035 EXP Use-after-free vulnerability in Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to trigger memory corru… Patch early 4.3 medium 10.1% 2008-06-03
CVE-2013-3969 EXP The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitializ… Patch early 6.5 medium 10.1% 2013-10-01
CVE-2009-0756 EXP The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that… Patch early 5.0 medium 10.1% 2009-03-03
CVE-2011-4618 EXP Cross-site scripting (XSS) vulnerability in advancedtext.php in Advanced Text Widget plugin before 2.0.2 for WordPress allows remote attackers to inje… Patch early 4.3 medium 10.1% 2013-01-24
CVE-2007-4722 EXP Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie07051001.dll 1.0.0.1 in Move Media Pl… Patch early 6.8 medium 10.1% 2007-09-05
CVE-2009-3305 EXP Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that… Patch early 5.0 medium 10.1% 2009-12-24
CVE-2011-2522 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attacke… Patch early 6.8 medium 10% 2011-07-29
CVE-2010-0682 EXP WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter. Patch early 4.0 medium 10% 2010-02-23
CVE-2005-0989 EXP The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attacker… Patch early 5.0 medium 10% 2005-05-02
CVE-2018-20523 EXP Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a t… Patch early 5.3 medium 10% 2019-06-07
CVE-2006-2460 EXP Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESS… Patch early 6.4 medium 10% 2006-05-19
CVE-2018-19042 EXP The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters o… Patch early 5.3 medium 10% 2019-01-31
CVE-2018-19043 EXP The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename) via a ../ directory traversal… Patch early 5.3 medium 10% 2019-01-31
CVE-2000-0213 EXP The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacha… Patch early 5.0 medium 10% 2000-02-23
CVE-2021-34370 EXP Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags an… Patch early 6.1 medium 10% 2021-06-09
CVE-2007-2807 EXP Stack-based buffer overflow in mod/server.mod/servrmsg.c in Eggdrop 1.6.18, and possibly earlier, allows user-assisted, remote IRC servers to execute… Patch early 6.8 medium 10% 2007-05-22
CVE-2006-4019 EXP Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variabl… Patch early 6.4 medium 10% 2006-08-11
CVE-2010-2939 EXP Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and possibly ot… Patch early 4.3 medium 10% 2010-08-17
CVE-2021-33904 EXP In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are conf… Patch early 6.1 medium 10% 2021-06-07
CVE-2012-4552 EXP Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute arbitrary code via a crafted 3… Patch early 6.8 medium 10% 2012-11-18
CVE-2011-5265 EXP Cross-site scripting (XSS) vulnerability in cached_image.php in the Featurific For WordPress plugin 1.6.2 for WordPress allows remote attackers to inj… Patch early 4.3 medium 10% 2013-02-12
CVE-2013-0238 EXP The try_parse_v4_netmask function in hostmask.c in IRCD-Hybrid before 8.0.6 does not properly validate masks, which allows remote attackers to cause a… Patch early 5.0 medium 10% 2013-02-13
CVE-2012-1617 EXP Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbitrary files via a .. (dot dot)… Patch early 6.4 medium 9.9% 2012-09-26
← previous page 53 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt