peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,058 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

169,925 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-1059 EXP Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute arbitrary PHP code by uploadi… Patch early 6.5 medium 5.4% 2015-01-16
CVE-2014-8391 EXP The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive information fr… Patch early 4.0 medium 5.4% 2015-06-02
CVE-2013-5573 EXP Cross-site scripting (XSS) vulnerability in the default markup formatter in Jenkins 1.523 allows remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 5.4% 2013-12-31
CVE-2004-2523 EXP Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to exe… Patch early 6.5 medium 5.4% 2004-12-31
CVE-2008-3303 EXP admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication and obtain administrative acces… Patch early 6.8 medium 5.4% 2008-07-25
CVE-2019-14339 EXP The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly restrict canon.ij.printer.capabil… Patch early 5.5 medium 5.4% 2019-09-05
CVE-2006-2465 EXP Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. NOTE: if mp3info is not installed setui… Patch early 5.1 medium 5.4% 2006-05-19
CVE-2011-4880 EXP Directory traversal vulnerability in the web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to read arbitrary file… Patch early 5.0 medium 5.4% 2012-04-13
CVE-2011-4074 EXP Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 5.4% 2011-11-02
CVE-2007-4517 EXP Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remote authenticated users to execute arbitrary code v… Patch early 6.0 medium 5.4% 2007-11-08
CVE-2007-6623 EXP Absolute path traversal vulnerability in ZeusCMS 0.3 and earlier might allow remote attackers to list arbitrary directories via a full pathname in the… Patch early 5.0 medium 5.4% 2008-01-04
CVE-2008-5266 EXP Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Applic… Patch early 4.3 medium 5.4% 2008-11-28
CVE-2002-0886 EXP Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a large… Patch early 5.0 medium 5.4% 2002-10-04
CVE-2022-22836 EXP CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request. Patch early 6.5 medium 5.4% 2022-01-10
CVE-2001-1064 EXP Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the route… Patch early 5.0 medium 5.4% 2001-08-31
CVE-2007-5410 EXP PHP remote file inclusion vulnerability in admin.wmtrssreader.php in the webmaster-tips.net Flash RSS Reader (com_wmtrssreader) 1.0 component for Joom… Patch early 6.8 medium 5.4% 2007-10-12
CVE-2004-2736 EXP Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cookie. Patch early 5.0 medium 5.4% 2004-12-31
CVE-2015-2678 EXP Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 5.4% 2015-03-23
CVE-2000-0278 EXP The SalesLogix Eviewer allows remote attackers to cause a denial of service by accessing the URL for the slxweb.dll administration program, which does… Patch early 5.0 medium 5.4% 2000-08-03
CVE-2009-0162 EXP Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7 and Windows allows remote att… Patch early 4.3 medium 5.4% 2009-05-13
CVE-2000-0212 EXP InterAccess TelnetD Server 4.0 allows remote attackers to conduct a denial of service via malformed terminal client configuration information. Patch early 5.0 medium 5.4% 2000-02-24
CVE-2000-0451 EXP The Intel express 8100 ISDN router allows remote attackers to cause a denial of service via oversized or fragmented ICMP packets. Patch early 5.0 medium 5.4% 2000-05-19
CVE-2006-1960 EXP Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express… Patch early 5.8 medium 5.3% 2006-04-21
CVE-2023-38357 EXP Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessions. Patch early 5.3 medium 5.3% 2023-08-01
CVE-2009-5112 EXP wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to obtain the installation path via a crafted request. Patch early 5.0 medium 5.3% 2012-03-19
CVE-2007-6615 EXP Directory traversal vulnerability in includes/block.php in Agares Media phpAutoVideo 2.21 allows remote attackers to include and execute arbitrary loc… Patch early 6.8 medium 5.3% 2008-01-03
CVE-2014-3110 EXP Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe c… Patch early 4.3 medium 5.3% 2014-07-24
CVE-2009-4092 EXP Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote attackers to hijack the authentica… Patch early 6.8 medium 5.3% 2009-11-29
CVE-2013-6627 EXP net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1xx) status codes, which allows… Patch early 5.0 medium 5.3% 2013-11-13
CVE-2007-5958 EXP X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program… Patch early 5.0 medium 5.3% 2008-01-18
← previous page 112 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt