peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,599 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

402,599 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-2361 EXP An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Help Viewer" component, which allows XSS… Patch early 6.1 medium 17.1% 2017-02-20
CVE-2021-25076 EXP The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscr… Patch early 8.8 high 17.1% 2022-01-24
CVE-2005-1191 EXP The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe ("'") in the author name in… Patch early 5.0 medium 17.1% 2005-05-02
CVE-2006-3317 EXP PHP remote file inclusion vulnerability in phpRaid 3.0.6 allows remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (… Patch early 5.1 medium 17.1% 2006-06-29
CVE-2006-5020 EXP Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 17.1% 2006-09-27
CVE-2006-5627 EXP Multiple PHP remote file inclusion vulnerabilities in QnECMS 2.5.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the a… Patch early 7.5 high 17.1% 2006-10-31
CVE-2013-0008 EXP win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Wind… Patch early 7.2 high 17.1% 2013-01-09
CVE-2025-0868 EXP A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an una… Patch early — 17.1% 2025-02-20
CVE-2018-13981 EXP The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code execution due to a default com… Patch early 9.8 critical 17.1% 2018-07-16
CVE-2006-3354 EXP Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter property of an ADODB.Recordset Active… Patch early 5.0 medium 17.1% 2006-07-06
CVE-2006-3910 EXP Internet Explorer 6 on Windows XP SP2, when Outlook is installed, allows remote attackers to cause a denial of service (crash) by calling the NewDefau… Patch early 5.0 medium 17.1% 2006-07-28
CVE-2016-8581 EXP A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker t… Patch early 6.1 medium 17.1% 2016-10-28
CVE-2017-15049 EXP The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, w… Patch early 8.8 high 17% 2017-12-19
CVE-2019-1912 EXP A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to u… Patch early 9.1 critical 17% 2019-08-07
CVE-2004-1029 EXP The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict acces… Patch early 9.3 high 17% 2005-03-01
CVE-2010-2943 EXP The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote au… Patch early 8.1 high 17% 2010-09-30
CVE-2015-5079 EXP Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 7.5 high 17% 2018-02-28
CVE-2013-6810 EXP The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE), HP B-series SAN Network Advi… Patch early 10.0 high 17% 2013-12-12
CVE-2001-0212 EXP Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and p… Patch early 7.5 high 17% 2001-06-02
CVE-2010-1956 EXP Directory traversal vulnerability in the Gadget Factory (com_gadgetfactory) component 1.0.0 and 1.5.0 for Joomla! allows remote attackers to read arbi… Patch early 7.5 high 17% 2010-05-19
CVE-2013-4977 EXP Buffer overflow in the RTSP Packet Handler in Hikvision DS-2CD7153-E IP camera with firmware 4.1.0 b130111 (Jan 2013), and possibly other devices, all… Patch early 10.0 high 17% 2014-03-03
CVE-2019-8641 EXP An out-of-bounds read was addressed with improved input validation. Patch early 9.8 critical 17% 2019-12-18
CVE-2015-2280 EXP snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709_r1192.pck allows remote authe… Patch early 8.8 high 17% 2017-07-25
CVE-2002-1634 EXP Novell NetWare 5.1 installs sample applications that allow remote attackers to obtain sensitive information via (1) ndsobj.nlm, (2) allfield.jse, (3)… Patch early 5.0 medium 17% 2002-12-31
CVE-2019-11469 EXP Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user c… Patch early 9.8 critical 17% 2019-04-23
CVE-2014-5119 EXP Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a den… Patch early 7.5 high 17% 2014-08-29
CVE-2019-1120 EXP A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerabili… Patch early 8.8 high 16.9% 2019-07-15
CVE-2019-1121 EXP A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerabili… Patch early 8.8 high 16.9% 2019-07-15
CVE-2019-1122 EXP A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerabili… Patch early 8.8 high 16.9% 2019-07-15
CVE-2019-1123 EXP A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerabili… Patch early 8.8 high 16.9% 2019-07-15
← previous page 195 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt