peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,092 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

319,698 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-6825 EXP Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to include and execute arbitrary… Patch early 6.8 medium 20.3% 2009-06-05
CVE-2014-1815 EXP Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch early 9.3 high 20.3% 2014-05-14
CVE-2005-1381 EXP Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) ca… Patch early 6.8 medium 20.2% 2005-05-03
CVE-2010-1039 EXP Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.3… Patch early 10.0 high 20.2% 2010-05-20
CVE-2004-0502 EXP Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the original message,… Patch early 5.0 medium 20.2% 2004-08-18
CVE-2005-3559 EXP Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) in… Patch early 5.0 medium 20.2% 2005-11-16
CVE-2019-0573 EXP An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Ser… Patch early 7.8 high 20.1% 2019-01-08
CVE-2006-3124 EXP Buffer overflow in the HTTP header parsing in Streamripper before 1.61.26 allows remote attackers to cause a denial of service and possibly execute ar… Patch early 7.5 high 20.1% 2006-08-26
CVE-2006-4138 EXP Multiple unspecified vulnerabilities in Microsoft Windows Help File viewer (winhlp32.exe) allow user-assisted attackers to execute arbitrary code via… Patch early 7.6 high 20.1% 2006-08-14
CVE-2011-1271 EXP The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not properly handle expressi… Patch early 7.7 high 20.1% 2011-05-10
CVE-2012-3456 EXP Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and ea… Patch early 7.5 high 20.1% 2012-08-20
CVE-2004-0213 EXP Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system… Patch early 7.8 high 20.1% 2004-08-06
CVE-2018-12589 EXP Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in the current working directory. Patch early 7.8 high 20.1% 2018-06-28
CVE-2010-3187 EXP Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command. Patch early 10.0 high 20% 2010-08-30
CVE-2006-6652 EXP Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple Mac OS X… Patch early 9.0 high 20% 2006-12-20
CVE-2009-4462 EXP Stack-based buffer overflow in the NetBiterConfig utility (NetBiterConfig.exe) 1.3.0 for Intellicom NetBiter WebSCADA allows remote attackers to execu… Patch early 10.0 high 20% 2009-12-30
CVE-2014-2775 EXP Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch early 9.3 high 20% 2014-06-11
CVE-2015-6908 EXP The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable ass… Patch early 5.0 medium 20% 2015-09-11
CVE-2010-0359 EXP Buffer overflow in the SSLv2 support in Zeus Web Server before 4.3r5 allows remote attackers to cause a denial of service (daemon crash) or possibly e… Patch early 10.0 high 20% 2010-01-20
CVE-2025-49619 EXP Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block.… Patch early 8.5 high 20% 2025-06-07
CVE-2010-2305 EXP Buffer overflow in an ActiveX control in SSHelper.dll for Symantec Sygate Personal Firewall 5.6 build 2808 allows remote attackers to execute arbitrar… Patch early 9.3 high 20% 2010-06-16
CVE-2004-2383 EXP Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from othe… Patch early 5.1 medium 20% 2004-12-31
CVE-2008-1765 EXP Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remote attackers and physically pro… Patch early 9.3 high 20% 2008-04-23
CVE-1999-0107 EXP Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a lar… Patch early 5.0 medium 19.9% 1997-12-30
CVE-2016-3387 EXP Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain… Patch early 7.5 high 19.9% 2016-10-14
CVE-2008-6347 EXP PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b component for Joomla! allows r… Patch early 7.5 high 19.9% 2009-03-02
CVE-2018-1322 EXP An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x whi… Patch early 4.9 medium 19.9% 2018-03-20
CVE-2007-0168 EXP The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Prote… Patch early 7.5 high 19.9% 2007-01-11
CVE-2002-0540 EXP Nortel CVX 1800 is installed with a default "public" community string, which allows remote attackers to read usernames and passwords and modify the CV… Patch early 7.5 high 19.9% 2002-07-03
CVE-2017-16921 EXP In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged i… Patch early 8.8 high 19.9% 2017-12-08
← previous page 142 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt