peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,121 CVEs 1,733 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

206,666 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-0025 EXP Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for Irfan… Patch early 6.8 medium 6.4% 2012-11-02
CVE-2020-15718 EXP RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could… Patch early 6.1 medium 6.4% 2020-07-15
CVE-2009-4091 EXP comments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers to edit or delete comments via… Patch early 5.0 medium 6.4% 2009-11-29
CVE-2001-1490 EXP Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images. Patch early 5.0 medium 6.4% 2001-12-31
CVE-2006-2516 EXP mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite variables such as $xoopsOption['noc… Patch early 5.1 medium 6.4% 2006-05-22
CVE-2009-3643 EXP Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote attackers to cause a denial of service via a long argument to the (1) LIST and (2) NLST comman… Patch early 5.0 medium 6.4% 2009-10-09
CVE-2019-8927 EXP An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfi… Patch early 6.1 medium 6.3% 2019-05-17
CVE-2013-2682 EXP Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information. Patch early 4.3 medium 6.3% 2020-02-05
CVE-2026-25895 EXP FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote att… Patch early 9.8 critical 6.3% 2026-02-09
CVE-2021-45814 EXP Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an administrative account… Patch early 9.8 critical 6.3% 2021-12-28
CVE-2007-6537 EXP Stack-based buffer overflow in the zfile_gunzip function in zfile.c in WinUAE 1.4.4 and earlier allows user-assisted remote attackers to execute arbit… Patch early 6.8 medium 6.3% 2007-12-27
CVE-2020-14944 EXP Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeov… Patch early 9.8 critical 6.3% 2020-06-22
CVE-2009-0572 EXP PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enab… Patch early 5.1 medium 6.3% 2009-02-13
CVE-2000-0146 EXP The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service via a long URL to the servlet… Patch early 5.0 medium 6.3% 2000-02-07
CVE-2017-2479 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affect… Patch early 6.5 medium 6.3% 2017-04-02
CVE-2014-3146 EXP Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) at… Patch early 6.1 medium 6.3% 2014-05-14
CVE-2013-1402 EXP DigiLIBE 3.4 and possibly other versions sends a redirect but does not exit, which allows remote attackers to obtain sensitive configuration informati… Patch early 5.0 medium 6.3% 2013-02-14
CVE-2011-4810 EXP Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read arbitrary files via the templat… Patch early 5.0 medium 6.3% 2011-12-14
CVE-2013-1937 EXP Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inje… Patch early 6.1 medium 6.3% 2013-04-16
CVE-2008-5919 EXP Directory traversal vulnerability in rss.php in WebSVN 2.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to overwrite arbitr… Patch early 6.8 medium 6.3% 2009-01-21
CVE-2022-39195 EXP A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c p… Patch early 6.1 medium 6.3% 2023-01-17
CVE-2013-1636 EXP Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin be… Patch early 4.3 medium 6.3% 2014-03-12
CVE-2019-8926 EXP An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp fi… Patch early 6.1 medium 6.3% 2019-05-17
CVE-2019-8928 EXP An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp via these GET… Patch early 6.1 medium 6.3% 2019-05-17
CVE-2014-9598 EXP The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial… Patch early 6.8 medium 6.3% 2015-01-21
CVE-2018-1185 EXP An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint versi… Patch early 6.7 medium 6.3% 2018-02-03
CVE-2013-4864 EXP MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/prox… Patch early 9.8 critical 6.3% 2020-01-28
CVE-2020-6862 EXP V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page i… Patch early 5.3 medium 6.3% 2020-01-17
CVE-2017-5344 EXP An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet per… Patch early 9.8 critical 6.3% 2017-02-17
CVE-2013-6796 EXP The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, which triggers an LDAP anonymous b… Patch early 5.0 medium 6.3% 2014-10-26
← previous page 150 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt