peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,483 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-2329 EXP Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of s… Patch early 5.0 medium 62.3% 2012-05-11
CVE-2006-4446 EXP Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to c… Patch early 5.0 medium 62.2% 2006-08-30
CVE-2012-2982 EXP file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as d… Patch early 6.5 medium 62.2% 2012-09-11
CVE-2006-4318 EXP Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands. Patch early 6.5 medium 62.1% 2006-08-24
CVE-2005-2120 EXP Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or loca… Patch early 6.5 medium 62% 2005-10-13
CVE-2005-0277 EXP Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execu… Patch early 5.0 medium 61.9% 2005-05-02
CVE-2007-1061 EXP SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote a… Patch early 6.8 medium 61.8% 2007-02-22
CVE-2007-3632 EXP Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a… Patch early 6.8 medium 61.5% 2007-07-10
CVE-2005-2087 EXP Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a… Patch early 5.0 medium 61.4% 2005-07-05
CVE-2013-1428 EXP Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated… Patch early 6.5 medium 60.7% 2013-04-26
CVE-2013-4074 EXP The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 in… Patch early 5.0 medium 60.6% 2013-06-09
CVE-2018-3639 EXP Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes… Patch early 5.5 medium 60.6% 2018-05-22
CVE-2006-5198 EXP The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers… Patch early 4.0 medium 60.4% 2006-11-14
CVE-2004-0184 EXP Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP pack… Patch early 5.0 medium 60.3% 2004-05-04
CVE-2015-8399 EXP Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdef… Patch early 4.3 medium 60.2% 2016-04-11
CVE-2010-2333 EXP LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a… Patch early 5.0 medium 60.2% 2010-06-18
CVE-2007-4744 EXP PHP remote file inclusion vulnerability in environment.php in AnyInventory 1.9.1 and 2.0, when register_globals is enabled, allows remote attackers to… Patch early 6.8 medium 60.1% 2007-09-06
CVE-2014-100002 EXP Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot… Patch early 5.0 medium 59.9% 2015-01-13
CVE-2013-3763 EXP Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to aff… Patch early 5.5 medium 59.8% 2013-07-17
CVE-2011-4404 EXP The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Up… Patch early 5.0 medium 59.7% 2011-11-19
CVE-2011-4317 EXP The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch i… Patch early 4.3 medium 59.6% 2011-11-30
CVE-2013-5880 EXP Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.0, 12.2.1, and 12.2.2 allows r… Patch early 5.0 medium 59.6% 2014-01-15
CVE-2013-7108 EXP Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote au… Patch early 5.5 medium 59.5% 2014-01-15
CVE-2013-5795 EXP Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 1… Patch early 5.0 medium 59.5% 2014-01-15
CVE-2007-3813 EXP PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitrary PHP c… Patch early 4.3 medium 59.4% 2007-07-17
CVE-2015-5603 EXP The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors,… Patch early 6.5 medium 59.3% 2015-09-21
CVE-2008-5081 EXP The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause… Patch early 5.0 medium 59.2% 2008-12-17
CVE-2018-8770 EXP Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, contr… Patch early 5.3 medium 59.2% 2018-03-18
CVE-2019-0221 EXP The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is,… Patch early 6.1 medium 59.2% 2019-05-28
CVE-2008-2463 EXP The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Offic… Patch early 6.8 medium 59.1% 2008-07-07
← previous page 8 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt