peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,003 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-3039 EXP /usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated… Patch early 6.8 medium 8.6% 2010-11-09
CVE-2000-0977 EXP mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" paramet… Patch early 5.0 medium 8.6% 2000-12-19
CVE-2010-2307 EXP Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHP… Patch early 5.0 medium 8.6% 2010-06-16
CVE-2007-0817 EXP Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Ag… Patch early 4.3 medium 8.6% 2007-02-07
CVE-2005-4559 EXP mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly ini… Patch early 5.0 medium 8.6% 2005-12-28
CVE-2007-2482 EXP Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allo… Patch early 6.8 medium 8.6% 2007-05-03
CVE-2008-4323 EXP Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application crash) via a crafted .ZIP file. Patch early 4.3 medium 8.6% 2008-09-29
CVE-2016-3963 EXP Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 443. Patch early 5.3 medium 8.6% 2016-04-08
CVE-2011-1143 EXP epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (NULL pointer… Patch early 4.3 medium 8.6% 2011-03-03
CVE-2000-0508 EXP rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request. Patch early 5.0 medium 8.6% 1994-12-19
CVE-2006-4877 EXP Variable overwrite vulnerability in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to overwrite arbitrary program variables via… Patch early 5.0 medium 8.6% 2006-09-19
CVE-2007-6584 EXP Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot)… Patch early 6.4 medium 8.6% 2007-12-28
CVE-2010-3306 EXP Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%… Patch early 5.0 medium 8.6% 2010-09-24
CVE-2000-0906 EXP Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to read arbitrary files via a .. (d… Patch early 5.0 medium 8.6% 2000-12-19
CVE-2015-1482 EXP Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connecti… Patch early 5.0 medium 8.5% 2015-02-04
CVE-2002-2314 EXP Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which cause… Patch early 5.0 medium 8.5% 2002-12-31
CVE-2005-2455 EXP Greasemonkey before 0.3.5 allows remote web servers to (1) read arbitrary files via a GET request to a file:// URL in the GM_xmlhttpRequest API functi… Patch early 5.0 medium 8.5% 2005-08-04
CVE-2012-5329 EXP Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application crash) via a long string in an A… Patch early 4.0 medium 8.5% 2012-10-08
CVE-2001-0495 EXP Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack. Patch early 5.0 medium 8.5% 2001-06-27
CVE-2008-4409 EXP libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a de… Patch early 5.0 medium 8.5% 2008-10-03
CVE-2010-4617 EXP Directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers to read arbitrary files via dir… Patch early 6.8 medium 8.5% 2010-12-29
CVE-2009-4501 EXP The zbx_get_next_field function in libs/zbxcommon/str.c in Zabbix Server before 1.6.8 allows remote attackers to cause a denial of service (crash) via… Patch early 5.0 medium 8.5% 2009-12-31
CVE-2007-4976 EXP Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to in… Patch early 6.5 medium 8.5% 2007-09-19
CVE-2010-3203 EXP Directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot… Patch early 5.0 medium 8.5% 2010-09-03
CVE-2008-5715 EXP Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long string… Patch early 5.0 medium 8.5% 2008-12-24
CVE-2008-4558 EXP Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary code via an XSPF playlist file… Patch early 6.8 medium 8.5% 2008-10-15
CVE-2006-0891 EXP Multiple directory traversal vulnerabilities in NOCC Webmail 1.0 allow remote attackers to include arbitrary files via .. (dot dot) sequences and a tr… Patch early 5.0 medium 8.5% 2006-02-25
CVE-2007-4533 EXP Format string vulnerability in the Say command in sv_main.cpp in Vavoom 1.24 and earlier allows remote attackers to execute arbitrary code via format… Patch early 6.8 medium 8.5% 2007-08-25
CVE-2014-2880 EXP Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows rem… Patch early 5.8 medium 8.5% 2014-04-17
CVE-2007-1521 EXP Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the… Patch early 6.8 medium 8.5% 2007-03-20
← previous page 63 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt