peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,935 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-2535 EXP Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumpti… Patch early 5.0 medium 9.4% 2009-07-20
CVE-2019-14280 EXP In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so,… Patch early 5.3 medium 9.4% 2019-07-26
CVE-2001-0784 EXP Directory traversal vulnerability in Icecast 1.3.10 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack us… Patch early 5.0 medium 9.4% 2001-10-18
CVE-2009-3840 EXP The embedded database engine service (aka ovdbrun.exe) in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to cause a d… Patch early 5.0 medium 9.3% 2009-11-19
CVE-2010-0519 EXP Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (applicat… Patch early 6.8 medium 9.3% 2010-03-30
CVE-2001-0009 EXP Directory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack. Patch early 5.0 medium 9.3% 2001-02-12
CVE-2012-0298 EXP The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to (1) read or (2) delete arbitrar… Patch early 6.4 medium 9.3% 2012-05-21
CVE-2004-0129 EXP Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) seque… Patch early 5.0 medium 9.3% 2004-03-03
CVE-2006-6493 EXP Buffer overflow in the krbv4_ldap_auth function in servers/slapd/kerberos.c in OpenLDAP 2.4.3 and earlier, when OpenLDAP is compiled with the --enable… Patch early 5.1 medium 9.3% 2006-12-13
CVE-2011-5233 EXP Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pi… Patch early 4.3 medium 9.3% 2012-10-25
CVE-2018-9038 EXP Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request. Patch early 6.5 medium 9.3% 2018-04-10
CVE-2008-4682 EXP wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application abort) via a malformed Tamos CommView captu… Patch early 5.0 medium 9.3% 2008-10-22
CVE-2010-4301 EXP epan/dissectors/packet-zbee-zcl.c in the ZigBee ZCL dissector in Wireshark 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (i… Patch early 5.0 medium 9.3% 2010-11-26
CVE-2020-11457 EXP pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user. Patch early 5.4 medium 9.3% 2020-04-01
CVE-2012-4242 EXP Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or H… Patch early 4.3 medium 9.3% 2012-10-01
CVE-2008-4610 EXP MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2)… Patch early 5.0 medium 9.3% 2008-10-20
CVE-2000-1132 EXP DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed "forum" variable. Patch early 6.4 medium 9.3% 2001-01-09
CVE-2024-45440 EXP core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of… Patch early 5.3 medium 9.3% 2024-08-29
CVE-2007-6528 EXP Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) a… Patch early 5.0 medium 9.3% 2007-12-27
CVE-2008-0073 EXP Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code v… Patch early 6.8 medium 9.3% 2008-03-24
CVE-2024-12342 EXP A vulnerability was found in TP-Link VN020 F3v(T) TT_V6.2.1021. It has been rated as critical. This issue affects some unknown processing of the file… Patch early 6.5 medium 9.3% 2024-12-08
CVE-2004-2526 EXP Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .… Patch early 5.0 medium 9.3% 2004-12-31
CVE-2023-38501 EXP copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and… Patch early 6.3 medium 9.2% 2023-07-25
CVE-2002-0772 EXP Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories via a .. (d… Patch early 6.4 medium 9.2% 2002-08-12
CVE-2013-2287 EXP Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject ar… Patch early 4.3 medium 9.2% 2014-04-04
CVE-2007-1701 EXP PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deseria… Patch early 6.8 medium 9.2% 2007-03-27
CVE-2005-2006 EXP JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a "%." (percent dot), which rev… Patch early 5.0 medium 9.2% 2005-06-17
CVE-2002-1559 EXP Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (drive letter) or (2) .. (dot-do… Patch early 5.0 medium 9.2% 2003-03-31
CVE-2014-9225 EXP The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server… Patch early 4.0 medium 9.2% 2015-01-21
CVE-2009-1045 EXP requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of service (stack consumption and crash) via a long input argument in an i… Patch early 5.0 medium 9.2% 2009-03-23
← previous page 57 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt