peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,074 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

169,946 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-7026 EXP Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary co… Patch early 6.8 medium 4.7% 2009-08-21
CVE-2009-1873 EXP Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4 Updater 7 allows remote authen… Patch early 4.0 medium 4.7% 2009-08-18
CVE-2009-1294 EXP Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remo… Patch early 4.3 medium 4.7% 2009-04-16
CVE-2022-34140 EXP A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts… Patch early 5.4 medium 4.7% 2022-07-28
CVE-2002-2195 EXP Buffer overflow in the version update check for Winamp 2.80 and earlier allows remote attackers who can spoof www.winamp.com to execute arbitrary code… Patch early 5.0 medium 4.7% 2002-12-31
CVE-2015-4010 EXP Cross-site request forgery (CSRF) vulnerability in the Encrypted Contact Form plugin before 1.1 for WordPress allows remote attackers to hijack the au… Patch early 6.8 medium 4.7% 2015-06-09
CVE-2010-2314 EXP PHP remote file inclusion vulnerability in nucleus/plugins/NP_Twitter.php in the NP_Twitter Plugin 0.8 and 0.9 for Nucleus, when register_globals is e… Patch early 6.8 medium 4.7% 2010-06-17
CVE-2002-1334 EXP Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other use… Patch early 6.8 medium 4.7% 2002-12-11
CVE-2000-0740 EXP Buffer overflow in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary commands via a long… Patch early 5.0 medium 4.7% 2000-10-20
CVE-2015-8723 EXP The AirPDcapPacketProcess function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not… Patch early 5.5 medium 4.7% 2016-01-04
CVE-2006-1593 EXP The (1) ZD_MissingPlayer, (2) ZD_UseItem, and (3) ZD_LoadNewClientLevel functions in sv_main.cpp for (a) Zdaemon 1.08.01 and (b) X-Doom allows remote… Patch early 5.0 medium 4.7% 2006-04-03
CVE-2021-24247 EXP The Contact Form Check Tester WordPress plugin through 1.0.2 settings are visible to all registered users in the dashboard and are lacking any sanitis… Patch early 5.4 medium 4.7% 2021-05-06
CVE-2013-2618 EXP Cross-site scripting (XSS) vulnerability in editor.php in Network Weathermap before 0.97b allows remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 4.7% 2014-06-05
CVE-2012-2331 EXP Cross-site scripting (XSS) vulnerability in serendipity/serendipity_admin_image_selector.php in Serendipity before 1.6.1 allows remote attackers to in… Patch early 4.3 medium 4.7% 2012-08-13
CVE-2010-1458 EXP Stack-based buffer overflow in Create and Extract Zips TweakFS Zip Utility 1.0 for Flight Simulator X (FSX) allows remote attackers to execute arbitra… Patch early 6.8 medium 4.7% 2010-04-20
CVE-2011-0887 EXP The web management portal on the SMC SMCD3G-CCR (aka Comcast Business Gateway) with firmware before 1.4.0.49.2 uses predictable session IDs based on t… Patch early 4.3 medium 4.7% 2011-02-08
CVE-2014-1843 EXP Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to obtain the property info… Patch early 5.0 medium 4.7% 2014-04-29
CVE-2009-1030 EXP Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allow… Patch early 4.3 medium 4.7% 2009-03-20
CVE-2019-10846 EXP Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via the usernam… Patch early 6.1 medium 4.7% 2019-05-23
CVE-2011-0740 EXP Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in RSS Feed Reader 0.1 for WordPress allows remote attackers to inject… Patch early 4.3 medium 4.7% 2011-02-02
CVE-2005-2295 EXP NetPanzer 0.8 and earlier allows remote attackers to cause a denial of service (infinite loop) via a packet with a zero datablock size. Patch early 5.0 medium 4.7% 2005-07-18
CVE-2006-1046 EXP server.cpp in Monopd 0.9.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a string containing a large number of… Patch early 5.0 medium 4.7% 2006-03-07
CVE-2006-2575 EXP The setFrame function in Lib/2D/Surface.hpp for NetPanzer 0.8 and earlier allows remote attackers to cause a denial of service (crash) via a client fl… Patch early 5.0 medium 4.7% 2006-05-24
CVE-2007-1717 EXP The mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 truncates e-mail messages at the first ASCIIZ ('\0') byte, which might allow cont… Patch early 5.0 medium 4.7% 2007-03-28
CVE-1999-0905 EXP Denial of service in Axent Raptor firewall via malformed zero-length IP options. Patch early 5.0 medium 4.6% 1999-10-21
CVE-2007-4489 EXP Buffer overflow in the IUAComFormX ActiveX control in uacomx.ocx 2.0.1 in the eCentrex VOIP Client module allows remote attackers to execute arbitrary… Patch early 6.8 medium 4.6% 2007-08-22
CVE-2011-2732 EXP CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 allows remote atta… Patch early 4.3 medium 4.6% 2012-12-05
CVE-2010-4348 EXP Cross-site scripting (XSS) vulnerability in admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to inject arbitrary web scri… Patch early 4.3 medium 4.6% 2011-01-03
CVE-2008-3708 EXP Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter t… Patch early 4.3 medium 4.6% 2008-08-19
CVE-2013-1662 EXP vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host… Patch early 6.9 medium 4.6% 2013-08-24
← previous page 124 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt