peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,092 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

206,655 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-5309 EXP The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud;… Patch early 5.5 medium 6.9% 2017-04-14
CVE-2006-6808 EXP Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML v… Patch early 6.8 medium 6.9% 2006-12-28
CVE-2000-0396 EXP The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to… Patch early 5.0 medium 6.9% 2000-05-24
CVE-2015-4683 EXP Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by levera… Patch early 9.8 critical 6.9% 2017-09-19
CVE-2013-4103 EXP Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input Patch early 9.8 critical 6.9% 2019-11-04
CVE-2008-3667 EXP Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTTP header. Patch early 6.8 medium 6.9% 2008-08-13
CVE-2010-4437 EXP Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.4, 10.0.2, 10.3.2, and 10.3.3 allows remot… Patch early 5.8 medium 6.9% 2011-01-19
CVE-2017-6192 EXP Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arbitrary code via a crafted imag… Patch early 5.5 medium 6.9% 2018-02-20
CVE-1999-0414 EXP In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the conne… Patch early 5.0 medium 6.9% 1999-03-01
CVE-2000-0208 EXP The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters… Patch early 5.0 medium 6.9% 2000-02-29
CVE-2016-8580 EXP PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PH… Patch early 9.8 critical 6.9% 2016-10-28
CVE-2008-2390 EXP Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows remote attackers to execute ar… Patch early 6.8 medium 6.9% 2008-05-21
CVE-2012-0901 EXP Cross-site scripting (XSS) vulnerability in yousaytoo.php in YouSayToo auto-publishing plugin 1.0 for WordPress allows remote attackers to inject arbi… Patch early 4.3 medium 6.9% 2012-01-20
CVE-2015-8283 EXP Directory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00. Patch early 6.5 medium 6.8% 2017-04-13
CVE-2005-2075 EXP PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows… Patch early 5.0 medium 6.8% 2005-06-29
CVE-2006-2180 EXP Buffer overflow in Golden FTP Server Pro 2.70 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via… Patch early 6.4 medium 6.8% 2006-05-04
CVE-2014-2612 EXP Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux… Patch early 4.0 medium 6.8% 2014-06-28
CVE-2004-1947 EXP The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as s… Patch early 5.0 medium 6.8% 2004-04-19
CVE-2010-0982 EXP Directory traversal vulnerability in the CARTwebERP (com_cartweberp) component 1.56.75 for Joomla! allows remote attackers to read arbitrary files via… Patch early 4.3 medium 6.8% 2010-03-16
CVE-2003-0726 EXP RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation with a URL that references a scri… Patch early 5.1 medium 6.8% 2003-10-20
CVE-2007-2659 EXP Directory traversal vulnerability in index.php in PHP Advanced Transfer Manager (phpATM) 1.30 allows remote attackers to read arbitrary files and obta… Patch early 5.0 medium 6.8% 2007-05-14
CVE-2006-3636 EXP Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspe… Patch early 6.8 medium 6.8% 2006-09-06
CVE-2017-2527 EXP An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "CoreAnimation" component. It allows remot… Patch early 9.8 critical 6.8% 2017-05-22
CVE-2020-8865 EXP This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authenticat… Patch early 6.3 medium 6.8% 2020-03-23
CVE-2007-3957 EXP Buffer overflow in Nipun Jain xserver 0.1 alpha allows remote attackers to cause a denial of service via a POST request with a long URI. Patch early 5.0 medium 6.8% 2007-07-24
CVE-2018-10653 EXP There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. Patch early 9.8 critical 6.8% 2018-05-23
CVE-2006-2310 EXP BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to cause a denial of service (hang) via a request for a .cfm file whose… Patch early 5.0 medium 6.8% 2006-06-26
CVE-2008-1052 EXP The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large… Patch early 6.4 medium 6.8% 2008-02-27
CVE-2008-6423 EXP Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and earlier allows remote attackers to read arbitrary local files via a .. (d… Patch early 5.0 medium 6.8% 2009-03-06
CVE-2006-2745 EXP Multiple PHP remote file inclusion vulnerabilities in F@cile Interactive Web 0.8.5 and earlier, when register_globals is enabled, allow remote attacke… Patch early 5.1 medium 6.8% 2006-06-01
← previous page 143 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt