peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,502 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

169,001 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-5222 EXP A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the function isValidUser of the f… Patch early 6.3 medium 74.5% 2023-09-27
CVE-1999-0128 EXP Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death. Patch early 5.0 medium 74.5% 1996-12-18
CVE-2013-3336 EXP Unspecified vulnerability in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to read arbitrary files via unknown vectors. Patch early 5.0 medium 74.3% 2013-05-09
CVE-2005-2297 EXP Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a la… Patch early 4.6 medium 74.2% 2005-07-19
CVE-2017-5715 EXP Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an att… Patch early 5.6 medium 74% 2018-01-04
CVE-2019-10098 EXP In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newl… Patch early 6.1 medium 74% 2019-09-25
CVE-2011-0762 EXP The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption… Patch early 4.0 medium 73.9% 2011-03-02
CVE-2013-1814 EXP The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all… Patch early 4.0 medium 73.8% 2013-03-14
CVE-2005-2428 EXP Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows… Patch early 5.0 medium 73% 2005-08-03
CVE-2012-0394 EXP The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands… Patch early 6.8 medium 72.9% 2012-01-08
CVE-2008-6505 EXP Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary file… Patch early 5.0 medium 72.7% 2009-03-23
CVE-2004-0751 EXP The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a d… Patch early 5.0 medium 72.3% 2004-10-20
CVE-2006-7196 EXP Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through… Patch early 4.3 medium 72.2% 2007-05-10
CVE-2009-0478 EXP Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an inv… Patch early 5.0 medium 72% 2009-02-08
CVE-2010-2263 EXP nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary… Patch early 5.0 medium 71.9% 2010-06-15
CVE-1999-1551 EXP Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a lo… Patch early 5.0 medium 71.8% 1999-03-02
CVE-2021-39327 EXP The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~… Patch early 5.3 medium 71.7% 2021-09-17
CVE-2011-3011 EXP BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently… Patch early 5.0 medium 71.6% 2011-08-15
CVE-2019-19985 EXP The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclo… Patch early 5.3 medium 71.4% 2019-12-26
CVE-2006-0295 EXP Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code… Patch early 5.1 medium 71.3% 2006-02-02
CVE-2013-2641 EXP Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id pa… Patch early 5.0 medium 71% 2014-03-18
CVE-1999-0513 EXP ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service. Patch early 5.0 medium 70.9% 1998-01-05
CVE-2014-5460 EXP Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execu… Patch early 6.5 medium 70.9% 2014-09-11
CVE-2020-11456 EXP LimeSurvey before 4.1.12+200324 has stored XSS in application/views/admin/surveysgroups/surveySettings.php and application/models/SurveysGroups.php (a… Patch early 5.4 medium 70.8% 2020-04-01
CVE-2007-3431 EXP PHP remote file inclusion vulnerability in cal.func.php in Valerio Capello Dagger - The Cutting Edge r23jan2007 allows remote attackers to execute arb… Patch early 6.8 medium 70.7% 2007-06-27
CVE-2006-6565 EXP FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST comman… Patch early 4.0 medium 70.6% 2006-12-15
CVE-2001-1243 EXP Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) crea… Patch early 5.0 medium 70.5% 2001-07-04
CVE-2003-0001 EXP Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information f… Patch early 5.0 medium 70.2% 2003-01-17
CVE-2019-1184 EXP An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improperly handles COM calls. An attacker who successfully… Patch early 6.7 medium 70.2% 2019-08-14
CVE-2008-0927 EXP dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request… Patch early 5.0 medium 70.1% 2008-04-14
← previous page 11 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt