peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,212 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

319,768 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-0271 EXP Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before S… Patch early 10.0 high 17.2% 2012-09-19
CVE-2010-3609 EXP The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol daemon (SL… Patch early 5.0 medium 17.2% 2011-03-11
CVE-2013-4694 EXP Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possib… Patch early 7.5 high 17.2% 2014-04-16
CVE-2019-12099 EXP In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput.… Patch early 8.8 high 17.2% 2019-05-14
CVE-2008-4342 EXP NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnA… Patch early 9.3 high 17.2% 2008-09-30
CVE-2017-5850 EXP httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for a large file using an HTTP Ran… Patch early 7.5 high 17.2% 2017-03-27
CVE-2001-1370 EXP prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request… Patch early 10.0 high 17.2% 2001-07-21
CVE-2005-3330 EXP The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attack… Patch early 7.5 high 17.2% 2005-10-27
CVE-2006-4075 EXP Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and earlier allow remote attackers to… Patch early 5.1 medium 17.2% 2006-08-11
CVE-2001-0348 EXP Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace. Patch early 5.0 medium 17.2% 2001-07-21
CVE-2016-3237 EXP Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8… Patch early 7.5 high 17.2% 2016-08-09
CVE-2007-1090 EXP Microsoft Windows Explorer on Windows XP and 2003 allows remote user-assisted attackers to cause a denial of service (crash) via a malformed WMF file,… Patch early 7.1 high 17.2% 2007-02-26
CVE-1999-0113 EXP Some implementations of rlogin allow root access if given a -froot parameter. Patch early 10.0 high 17.2% 1994-05-23
CVE-2001-0763 EXP Buffer overflow in Linux xinetd 2.1.8.9pre11-1 and earlier may allow remote attackers to execute arbitrary code via a long ident response, which is no… Patch early 7.5 high 17.2% 2001-10-18
CVE-2016-9587 EXP Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker… Patch early 8.1 high 17.1% 2018-04-24
CVE-2011-3829 EXP ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the file name, w… Patch early 4.0 medium 17.1% 2012-01-29
CVE-2017-2361 EXP An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Help Viewer" component, which allows XSS… Patch early 6.1 medium 17.1% 2017-02-20
CVE-2021-25076 EXP The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscr… Patch early 8.8 high 17.1% 2022-01-24
CVE-2005-1191 EXP The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe ("'") in the author name in… Patch early 5.0 medium 17.1% 2005-05-02
CVE-2006-3317 EXP PHP remote file inclusion vulnerability in phpRaid 3.0.6 allows remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (… Patch early 5.1 medium 17.1% 2006-06-29
CVE-2006-5020 EXP Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 17.1% 2006-09-27
CVE-2006-5627 EXP Multiple PHP remote file inclusion vulnerabilities in QnECMS 2.5.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the a… Patch early 7.5 high 17.1% 2006-10-31
CVE-2013-0008 EXP win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Wind… Patch early 7.2 high 17.1% 2013-01-09
CVE-2006-3354 EXP Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter property of an ADODB.Recordset Active… Patch early 5.0 medium 17.1% 2006-07-06
CVE-2006-3910 EXP Internet Explorer 6 on Windows XP SP2, when Outlook is installed, allows remote attackers to cause a denial of service (crash) by calling the NewDefau… Patch early 5.0 medium 17.1% 2006-07-28
CVE-2016-8581 EXP A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker t… Patch early 6.1 medium 17.1% 2016-10-28
CVE-2017-15049 EXP The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, w… Patch early 8.8 high 17% 2017-12-19
CVE-2004-1029 EXP The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict acces… Patch early 9.3 high 17% 2005-03-01
CVE-2010-2943 EXP The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote au… Patch early 8.1 high 17% 2010-09-30
CVE-2015-5079 EXP Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 7.5 high 17% 2018-02-28
← previous page 152 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt