peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,267 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

319,807 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2013-6810 EXP The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE), HP B-series SAN Network Advi… Patch early 10.0 high 17% 2013-12-12
CVE-2001-0212 EXP Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and p… Patch early 7.5 high 17% 2001-06-02
CVE-2010-1956 EXP Directory traversal vulnerability in the Gadget Factory (com_gadgetfactory) component 1.0.0 and 1.5.0 for Joomla! allows remote attackers to read arbi… Patch early 7.5 high 17% 2010-05-19
CVE-2013-4977 EXP Buffer overflow in the RTSP Packet Handler in Hikvision DS-2CD7153-E IP camera with firmware 4.1.0 b130111 (Jan 2013), and possibly other devices, all… Patch early 10.0 high 17% 2014-03-03
CVE-2015-2280 EXP snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709_r1192.pck allows remote authe… Patch early 8.8 high 17% 2017-07-25
CVE-2002-1634 EXP Novell NetWare 5.1 installs sample applications that allow remote attackers to obtain sensitive information via (1) ndsobj.nlm, (2) allfield.jse, (3)… Patch early 5.0 medium 17% 2002-12-31
CVE-2014-5119 EXP Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a den… Patch early 7.5 high 17% 2014-08-29
CVE-2019-1120 EXP A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerabili… Patch early 8.8 high 16.9% 2019-07-15
CVE-2019-1121 EXP A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerabili… Patch early 8.8 high 16.9% 2019-07-15
CVE-2019-1122 EXP A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerabili… Patch early 8.8 high 16.9% 2019-07-15
CVE-2019-1123 EXP A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerabili… Patch early 8.8 high 16.9% 2019-07-15
CVE-2019-1128 EXP A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerabili… Patch early 8.8 high 16.9% 2019-07-15
CVE-2010-1531 EXP Directory traversal vulnerability in the redSHOP (com_redshop) component 1.0.x for Joomla! allows remote attackers to read arbitrary files via a .. (d… Patch early 7.5 high 16.9% 2010-04-26
CVE-2015-3440 EXP Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 16.9% 2015-08-03
CVE-2008-0250 EXP Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with… Patch early 9.3 high 16.9% 2008-01-12
CVE-2013-2678 EXP Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive informati… Patch early 8.1 high 16.9% 2020-02-04
CVE-2010-1345 EXP Directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to read arbitrary fil… Patch early 5.0 medium 16.9% 2010-04-09
CVE-2012-3282 EXP Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code v… Patch early 10.0 high 16.9% 2013-02-06
CVE-2008-5177 EXP Stack-based buffer overflow in the DtbClsLogin function in Yosemite Backup 8.7 allows remote attackers to (1) execute arbitrary code on a Linux platfo… Patch early 10.0 high 16.9% 2008-11-20
CVE-2006-3772 EXP PHP-Post 0.21 and 1.0, and possibly earlier versions, when auto-login is enabled, allows remote attackers to bypass security restrictions and obtain a… Patch early 5.1 medium 16.8% 2006-07-24
CVE-2008-3362 EXP Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to exec… Patch early 10.0 high 16.8% 2008-07-30
CVE-2010-3152 EXP Untrusted search path vulnerability in Adobe Illustrator CS4 14.0.0, CS5 15.0.1 and earlier, and possibly other versions allows local users, and possi… Patch early 9.3 high 16.8% 2010-08-27
CVE-2007-1770 EXP Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three t… Patch early 10.0 high 16.8% 2007-03-30
CVE-2020-26567 EXP An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any ac… Patch early 5.5 medium 16.8% 2020-10-08
CVE-2017-8535 EXP The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… Patch early 5.5 medium 16.8% 2017-05-26
CVE-2017-8536 EXP The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… Patch early 5.5 medium 16.8% 2017-05-26
CVE-2017-8537 EXP The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… Patch early 5.5 medium 16.8% 2017-05-26
CVE-2010-4227 EXP The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arbi… Patch early 10.0 high 16.8% 2011-02-25
CVE-2012-2131 EXP Multiple integer signedness errors in crypto/buffer/buffer.c in OpenSSL 0.9.8v allow remote attackers to conduct buffer overflow attacks, and cause a… Patch early 7.5 high 16.8% 2012-04-24
CVE-2020-5192 EXP PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validatin… Patch early 8.8 high 16.8% 2020-01-06
← previous page 153 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt