peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,405 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

400,405 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-3591 EXP Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with an invalid location. Patch early 5.0 medium 52.8% 2009-10-08
CVE-2014-1903 EXP admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not… Patch early 7.5 high 52.8% 2014-02-18
CVE-2007-4921 EXP PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attackers to execute arbitrary PHP cod… Patch early 7.5 high 52.8% 2007-09-17
CVE-2018-8021 EXP Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. N… Patch early 9.8 critical 52.8% 2018-11-07
CVE-2000-0457 EXP ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) a… Patch early 7.5 high 52.8% 2000-05-11
CVE-2018-7286 EXP An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjs… Patch early 6.5 medium 52.7% 2018-02-22
CVE-2022-31470 EXP An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 a… Patch early 6.1 medium 52.7% 2022-06-07
CVE-2008-2370 EXP Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization befo… Patch early 5.0 medium 52.7% 2008-08-04
CVE-2012-5691 EXP Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via… Patch early 9.3 high 52.7% 2012-12-19
CVE-2022-31126 EXP Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauth… Patch early 10.0 critical 52.6% 2022-07-06
CVE-2008-0108 EXP Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005,… Patch early 9.3 high 52.6% 2008-02-12
CVE-2008-2549 EXP Adobe Acrobat Reader 8.1.2 and earlier, and before 7.1.1, allows remote attackers to cause a denial of service (application crash) and possibly execut… Patch early 4.3 medium 52.6% 2008-06-04
CVE-2003-1041 EXP Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing "… Patch early 7.5 high 52.6% 2004-06-14
CVE-2009-3958 EXP Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adob… Patch early 10.0 high 52.6% 2010-01-13
CVE-2014-5468 EXP A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG f… Patch early 8.8 high 52.6% 2020-02-07
CVE-2018-11686 EXP The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php. Patch early 9.8 critical 52.5% 2019-07-03
CVE-2017-8734 EXP Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of… Patch early 7.5 high 52.5% 2017-09-13
CVE-2010-1157 EXP Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a… Patch early 2.6 low 52.5% 2010-04-23
CVE-2012-5192 EXP Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to read arbitrary files via "''%2F"… Patch early 5.0 medium 52.5% 2014-01-28
CVE-2016-0710 EXP Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL com… Patch early 8.8 high 52.4% 2016-04-11
CVE-2022-35919 EXP MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all 'admin' users authorized fo… Patch early 7.4 high 52.3% 2022-08-01
CVE-2007-3898 EXP The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, wh… Patch early 6.4 medium 52.3% 2007-11-14
CVE-2017-5174 EXP An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerability has bee… Patch early 9.8 critical 52.3% 2017-05-19
CVE-2007-4620 EXP Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0, as used… Patch early 9.0 high 52.3% 2008-04-07
CVE-2019-11447 EXP An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the… Patch early 8.8 high 52.3% 2019-04-22
CVE-2012-4031 EXP Multiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote attackers to read arbitrary files via… Patch early 5.0 medium 52.3% 2012-07-17
CVE-2019-8953 EXP The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php… Patch early 6.1 medium 52.2% 2019-02-20
CVE-2012-0897 EXP Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (… Patch early 6.8 medium 52.2% 2012-01-20
CVE-2015-0925 EXP The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via a DLL pathname in a crafted Un… Patch early 9.0 high 52.2% 2015-01-22
CVE-2008-3013 EXP gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP… Patch early 9.3 high 52.1% 2008-09-11
← previous page 114 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt