peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,503 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

169,001 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-2087 EXP Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a… Patch early 5.0 medium 61.4% 2005-07-05
CVE-2013-1428 EXP Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated… Patch early 6.5 medium 60.7% 2013-04-26
CVE-2013-4074 EXP The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 in… Patch early 5.0 medium 60.6% 2013-06-09
CVE-2018-3639 EXP Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes… Patch early 5.5 medium 60.6% 2018-05-22
CVE-2006-5198 EXP The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers… Patch early 4.0 medium 60.4% 2006-11-14
CVE-2004-0184 EXP Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP pack… Patch early 5.0 medium 60.3% 2004-05-04
CVE-2015-8399 EXP Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdef… Patch early 4.3 medium 60.2% 2016-04-11
CVE-2010-2333 EXP LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a… Patch early 5.0 medium 60.2% 2010-06-18
CVE-2007-4744 EXP PHP remote file inclusion vulnerability in environment.php in AnyInventory 1.9.1 and 2.0, when register_globals is enabled, allows remote attackers to… Patch early 6.8 medium 60.1% 2007-09-06
CVE-2014-100002 EXP Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot… Patch early 5.0 medium 59.9% 2015-01-13
CVE-2013-3763 EXP Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to aff… Patch early 5.5 medium 59.8% 2013-07-17
CVE-2011-4404 EXP The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Up… Patch early 5.0 medium 59.7% 2011-11-19
CVE-2011-4317 EXP The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch i… Patch early 4.3 medium 59.6% 2011-11-30
CVE-2013-5880 EXP Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.0, 12.2.1, and 12.2.2 allows r… Patch early 5.0 medium 59.6% 2014-01-15
CVE-2013-7108 EXP Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote au… Patch early 5.5 medium 59.5% 2014-01-15
CVE-2013-5795 EXP Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 1… Patch early 5.0 medium 59.5% 2014-01-15
CVE-2007-3813 EXP PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitrary PHP c… Patch early 4.3 medium 59.4% 2007-07-17
CVE-2015-5603 EXP The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors,… Patch early 6.5 medium 59.3% 2015-09-21
CVE-2008-5081 EXP The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause… Patch early 5.0 medium 59.2% 2008-12-17
CVE-2018-8770 EXP Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, contr… Patch early 5.3 medium 59.2% 2018-03-18
CVE-2019-0221 EXP The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is,… Patch early 6.1 medium 59.2% 2019-05-28
CVE-2008-2463 EXP The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Offic… Patch early 6.8 medium 59.1% 2008-07-07
CVE-2007-3386 EXP Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to… Patch early 4.3 medium 59% 2007-08-14
CVE-2008-0506 EXP include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows… Patch early 6.8 medium 58.9% 2008-01-31
CVE-2000-0574 EXP FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle… Patch early 5.0 medium 58.9% 2000-07-07
CVE-2006-2212 EXP Buffer overflow in KarjaSoft Sami FTP Server 2.0.2 and earlier allows remote attackers to execute arbitrary code via a long (1) USER or (2) PASS comma… Patch early 6.4 medium 58.9% 2006-05-05
CVE-2012-4347 EXP Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated users to r… Patch early 5.0 medium 58.8% 2012-12-05
CVE-2013-1559 EXP Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated… Patch early 4.0 medium 58.8% 2013-04-17
CVE-2002-0654 EXP Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .v… Patch early 5.0 medium 58.7% 2002-09-05
CVE-2004-1305 EXP The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers… Patch early 5.0 medium 58.6% 2004-12-23
← previous page 14 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt