peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,071 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

169,944 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-2748 EXP viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid pr… Patch early 4.3 medium 4.8% 2004-12-31
CVE-2009-2852 EXP WP-Syntax plugin 0.9.1 and earlier for Wordpress, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via the test_fi… Patch early 6.8 medium 4.8% 2009-08-18
CVE-2010-2349 EXP H264WebCam 3.7 allows remote attackers to cause a denial of service (crash) via a long URI in a GET request, which triggers a NULL pointer dereference… Patch early 5.0 medium 4.8% 2010-06-21
CVE-2018-9163 EXP A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users… Patch early 5.4 medium 4.8% 2018-04-02
CVE-2008-6995 EXP Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a denial of service (browser crash)… Patch early 4.3 medium 4.8% 2009-08-19
CVE-2019-9622 EXP eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as demonstrated by reading the use… Patch early 4.3 medium 4.8% 2019-03-07
CVE-1999-0751 EXP Buffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch. Patch early 5.0 medium 4.8% 1999-09-13
CVE-2017-0299 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 4.8% 2017-06-15
CVE-2012-0834 EXP Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web scri… Patch early 4.3 medium 4.8% 2012-02-11
CVE-2008-0661 EXP Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file with a long URI. NOTE: this mig… Patch early 6.8 medium 4.8% 2008-02-08
CVE-2010-3003 EXP Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote attackers to inject arbitrary… Patch early 4.3 medium 4.8% 2010-09-10
CVE-2011-3579 EXP server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly send HTTP req… Patch early 6.4 medium 4.8% 2011-09-30
CVE-2020-28413 EXP In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP. Patch early 5.3 medium 4.8% 2020-12-30
CVE-2017-13855 EXP An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchO… Patch early 5.5 medium 4.8% 2017-12-25
CVE-2008-0138 EXP PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows… Patch early 6.8 medium 4.8% 2008-01-08
CVE-2005-3959 EXP Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0 rev37 allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 4.3 medium 4.8% 2005-12-01
CVE-2004-2334 EXP Multiple cross-site scripting (XSS) vulnerabilities in EMU Webmail 5.2.7 allow remote attackers to inject arbitrary web script or HTML via (1) a hex-e… Patch early 4.3 medium 4.8% 2004-12-31
CVE-2007-5692 EXP Multiple cross-site scripting (XSS) vulnerabilities in SiteBar 3.3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the lang pa… Patch early 4.3 medium 4.8% 2007-10-29
CVE-2006-3883 EXP Multiple cross-site scripting (XSS) vulnerabilities in Gonafish LinksCaffe 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) t… Patch early 4.3 medium 4.8% 2006-07-27
CVE-2011-4273 EXP Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary web script or HTML via (1) th… Patch early 4.3 medium 4.8% 2011-11-03
CVE-2007-4257 EXP Multiple buffer overflows in Live for Speed (LFS) S1 and S2 allow user-assisted remote attackers to execute arbitrary code via (1) a .spr file (single… Patch early 6.8 medium 4.8% 2007-08-08
CVE-2019-7439 EXP cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter. Patch early 6.5 medium 4.8% 2019-03-21
CVE-2009-4086 EXP CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response sp… Patch early 5.0 medium 4.8% 2009-11-29
CVE-2006-3325 EXP client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious servers t… Patch early 5.0 medium 4.8% 2006-06-30
CVE-2008-2542 EXP Stack-based buffer overflow in the getline function in Ppm/ppm.C in NASA Ames Research Center BigView 1.8 allows user-assisted remote attackers to exe… Patch early 6.8 medium 4.8% 2008-06-05
CVE-2003-0038 EXP Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) ema… Patch early 4.3 medium 4.8% 2003-02-07
CVE-2007-4980 EXP The readRequest method in org/gcaldaemon/core/http/HTTPListener.java in GCALDaemon 1.0-beta13 allows remote attackers to cause a denial of service via… Patch early 4.3 medium 4.8% 2007-09-19
CVE-2006-4956 EXP Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote attackers to inject arbitrary we… Patch early 6.8 medium 4.8% 2006-09-23
CVE-2018-18774 EXP CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter. Patch early 6.1 medium 4.8% 2018-11-20
CVE-2006-1654 EXP Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows re… Patch early 5.0 medium 4.8% 2006-04-06
← previous page 122 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt