peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,074 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

169,946 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-1063 EXP Buffer overflow in eXeScope 6.50 allows user-assisted remote attackers to execute arbitrary code via a crafted executable (.exe) file. Patch early 6.8 medium 4.7% 2009-03-26
CVE-2017-9978 EXP On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on… Patch early 5.3 medium 4.7% 2017-08-28
CVE-2009-2654 EXP Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a… Patch early 5.8 medium 4.7% 2009-08-03
CVE-2007-1264 EXP Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail from visually distinguishing b… Patch early 5.0 medium 4.7% 2007-03-06
CVE-2013-5220 EXP goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted HTTP POST d… Patch early 6.1 medium 4.7% 2013-12-30
CVE-2010-0440 EXP Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA… Patch early 4.3 medium 4.7% 2010-02-03
CVE-2010-4821 EXP Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to… Patch early 4.3 medium 4.7% 2012-10-22
CVE-2010-1947 EXP Directory traversal vulnerability in scr/soustab.php in openMairie Openregistrecil 1.02, when register_globals is enabled, allows remote attackers to… Patch early 6.8 medium 4.7% 2010-05-19
CVE-2006-3103 EXP Cross-site scripting (XSS) vulnerability in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error parameter i… Patch early 4.3 medium 4.7% 2006-06-21
CVE-2017-13869 EXP An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchO… Patch early 5.5 medium 4.7% 2017-12-25
CVE-2005-4467 EXP Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrary files vi… Patch early 5.0 medium 4.7% 2005-12-22
CVE-2012-1904 EXP mp4fformat.dll in the QuickTime File Format plugin in RealNetworks RealPlayer 15 and earlier, and RealPlayer SP 1.1.4 Build 12.0.0.756 and earlier, al… Patch early 4.3 medium 4.7% 2012-03-28
CVE-2004-1569 EXP Buffer overflow in (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe in dBpowerAMP Audio Player 2.0 and dbPowerAmp Music Converter 10.0 allows… Patch early 4.0 medium 4.7% 2004-12-31
CVE-2004-2564 EXP Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, allow remote attacke… Patch early 4.3 medium 4.7% 2004-12-31
CVE-2008-6806 EXP Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and earlier allows remote attackers to execute arbitrary code by uploa… Patch early 6.8 medium 4.7% 2009-05-12
CVE-2015-8728 EXP The Mobile Identity parser in (1) epan/dissectors/packet-ansi_a.c in the ANSI A dissector and (2) epan/dissectors/packet-gsm_a_common.c in the GSM A d… Patch early 5.5 medium 4.7% 2016-01-04
CVE-2006-0660 EXP Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary files or trigger an error mess… Patch early 6.4 medium 4.7% 2006-02-13
CVE-2010-1186 EXP Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inje… Patch early 4.3 medium 4.7% 2010-04-07
CVE-2023-33383 EXP Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a device reload… Patch early 5.3 medium 4.7% 2023-08-02
CVE-2002-1079 EXP Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in a… Patch early 5.0 medium 4.7% 2002-10-04
CVE-2005-0253 EXP Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to delete arbitrary files via… Patch early 4.0 medium 4.7% 2005-05-02
CVE-2008-4584 EXP Insecure method vulnerability in Chilkat Mail 7.8 ActiveX control (ChilkatCert.dll) allows remote attackers to overwrite arbitrary files via a full pa… Patch early 6.8 medium 4.7% 2008-10-15
CVE-2011-3607 EXP Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_set… Patch early 4.4 medium 4.7% 2011-11-08
CVE-2006-7080 EXP Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".."… Patch early 4.3 medium 4.7% 2007-03-02
CVE-2007-4537 EXP Heap-based buffer overflow in the Huffman decompression algorithm implemented in Skulltag 0.97d-beta4.1 and earlier allows remote attackers to execute… Patch early 6.8 medium 4.7% 2007-08-27
CVE-2007-2980 EXP Heap-based buffer overflow in a certain ActiveX control in LEADTOOLS LEAD Raster ISIS Object (LTRIS14e.DLL) 14.5.0.44 allows remote attackers to cause… Patch early 6.8 medium 4.7% 2007-06-01
CVE-2017-13868 EXP An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchO… Patch early 5.5 medium 4.7% 2017-12-25
CVE-2014-4962 EXP Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantity parame… Patch early 6.4 medium 4.7% 2014-07-15
CVE-2006-1102 EXP Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (client exit) by forcing the server to c… Patch early 5.0 medium 4.7% 2006-03-09
CVE-2019-10226 EXP HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI. NOTE: the ven… Patch early 5.4 medium 4.7% 2019-06-10
← previous page 123 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt