peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,218 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

206,231 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-1586 EXP Open redirect vulnerability in red2301.html in HP System Management Homepage (SMH) 2.x.x.x allows remote attackers to redirect users to arbitrary web… Patch early 4.3 medium 10.3% 2010-04-28
CVE-2019-8661 EXP A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.6. A remote attacker may be able to ca… Patch early 9.8 critical 10.3% 2019-12-18
CVE-2002-0748 EXP LabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request that ends in two newline cha… Patch early 5.0 medium 10.3% 2002-08-12
CVE-2020-6519 EXP Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page. Patch early 6.5 medium 10.3% 2020-07-22
CVE-2019-15993 EXP A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information.… Patch early 5.3 medium 10.3% 2020-09-23
CVE-2013-1114 EXP Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unity Express before 8.0 allow remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 10.3% 2013-02-13
CVE-2021-25157 EXP A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.… Patch early 4.9 medium 10.3% 2021-03-30
CVE-2008-4500 EXP Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted stou com… Patch early 4.0 medium 10.3% 2008-10-09
CVE-2018-6228 EXP A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload an… Patch early 9.8 critical 10.2% 2018-03-15
CVE-2018-6229 EXP A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker to execute SQL commands to upl… Patch early 9.8 critical 10.2% 2018-03-15
CVE-2009-0922 EXP PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and cras… Patch early 4.0 medium 10.2% 2009-03-17
CVE-2012-6303 EXP Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows rem… Patch early 6.8 medium 10.2% 2013-10-28
CVE-2007-5301 EXP Buffer overflow in the vorbis_stream_info function in input/vorbis/vorbis_engine.c (aka the vorbis input plugin) in AlsaPlayer before 0.99.80-rc3 allo… Patch early 6.8 medium 10.2% 2007-10-09
CVE-2005-4718 EXP Opera 8.02 and earlier allows remote attackers to cause a denial of service (client crash) via (1) a crafted HTML file with a "content: url(0);" style… Patch early 5.0 medium 10.2% 2005-12-31
CVE-2012-0221 EXP The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does not… Patch early 5.0 medium 10.2% 2012-04-02
CVE-2012-2577 EXP Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inje… Patch early 4.3 medium 10.2% 2012-08-12
CVE-2013-4579 EXP The ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12 uses a BSSID masking approach… Patch early 4.3 medium 10.2% 2013-11-20
CVE-2013-6236 EXP IZON IP 2.0.2: hard-coded password vulnerability Patch early 9.8 critical 10.2% 2020-02-12
CVE-2013-0332 EXP Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x before 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in t… Patch early 5.0 medium 10.2% 2013-03-20
CVE-2006-1931 EXP The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a lar… Patch early 5.0 medium 10.2% 2006-04-20
CVE-2005-1280 EXP The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of… Patch early 5.0 medium 10.2% 2005-05-02
CVE-2009-4490 EXP mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title,… Patch early 5.0 medium 10.2% 2010-01-13
CVE-2008-4582 EXP Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify t… Patch early 4.3 medium 10.2% 2008-10-15
CVE-2009-0819 EXP sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XP… Patch early 4.0 medium 10.2% 2009-03-05
CVE-2011-1398 EXP The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return charac… Patch early 4.3 medium 10.2% 2012-08-30
CVE-2025-10327 EXP A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdoc… Patch early 6.3 medium 10.2% 2025-09-12
CVE-2010-1307 EXP Directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers to read arbitrary files via a… Patch early 5.0 medium 10.2% 2010-04-08
CVE-2015-7247 EXP D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and… Patch early 9.8 critical 10.2% 2017-04-24
CVE-2019-12922 EXP A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page. Patch early 6.5 medium 10.1% 2019-09-13
CVE-2008-1035 EXP Use-after-free vulnerability in Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to trigger memory corru… Patch early 4.3 medium 10.1% 2008-06-03
← previous page 105 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt