peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,546 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

320,042 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-7944 EXP The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13… Patch early 7.5 high 14.2% 2017-08-18
CVE-2013-1597 EXP A Directory Traversal vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via a specially crafted GET request, which could let a malicio… Patch early 6.5 medium 14.2% 2020-01-24
CVE-2018-0891 EXP ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and… Patch early 4.3 medium 14.2% 2018-03-14
CVE-2011-4451 EXP libs/Wakka.class.php in WikkaWiki 1.3.1 and 1.3.2, when the spam_logging option is enabled, allows remote attackers to write arbitrary PHP code to the… Patch early 4.3 medium 14.2% 2012-09-05
CVE-2010-4435 EXP Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability, related to CD… Patch early 10.0 high 14.2% 2011-01-19
CVE-2008-4318 EXP Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter to (1) whois.php or… Patch early 10.0 high 14.1% 2008-09-29
CVE-2014-0787 EXP Stack-based buffer overflow in WellinTech KingSCADA before 3.1.2.13 allows remote attackers to execute arbitrary code via a crafted packet. Patch early 10.0 high 14.1% 2014-04-12
CVE-2006-2270 EXP PHP remote file inclusion vulnerability in includes/config.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary code via a URL in the re… Patch early 7.5 high 14.1% 2006-05-09
CVE-2005-4593 EXP PHP remote file inclusion vulnerability in phpDocumentor 1.3.0 rc4 and earlier, when register_globals is enabled, allows remote attackers to execute a… Patch early 7.5 high 14.1% 2005-12-31
CVE-2003-0166 EXP Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possi… Patch early 7.5 high 14.1% 2003-04-02
CVE-2012-2138 EXP The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to cop… Patch early 5.0 medium 14.1% 2012-07-09
CVE-2005-2841 EXP Buffer overflow in Firewall Authentication Proxy for FTP and/or Telnet Sessions for Cisco IOS 12.2ZH and 12.2ZL, 12.3 and 12.3T, and 12.4 and 12.4T al… Patch early 7.5 high 14.1% 2005-09-08
CVE-2017-7783 EXP If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example.com"), the resulting modal pr… Patch early 7.5 high 14.1% 2018-06-11
CVE-2016-5679 EXP cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary… Patch early 8.8 high 14.1% 2016-08-31
CVE-2009-1669 EXP The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary commands… Patch early 10.0 high 14.1% 2009-05-18
CVE-2012-5106 EXP Stack-based buffer overflow in FreeFloat FTP Server 1.0 allows remote authenticated users to execute arbitrary code via a long string in a PUT command… Patch early 10.0 high 14.1% 2014-06-20
CVE-2010-1175 EXP Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified impact via a certain XML document… Patch early 9.3 high 14.1% 2010-03-29
CVE-2021-42165 EXP MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &… Patch early 8.8 high 14.1% 2022-05-03
CVE-2016-9838 EXP An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored… Patch early 7.5 high 14.1% 2016-12-16
CVE-2003-1228 EXP Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions, allows remote attackers to c… Patch early 7.5 high 14.1% 2003-12-31
CVE-2017-0211 EXP An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Se… Patch early 5.5 medium 14.1% 2017-04-12
CVE-2023-32749 EXP Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when crea… Patch early 8.8 high 14.1% 2023-06-08
CVE-2008-3655 EXP Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to critical variab… Patch early 7.5 high 14.1% 2008-08-13
CVE-2018-6409 EXP An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the… Patch early 5.3 medium 14.1% 2018-05-26
CVE-2019-6445 EXP An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can cause a NULL pointer dereference and ntpd crash in ntp_control.c, relate… Patch early 6.5 medium 14.1% 2019-01-16
CVE-2007-6731 EXP Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses… Patch early 10.0 high 14.1% 2009-09-13
CVE-2015-2099 EXP Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vectors to the (1) GetRecFileInfo… Patch early 8.8 high 14.1% 2021-07-22
CVE-2004-2501 EXP Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute arbitrary c… Patch early 7.5 high 14.1% 2004-12-31
CVE-2018-0710 EXP Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrar… Patch early 8.8 high 14.1% 2018-07-17
CVE-2010-0944 EXP Directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to read arbitrary files via a ..… Patch early 5.0 medium 14% 2010-03-08
← previous page 170 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt