peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

206,641 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2000-0423 EXP Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd, and utag. Patch early 5.0 medium 7.8% 2000-05-05
CVE-2009-3242 EXP Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2.0 and 1.2.1 allows remote attackers to cause a denial of service (app… Patch early 5.0 medium 7.8% 2009-09-18
CVE-2018-12979 EXP An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions allow an authenticated user t… Patch early 6.5 medium 7.8% 2018-07-12
CVE-2000-0282 EXP TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webpl… Patch early 5.0 medium 7.8% 2000-04-12
CVE-2002-1432 EXP MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly r… Patch early 5.0 medium 7.8% 2003-04-11
CVE-2006-0714 EXP Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbitrary file… Patch early 5.0 medium 7.8% 2006-02-15
CVE-2009-5026 EXP The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave i… Patch early 6.8 medium 7.8% 2012-08-17
CVE-2003-1263 EXP ICAL.EXE in iCal 3.7 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, possibly due to an invalid method name… Patch early 5.0 medium 7.8% 2003-12-31
CVE-2005-1703 EXP Warrior Kings: Battles 1.23 and earlier allows remote attackers to cause a denial of service (server crash) via a partial join packet that triggers a… Patch early 5.0 medium 7.7% 2005-05-24
CVE-2024-39930 EXP The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attac… Patch early 9.9 critical 7.7% 2024-07-04
CVE-2008-4514 EXP The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a font tag with a long color value… Patch early 5.0 medium 7.7% 2008-10-09
CVE-2015-2169 EXP Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attackers to inject arbitrary web scri… Patch early 4.3 medium 7.7% 2015-06-24
CVE-2004-2507 EXP Absolute path traversal vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to read arbitrary files v… Patch early 5.0 medium 7.7% 2004-12-31
CVE-2011-4643 EXP Multiple directory traversal vulnerabilities in Splunk 4.x before 4.2.5 allow remote authenticated users to read arbitrary files via a .. (dot dot) in… Patch early 4.0 medium 7.7% 2012-01-03
CVE-2006-4850 EXP PHP remote file inclusion vulnerability in system/_b/contentFiles/gBIndex.php in BolinOS 4.5.5 and earlier allows remote attackers to execute arbitrar… Patch early 5.1 medium 7.7% 2006-09-19
CVE-2012-4889 EXP Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 7.7% 2012-09-10
CVE-2008-0767 EXP ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain "number of URLs" field is consistent with the… Patch early 5.0 medium 7.7% 2008-02-13
CVE-2008-3396 EXP Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via… Patch early 5.0 medium 7.7% 2008-07-31
CVE-2003-1386 EXP AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displ… Patch early 6.4 medium 7.7% 2003-12-31
CVE-2009-5134 EXP Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions before 1.8.3 (Build 16010), al… Patch early 6.8 medium 7.7% 2013-01-18
CVE-2017-0245 EXP The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1 and Windows Server 2012 Gold allow a local authenticated attacker to exec… Patch early 4.7 medium 7.7% 2017-05-12
CVE-2000-0452 EXP Buffer overflow in the ESMTP service of Lotus Domino Server 5.0.1 allows remote attackers to cause a denial of service via a long MAIL FROM command. Patch early 5.0 medium 7.7% 2000-05-18
CVE-1999-1016 EXP Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows… Patch early 5.0 medium 7.7% 1999-08-27
CVE-2002-0230 EXP Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cm… Patch early 5.0 medium 7.7% 2002-05-16
CVE-2020-14946 EXP downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and earlier allows users to downloa… Patch early 4.3 medium 7.7% 2020-06-22
CVE-2013-6674 EXP Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 a… Patch early 4.3 medium 7.7% 2014-02-17
CVE-2011-5129 EXP Heap-based buffer overflow in XChat 2.8.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code… Patch early 5.0 medium 7.7% 2012-08-30
CVE-2007-3725 EXP The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) before 0.91 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted… Patch early 4.3 medium 7.7% 2007-07-12
CVE-2000-0329 EXP A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka… Patch early 5.1 medium 7.7% 1999-11-11
CVE-2021-44665 EXP A Directory Traversal vulnerability exists in the Xerte Project Xerte through 3.10.3 when downloading a project file via download.php. Patch early 6.5 medium 7.7% 2022-02-24
← previous page 128 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt