peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,069 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

169,942 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-0241 EXP Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to a… Patch early 5.0 medium 4.9% 2012-02-21
CVE-2007-5300 EXP Off-by-one error in the do_login_loop function in libwzd-core/wzd_login.c in wzdftpd 0.8.0, 0.8.2, and possibly other versions allows remote attackers… Patch early 5.0 medium 4.9% 2007-10-09
CVE-2006-4553 EXP PHP remote file inclusion vulnerability in plugin.class.php in the com_comprofiler Components 1.0 RC2 for Mambo and Joomla! allows remote attackers to… Patch early 6.8 medium 4.9% 2006-09-06
CVE-2007-5229 EXP Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attackers to change settings and hi… Patch early 6.4 medium 4.9% 2007-10-05
CVE-2013-6114 EXP Integer overflow in the OZDocument::parseElement function in Apple Motion 5.0.7 allows remote attackers to cause a denial of service (application cras… Patch early 5.0 medium 4.9% 2013-11-04
CVE-2014-1695 EXP Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.1.x before 3.1.20, 3.2.x before 3.2.15, and 3.3.x before 3.3.5 allows… Patch early 4.3 medium 4.9% 2014-03-01
CVE-2008-5288 EXP PHP remote file inclusion vulnerability in include/header.php in Werner Hilversum FAQ Manager 1.2, when register_globals is enabled, allows remote att… Patch early 6.8 medium 4.9% 2008-12-01
CVE-1999-1171 EXP IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920. Patch early 4.6 medium 4.9% 1999-02-02
CVE-2007-1280 EXP Cross-site scripting (XSS) vulnerability in Adobe RoboHelp X5, 6, and Server 6 allows remote attackers to inject arbitrary web script or HTML via a UR… Patch early 4.3 medium 4.9% 2007-05-10
CVE-2015-2321 EXP Cross-site scripting (XSS) vulnerability in the Job Manager plugin 0.7.22 and earlier for WordPress allows remote attackers to inject arbitrary web sc… Patch early 4.3 medium 4.9% 2015-08-13
CVE-2008-4725 EXP Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web script or HTML via the query strin… Patch early 4.3 medium 4.9% 2008-10-23
CVE-2014-5347 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress allow remote attackers to hij… Patch early 6.8 medium 4.9% 2014-08-19
CVE-1999-0193 EXP Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option. Patch early 5.0 medium 4.9% 1997-12-01
CVE-2008-1974 EXP Cross-site scripting (XSS) vulnerability in addevent.php in Horde Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and Groupware 1.0.5 allows remote… Patch early 4.3 medium 4.9% 2008-04-27
CVE-2006-0625 EXP Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier allows remote attackers to read or include arbitrary files via ".." sequ… Patch early 6.4 medium 4.9% 2006-02-09
CVE-2009-2174 EXP GUPnP 0.12.7 allows remote attackers to cause a denial of service (crash) via an empty (1) subscription or (2) control message. Patch early 5.0 medium 4.9% 2009-06-23
CVE-2006-4608 EXP Multiple cross-site scripting (XSS) vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to inject arbitrary web script or HTML… Patch early 6.8 medium 4.9% 2006-09-07
CVE-2006-4794 EXP Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the query string (… Patch early 4.3 medium 4.9% 2006-09-14
CVE-2007-2576 EXP Buffer overflow in the East Wind Software advdaudio.ocx 1.5.1.1 ActiveX control allows user-assisted remote attackers to execute arbitrary code via a… Patch early 6.8 medium 4.9% 2007-05-09
CVE-2017-8490 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 4.9% 2017-06-15
CVE-2002-1060 EXP Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway 2.1.02, and… Patch early 4.3 medium 4.9% 2002-10-04
CVE-2013-4092 EXP The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent attackers to obtain sensitive inf… Patch early 5.0 medium 4.9% 2013-06-28
CVE-2005-1374 EXP Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to… Patch early 6.8 medium 4.9% 2005-05-03
CVE-2009-1469 EXP CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and WebMail Server before 9.4.2 makes… Patch early 4.3 medium 4.9% 2009-05-05
CVE-2006-1413 EXP Multiple cross-site scripting (XSS) vulnerabilities in EZHomepagePro 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 4.9% 2006-03-28
CVE-2015-8703 EXP ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authenticated users to bypass inten… Patch early 6.5 medium 4.9% 2015-12-30
CVE-2012-0869 EXP Cross-site scripting (XSS) vulnerability in fup in Frams' Fast File EXchange (F*EX, aka fex) before 20120215 allows remote attackers to inject arbitra… Patch early 4.3 medium 4.9% 2012-09-25
CVE-2014-1841 EXP Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to copy an arbitrary user's… Patch early 5.0 medium 4.9% 2014-04-29
CVE-2007-1563 EXP The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to connect to other servers, perfor… Patch early 6.8 medium 4.8% 2007-03-21
CVE-2005-4417 EXP The default configuration of Widcomm Bluetooth for Windows (BTW) 4.0.1.1500 and earlier, as installed on Belkin Bluetooth Software 1.4.2 Build 10 and… Patch early 6.4 medium 4.8% 2005-12-20
← previous page 120 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt