peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,810 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

25,086 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-3189 EXP The extSetOwner function in the UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll) in Trend Micro Internet Security Pro 2010 allows remote attackers to… Patch early 9.3 high 39.2% 2010-08-31
CVE-2003-1026 EXP Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added… Patch early 9.3 high 39.2% 2004-01-20
CVE-2008-1903 EXP PHP remote file inclusion vulnerability in news_show.php in Newanz NewsOffice 1.0 and 1.1, when register_globals is enabled, allows remote attackers t… Patch early 7.5 high 39.2% 2008-04-22
CVE-2008-5763 EXP PHP remote file inclusion vulnerability in slogin_lib.inc.php in Simple Text-File Login Script (SiTeFiLo) 1.0.6 allows remote attackers to execute arb… Patch early 7.5 high 39.2% 2008-12-30
CVE-2020-25494 EXP Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels paramete… Patch early 9.8 critical 39.2% 2020-12-18
CVE-2011-4786 EXP A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an arbitrary program… Patch early 9.3 high 39.2% 2012-01-12
CVE-2012-0439 EXP An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arb… Patch early 9.3 high 39.2% 2013-02-24
CVE-2006-1491 EXP Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitra… Patch early 7.5 high 39.2% 2006-03-29
CVE-2016-0108 EXP Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… Patch early 7.5 high 39.2% 2016-03-09
CVE-2004-1166 EXP CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via an… Patch early 7.5 high 39.2% 2004-12-31
CVE-2011-4825 EXP Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6… Patch early 7.5 high 39.2% 2011-12-15
CVE-2016-0063 EXP Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch early 8.8 high 39.1% 2016-02-10
CVE-2018-5262 EXP A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context… Patch early 9.8 critical 39.1% 2018-01-12
CVE-2013-1309 EXP Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that… Patch early 9.3 high 39.1% 2013-05-15
CVE-2023-32235 EXP Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory travers… Patch early 7.5 high 39.1% 2023-05-05
CVE-2006-4301 EXP Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attribute in multiple DirectX Media… Patch early 5.0 medium 39.1% 2006-08-23
CVE-2008-1963 EXP PHP remote file inclusion vulnerability in includes/functions.php in Quate Grape Web Statistics 0.2a allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 39% 2008-04-25
CVE-2008-2645 EXP Multiple PHP remote file inclusion vulnerabilities in Brim (formerly Booby) 1.0.1 allow remote attackers to execute arbitrary PHP code via a URL in th… Patch early 7.5 high 39% 2008-06-10
CVE-2017-0283 EXP Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1… Patch early 8.8 high 39% 2017-06-15
CVE-2008-1472 EXP Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5… Patch early 9.3 high 39% 2008-03-24
CVE-2018-12054 EXP Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absolute path traversal. Patch early 7.5 high 39% 2018-06-08
CVE-2021-35380 EXP A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious user gain a… Patch early 7.5 high 39% 2022-02-15
CVE-2003-1328 EXP The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to… Patch early 7.5 high 38.9% 2003-02-19
CVE-2015-0554 EXP The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6 does not properly restrict access to the web interfa… Patch early 9.4 high 38.9% 2015-01-21
CVE-2016-0121 EXP The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gol… Patch early 8.8 high 38.9% 2016-03-09
CVE-2018-1000094 EXP CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has… Patch early 7.2 high 38.8% 2018-03-13
CVE-2003-0161 EXP The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int ty… Patch early 10.0 high 38.8% 2003-04-02
CVE-2009-3641 EXP Snort before 2.8.5.1, when the -v option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted IPv6 packe… Patch early 4.3 medium 38.8% 2009-10-28
CVE-2020-5504 EXP In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of… Patch early 8.8 high 38.8% 2020-01-09
CVE-2005-2612 EXP Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[… Patch early 7.5 high 38.8% 2005-08-17
← previous page 92 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt