peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,546 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

170,147 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-1674 EXP The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly validate an unspecified… Patch early 4.6 medium 3.3% 2015-05-13
CVE-2001-1347 EXP Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using globa… Patch early 4.6 medium 3.3% 2001-05-24
CVE-2010-3314 EXP Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1… Patch early 4.3 medium 3.3% 2010-09-22
CVE-2004-2675 EXP ArGoSoft FTP Server before 1.4.1.6 allows remote authenticated users to cause a denial of service (crash) via a SITE PASS command with a long password… Patch early 6.8 medium 3.3% 2004-12-31
CVE-2017-11831 EXP Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,… Patch early 4.7 medium 3.3% 2017-11-15
CVE-2009-4612 EXP Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inje… Patch early 4.3 medium 3.3% 2010-01-13
CVE-2012-1464 EXP Dashboard Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the installation path via a request with a trailing "?" c… Patch early 5.0 medium 3.3% 2012-03-19
CVE-2012-1466 EXP The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code of NtDecision script files with… Patch early 5.0 medium 3.3% 2012-03-19
CVE-2002-1945 EXP Buffer overflow in SmartMail Server 1.0 Beta 10 allows remote attackers to cause a denial of service (crash) via a long request to (1) TCP port 25 (SM… Patch early 5.0 medium 3.3% 2002-12-31
CVE-2003-1158 EXP Multiple buffer overflows in the FTP service in Plug and Play Web Server 1.0002c allow remote attackers to cause a denial of service (crash) via long… Patch early 5.0 medium 3.3% 2003-12-31
CVE-2017-6443 EXP Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web script or HTML via the W_AD1 pa… Patch early 6.1 medium 3.3% 2017-03-15
CVE-2006-6203 EXP Directory traversal vulnerability in startdown.php in the Flyspray ME 1.0.1 (com_flyspray) component for Mambo allows remote attackers to read arbitra… Patch early 5.0 medium 3.3% 2006-12-01
CVE-2012-1258 EXP cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow… Patch early 6.5 medium 3.3% 2020-01-09
CVE-2008-3208 EXP Simple DNS Plus 4.1, 5.0, and possibly other versions before 5.1.101 allows remote attackers to cause a denial of service via multiple DNS reply packe… Patch early 5.0 medium 3.3% 2008-07-18
CVE-2013-3514 EXP Multiple directory traversal vulnerabilities in OpenX before 2.8.10 revision 82710 allow remote administrators to read arbitrary files via a .. (dot d… Patch early 4.3 medium 3.3% 2014-05-14
CVE-2008-2648 EXP Unrestricted file upload vulnerability in upload/uploader.html in meBiblio 0.4.7 allows remote attackers to execute arbitrary code by uploading a .php… Patch early 6.8 medium 3.3% 2008-06-10
CVE-2008-6617 EXP Unrestricted file upload vulnerability in adm/visual/upload.php in SiteXS CMS 0.1.1 allows remote attackers to execute arbitrary code by uploading a f… Patch early 6.8 medium 3.3% 2009-04-06
CVE-2008-6814 EXP Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earlier for Mambo allows remote at… Patch early 6.8 medium 3.3% 2009-05-28
CVE-2008-7157 EXP Unrestricted file upload vulnerability in EkinBoard 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading an avatar file wi… Patch early 6.8 medium 3.3% 2009-09-02
CVE-2022-41358 EXP A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a cra… Patch early 5.4 medium 3.3% 2022-10-20
CVE-2004-1923 EXP Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (2… Patch early 5.0 medium 3.3% 2004-04-11
CVE-2001-0038 EXP Offline Explorer 1.4 before Service Release 2 allows remote attackers to read arbitrary files by specifying the drive letter (e.g. C:) in the requeste… Patch early 5.0 medium 3.3% 2001-02-16
CVE-2001-0452 EXP BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls com… Patch early 5.0 medium 3.3% 2001-06-27
CVE-2007-5386 EXP Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allo… Patch early 4.3 medium 3.3% 2007-10-12
CVE-2007-5589 EXP Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.11.1.2 allow remote attackers to inject arbitrary web script or HTML via ce… Patch early 4.3 medium 3.3% 2007-10-19
CVE-2007-1968 EXP PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP co… Patch early 6.8 medium 3.3% 2007-04-11
CVE-2014-7177 EXP XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a crafted xml docume… Patch early 4.0 medium 3.3% 2014-10-31
CVE-2006-6899 EXP hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a… Patch early 5.4 medium 3.3% 2006-12-31
CVE-2008-0464 EXP Directory traversal vulnerability in archiv.cgi in absofort aconon Mail 2007 Enterprise SQL 11.7.0 and Mail 2004 Enterprise SQL 11.5.1 allows remote a… Patch early 5.0 medium 3.3% 2008-01-25
CVE-2008-0790 EXP Directory traversal vulnerability in ipdsserver.exe in Intermate WinIPDS 3.3 G52-33-021 allows remote attackers to read arbitrary files via a .. (dot… Patch early 5.0 medium 3.3% 2008-02-15
← previous page 166 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt