peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,218 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-1999-0771 EXP The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack… Patch early 5.0 medium 6.2% 1999-05-26
CVE-2008-0852 EXP freeSSHd 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a SSH2_MSG_NEWKEYS packet to TCP port 22, which triggers a N… Patch early 5.0 medium 6.2% 2008-02-21
CVE-2008-2398 EXP Cross-site scripting (XSS) vulnerability in index.php in AppServ Open Project 2.5.10 and earlier allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 6.2% 2008-05-21
CVE-2012-2593 EXP Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web… Patch early 6.1 medium 6.2% 2020-02-06
CVE-2006-6624 EXP The FTP Server in Sambar Server 6.4 allows remote authenticated users to cause a denial of service (application crash) via a long series of "./" seque… Patch early 4.0 medium 6.2% 2006-12-18
CVE-2004-0312 EXP Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy strings via a qu… Patch early 6.4 medium 6.2% 2004-11-23
CVE-2012-2315 EXP admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authent… Patch early 4.0 medium 6.2% 2012-09-09
CVE-2007-5642 EXP Multiple directory traversal vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to include and execute arbitrary loca… Patch early 6.8 medium 6.2% 2007-10-23
CVE-2007-5837 EXP GUI.pm in yarssr 0.2.2, when Gnome default URL handling is disabled, allows remote attackers to execute arbitrary commands via shell metacharacters in… Patch early 6.8 medium 6.2% 2007-11-05
CVE-2009-4051 EXP Home FTP Server 1.10.1.139 allows remote attackers to cause a denial of service (daemon outage) via multiple invalid SITE INDEX commands. Patch early 5.0 medium 6.2% 2009-11-23
CVE-2009-1724 EXP Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touc… Patch early 4.3 medium 6.2% 2009-07-09
CVE-2007-4174 EXP Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify… Patch early 5.8 medium 6.2% 2007-08-07
CVE-2008-1480 EXP rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC request. Patch early 4.3 medium 6.2% 2008-03-24
CVE-2001-0421 EXP FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permiss… Patch early 6.4 medium 6.2% 2001-07-02
CVE-2000-0626 EXP Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request. Patch early 5.0 medium 6.2% 2000-07-18
CVE-2008-5932 EXP CodeAvalanche FreeForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download th… Patch early 5.0 medium 6.2% 2009-01-21
CVE-2008-6869 EXP Oramon Oracle Database Monitoring Tool 2.0.1 stores sensitive information under the web root with insufficient access control, which allows remote att… Patch early 5.0 medium 6.2% 2009-07-23
CVE-2000-0001 EXP RealMedia server allows remote attackers to cause a denial of service via a long ramgen request. Patch early 5.0 medium 6.2% 1999-12-23
CVE-2008-4907 EXP The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a d… Patch early 4.3 medium 6.2% 2008-11-04
CVE-2014-8603 EXP cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell… Patch early 6.5 medium 6.2% 2015-06-10
CVE-2008-1357 EXP Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used i… Patch early 5.4 medium 6.2% 2008-03-17
CVE-2003-1354 EXP Multiple GameSpy 3D 2.62 compatible gaming servers generate very large UDP responses to small requests, which allows remote attackers to use the serve… Patch early 5.0 medium 6.2% 2003-12-31
CVE-2003-1469 EXP The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the… Patch early 5.0 medium 6.2% 2003-12-31
CVE-2018-18762 EXP SaltOS 3.1 r8126 contains a database download vulnerability. Patch early 6.5 medium 6.2% 2019-03-21
CVE-2018-10371 EXP An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scripting vulnerability has been ident… Patch early 6.1 medium 6.2% 2018-05-01
CVE-2007-4638 EXP Blizzard Entertainment StarCraft Brood War 1.15.1 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed… Patch early 4.3 medium 6.2% 2007-08-31
CVE-2004-2750 EXP Directory traversal vulnerability in browser.php in JBrowser 1.0 through 2.1 allows remote attackers to read arbitrary files via the directory paramet… Patch early 5.0 medium 6.2% 2004-12-31
CVE-2017-15359 EXP In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/api/Recordi… Patch early 6.5 medium 6.2% 2017-10-18
CVE-2017-2367 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… Patch early 6.5 medium 6.2% 2017-04-02
CVE-2017-2442 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit JavaScr… Patch early 6.5 medium 6.2% 2017-04-02
← previous page 95 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt