peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,488 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

206,856 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-1915 EXP Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial of service (persistent crash)… Patch early 4.3 medium 5% 2009-06-04
CVE-2006-0315 EXP index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote… Patch early 5.8 medium 4.9% 2006-01-19
CVE-2007-1474 EXP Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users… Patch early 6.8 medium 4.9% 2007-03-16
CVE-2008-3140 EXP The syslog dissector in Wireshark (formerly Ethereal) 1.0.0 allows remote attackers to cause a denial of service (application crash) via unknown vecto… Patch early 5.0 medium 4.9% 2008-07-10
CVE-2017-15014 EXP OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows authenticated… Patch early 4.3 medium 4.9% 2017-10-13
CVE-2004-1075 EXP Cross-site scripting (XSS) vulnerability in standard_error_message.dtml for Zwiki after 0.10.0rc1 to 0.36.2 allows remote attackers to inject arbitrar… Patch early 6.8 medium 4.9% 2005-01-10
CVE-2012-2698 EXP Cross-site scripting (XSS) vulnerability in the outputPage function in includes/SkinTemplate.php in MediaWiki before 1.17.5, 1.18.x before 1.18.4, and… Patch early 4.3 medium 4.9% 2012-06-29
CVE-2021-26929 EXP An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker… Patch early 6.1 medium 4.9% 2021-02-14
CVE-2017-8837 EXP Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1… Patch early 9.8 critical 4.9% 2017-06-05
CVE-2002-0031 EXP Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsgr URI with long arguments to (… Patch early 4.6 medium 4.9% 2002-07-26
CVE-2003-1085 EXP The HTTP server in the Thomson TWC305, TWC315, and TCW690 cable modem ST42.03.0a allows remote attackers to cause a denial of service (unstable servic… Patch early 5.0 medium 4.9% 2003-12-31
CVE-2007-1540 EXP Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to run arbitr… Patch early 4.3 medium 4.9% 2007-03-20
CVE-2012-5699 EXP BabyGekko before 1.2.4 allows PHP file inclusion. Patch early 9.8 critical 4.9% 2020-01-23
CVE-2019-11370 EXP Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" field. Patch early 5.4 medium 4.9% 2019-06-03
CVE-2017-15962 EXP iStock Management System 1.0 allows Arbitrary File Upload via user/profile. Patch early 9.8 critical 4.9% 2017-10-29
CVE-2001-0484 EXP Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which all… Patch early 6.4 medium 4.9% 2001-06-27
CVE-2008-6769 EXP Unrestricted file upload vulnerability in upload.php in YourPlace 1.0.2 and earlier allows remote authenticated users to execute arbitrary code by upl… Patch early 6.0 medium 4.9% 2009-04-29
CVE-2008-0466 EXP Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authenticati… Patch early 5.0 medium 4.9% 2008-01-29
CVE-2015-4684 EXP Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated users to re… Patch early 6.5 medium 4.9% 2017-09-19
CVE-2004-2078 EXP Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss of logged events) via a long re… Patch early 5.0 medium 4.9% 2004-02-09
CVE-2019-6780 EXP The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPostFilter.php omits noopener and… Patch early 6.1 medium 4.9% 2019-01-24
CVE-1999-0173 EXP FormMail CGI program can be used by web servers other than the host server that the program resides on. Patch early 5.0 medium 4.9% 1997-01-01
CVE-2014-8305 EXP Open redirect vulnerability in the redir function in includes/function.php in C97net Cart Engine before 4.0 allows remote attackers to redirect users… Patch early 6.4 medium 4.9% 2014-10-16
CVE-2000-0645 EXP WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file… Patch early 6.4 medium 4.9% 2000-07-21
CVE-2004-1705 EXP Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username. Patch early 5.0 medium 4.9% 2004-07-30
CVE-2011-0507 EXP FTPService.exe in Blackmoon FTP 3.1 Build 1735 and Build 1736 (3.1.7.1736), and possibly other versions before 3.1.8.1737, allows remote attackers to… Patch early 4.3 medium 4.9% 2011-01-20
CVE-2017-9125 EXP The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-… Patch early 6.5 medium 4.9% 2017-06-12
CVE-2012-0241 EXP Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to a… Patch early 5.0 medium 4.9% 2012-02-21
CVE-2007-5300 EXP Off-by-one error in the do_login_loop function in libwzd-core/wzd_login.c in wzdftpd 0.8.0, 0.8.2, and possibly other versions allows remote attackers… Patch early 5.0 medium 4.9% 2007-10-09
CVE-2007-5229 EXP Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attackers to change settings and hi… Patch early 6.4 medium 4.9% 2007-10-05
← previous page 172 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt