peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,573 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

170,169 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2000-0440 EXP NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option. Patch early 5.0 medium 3.2% 2000-05-01
CVE-2007-2068 EXP Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute arbitrary PHP code via a URL i… Patch early 6.8 medium 3.2% 2007-04-18
CVE-2013-6937 EXP Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the name attrib… Patch early 6.8 medium 3.2% 2013-12-04
CVE-2002-0922 EXP CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.sty… Patch early 5.0 medium 3.2% 2002-10-04
CVE-2002-1248 EXP Northern Solutions Xeneo Web Server 2.1.0.0, 2.0.759.6, and other versions before 2.1.5 allows remote attackers to cause a denial of service (crash) v… Patch early 5.0 medium 3.2% 2002-11-12
CVE-2004-1109 EXP The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption and system fre… Patch early 5.0 medium 3.2% 2005-01-10
CVE-2005-4319 EXP Directory traversal vulnerability in index2.php in Limbo CMS 1.0.4.2 and earlier allows remote attackers to include arbitrary PHP files via ".." seque… Patch early 5.0 medium 3.2% 2005-12-17
CVE-2004-1866 EXP nstxd in Nstx 1.1 beta3 and earlier allows remote attackers to cause a denial of service (crash) via a large packet, which triggers a null dereference… Patch early 5.0 medium 3.2% 2004-03-26
CVE-2012-6505 EXP Cross-site scripting (XSS) vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to inject arbitrar… Patch early 4.3 medium 3.2% 2013-01-24
CVE-2014-5216 EXP Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allow remote attackers to inject arbitrary web… Patch early 4.3 medium 3.2% 2014-12-23
CVE-2014-7200 EXP Cross-site scripting (XSS) vulnerability in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extension 2.14.0 and earlier for TYPO… Patch early 4.3 medium 3.2% 2014-10-10
CVE-2014-9412 EXP Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.1 allow remote attackers to inject arbitrary web script… Patch early 4.3 medium 3.2% 2014-12-23
CVE-2017-16951 EXP Winamp Pro 5.66 Build 3512 allows remote attackers to cause a denial of service via a crafted WAV, WMV, AU, ASF, AIFF, or AIF file. Patch early 5.5 medium 3.2% 2017-11-28
CVE-2009-1834 EXP Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 allows remote attacke… Patch early 4.3 medium 3.2% 2009-06-12
CVE-2007-4843 EXP Directory traversal vulnerability in X-Diesel Unreal Commander 0.92 build 565 and 573 allows remote FTP servers to create or overwrite arbitrary files… Patch early 5.8 medium 3.2% 2007-09-12
CVE-2008-4183 EXP IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup… Patch early 5.0 medium 3.2% 2008-09-23
CVE-2013-3082 EXP Cross-site scripting (XSS) vulnerability in plugins/jojo_core/forgot_password.php in Jojo before 1.2.2 allows remote attackers to inject arbitrary web… Patch early 4.3 medium 3.2% 2014-06-09
CVE-2003-1540 EXP WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authenticat… Patch early 5.0 medium 3.2% 2003-12-31
CVE-2015-1373 EXP Multiple cross-site scripting (XSS) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 3.2% 2015-01-27
CVE-2013-5693 EXP Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web script or HTML via the model par… Patch early 4.3 medium 3.2% 2013-09-30
CVE-2012-2584 EXP Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitrary web script or HTML via an… Patch early 4.3 medium 3.2% 2012-08-12
CVE-2014-8375 EXP SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administrators to execute arbitrary SQ… Patch early 6.5 medium 3.2% 2014-10-21
CVE-2021-35956 EXP Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introd… Patch early 5.4 medium 3.2% 2021-06-30
CVE-2015-6100 EXP The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2,… Patch early 6.9 medium 3.2% 2015-11-11
CVE-2008-0094 EXP Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary loc… Patch early 6.4 medium 3.2% 2008-01-08
CVE-2015-1057 EXP Cross-site scripting (XSS) vulnerability in usersettings.php in e107 2.0.0 allows remote attackers to inject arbitrary web script or HTML via the "Rea… Patch early 4.3 medium 3.2% 2015-01-16
CVE-2011-5028 EXP Directory traversal vulnerability in novelllogmanager/FileDownload in Novell Sentinel Log Manager 1.2.0.1_938 and earlier, as used in Novell Sentinel… Patch early 4.0 medium 3.2% 2011-12-29
CVE-2019-3759 EXP The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerabi… Patch early 6.4 medium 3.2% 2019-09-11
CVE-2017-16952 EXP KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file. Patch early 5.5 medium 3.2% 2017-11-28
CVE-2004-1212 EXP Directory traversal vulnerability in btdownload.php in Blog Torrent preview 0.8 allows remote attackers to download arbitrary files via a .. (dot dot)… Patch early 5.0 medium 3.2% 2005-01-10
← previous page 171 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt