peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,185 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

169,970 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-8481 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 3.9% 2017-06-15
CVE-2017-8489 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 3.9% 2017-06-15
CVE-2017-8491 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 3.9% 2017-06-15
CVE-2007-4140 EXP Buffer overflow in Live for Speed (LFS) S2 ALPHA PATCH 0.5x allows user-assisted remote attackers to execute arbitrary code via a .mpr file (replay fi… Patch early 6.8 medium 3.9% 2007-08-03
CVE-2010-3077 EXP Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows remote attackers to inject ar… Patch early 4.3 medium 3.9% 2010-11-09
CVE-2006-2027 EXP Buffer overflow in Unicode processing in the logging functionality in Pablo Software Solutions Quick 'n Easy FTP Server Professional and Lite, probabl… Patch early 6.5 medium 3.9% 2006-04-26
CVE-2011-5228 EXP Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote attackers to inject arbitrary web… Patch early 4.3 medium 3.9% 2012-10-25
CVE-2013-4950 EXP Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the element_2 pa… Patch early 4.3 medium 3.9% 2013-07-29
CVE-2008-5185 EXP The highlighting functionality in geshi.php in GeSHi before 1.0.8 allows remote attackers to cause a denial of service (infinite loop) via an XML sequ… Patch early 5.0 medium 3.9% 2008-11-21
CVE-2007-4803 EXP Buffer overflow in AtomixMP3 2.3 allows user-assisted remote attackers to execute arbitrary code via long strings in file and title fields in a .pls f… Patch early 6.8 medium 3.9% 2007-09-11
CVE-2019-10349 EXP A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jen… Patch early 5.4 medium 3.9% 2019-07-11
CVE-2003-1157 EXP Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 3.9% 2003-12-31
CVE-2006-2986 EXP Multiple cross-site scripting (XSS) vulnerabilities in Baby Katie Media (a) very Simple Car Lister (vSCAL) 1.0 and (b) very simple Realty Lister (vsRE… Patch early 4.3 medium 3.9% 2006-06-13
CVE-2006-3006 EXP Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly other versions before 0.50, allows remote attackers to inject arbitrary HTML or w… Patch early 4.3 medium 3.9% 2006-06-13
CVE-2015-2511 EXP The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012… Patch early 6.9 medium 3.9% 2015-09-09
CVE-2015-2518 EXP The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012… Patch early 6.9 medium 3.9% 2015-09-09
CVE-2018-6219 EXP An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain typ… Patch early 6.5 medium 3.9% 2018-03-15
CVE-2023-1258 EXP Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allo… Patch early 5.3 medium 3.9% 2023-03-31
CVE-2002-2338 EXP The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no n… Patch early 5.0 medium 3.9% 2002-12-31
CVE-2006-1486 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in realestateZONE 4.2 allow remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 3.9% 2006-03-29
CVE-2004-2528 EXP Cross-site scripting (XSS) vulnerability in sresult.exe in Webcam Watchdog 4.0.1a allows remote attackers to inject arbitrary web script or HTML via t… Patch early 4.3 medium 3.9% 2004-12-31
CVE-2007-5064 EXP Buffer overflow in a certain ActiveX control in Xunlei Web Thunder 5.6.9.344, possibly the DapPlayer ActiveX control in DapPlayer_Now.dll, allows remo… Patch early 6.8 medium 3.9% 2007-09-24
CVE-2008-0479 EXP Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz NewsPad 1.02 allows remote attackers to list arbitrary directories, and .txt and… Patch early 5.0 medium 3.9% 2008-01-29
CVE-2008-0480 EXP Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary directories, and .txt and .zi… Patch early 5.0 medium 3.9% 2008-01-29
CVE-2008-0481 EXP Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .… Patch early 5.0 medium 3.9% 2008-01-29
CVE-2007-0707 EXP Stack-based buffer overflow in GOM Player 2.0.12.3375 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI… Patch early 6.8 medium 3.9% 2007-02-04
CVE-2017-13754 EXP Cross-site scripting (XSS) vulnerability in the "advanced settings - time server" module in Wibu-Systems CodeMeter before 6.50b allows remote attacker… Patch early 5.4 medium 3.9% 2017-09-07
CVE-2010-2543 EXP Cross-site scripting (XSS) vulnerability in include/top_graph_header.php in Cacti before 0.8.7g allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 3.9% 2010-08-23
CVE-2001-0821 EXP The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive d… Patch early 5.0 medium 3.9% 2001-12-06
CVE-2006-2254 EXP Buffer overflow in filecpnt.exe in FileCOPA 1.01 allows remote attackers to cause a denial of service (application crash) via a username with a large… Patch early 5.0 medium 3.9% 2006-05-09
← previous page 143 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt