peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,941 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

402,984 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-1487 EXP The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by sending the raw messages (1) 2… Patch early 5.0 medium 13.6% 2003-04-02
CVE-2002-1522 EXP Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute ar… Patch early 5.0 medium 13.6% 2003-04-02
CVE-2024-11728 EXP The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter… Patch early 7.5 high 13.6% 2024-12-06
CVE-2015-0565 EXP NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible. Patch early 10.0 critical 13.6% 2020-02-25
CVE-2006-2686 EXP PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[AA_INC_PAT… Patch early 6.4 medium 13.6% 2006-05-31
CVE-2020-11027 EXP In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to… Patch early 6.1 medium 13.6% 2020-04-30
CVE-2010-1312 EXP Directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote attackers to read arbitrary f… Patch early 5.0 medium 13.6% 2010-04-08
CVE-2010-1340 EXP Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote attackers to read arbitrary f… Patch early 5.0 medium 13.6% 2010-04-09
CVE-2010-1534 EXP Directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (d… Patch early 5.0 medium 13.6% 2010-04-26
CVE-2010-1858 EXP Directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote attackers to read arbitrary files… Patch early 5.0 medium 13.6% 2010-05-07
CVE-2008-4787 EXP Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a URL with a hostname containing… Patch early 5.8 medium 13.6% 2008-10-29
CVE-2007-5849 EXP Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute… Patch early 9.3 high 13.6% 2007-12-19
CVE-2019-7391 EXP ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF. Patch early 8.8 high 13.6% 2019-03-21
CVE-2002-0189 EXP Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that explo… Patch early 7.5 high 13.6% 2002-05-29
CVE-2010-1352 EXP Directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote attackers to read arbitrary fi… Patch early 5.0 medium 13.6% 2010-04-12
CVE-2010-1491 EXP Directory traversal vulnerability in the MMS Blog (com_mmsblog) component 2.3.0 for Joomla! allows remote attackers to read arbitrary files and possib… Patch early 5.0 medium 13.6% 2010-04-23
CVE-2002-0682 EXP Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /s… Patch early 7.5 high 13.6% 2002-07-23
CVE-2006-3121 EXP The peel_netstring function in cl_netstring.c in the heartbeat subsystem in High-Availability Linux before 1.2.5, and 2.0 before 2.0.7, allows remote… Patch early 5.0 medium 13.6% 2006-08-17
CVE-2010-4711 EXP Double free vulnerability in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allows remote attackers to… Patch early 10.0 high 13.6% 2011-01-31
CVE-2012-4415 EXP Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of… Patch early 7.5 high 13.6% 2012-10-01
CVE-2004-0277 EXP Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via for… Patch early 10.0 high 13.6% 2004-11-23
CVE-2015-6589 EXP Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0… Patch early 8.8 high 13.6% 2020-02-13
CVE-2006-0179 EXP The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary p… Patch early 5.0 medium 13.6% 2006-01-11
CVE-1999-0140 EXP Denial of service in RAS/PPTP on NT systems. Patch early 5.0 medium 13.6% 1999-06-30
CVE-2006-4227 EXP MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine… Patch early 6.5 medium 13.6% 2006-08-18
CVE-2010-3149 EXP Untrusted search path vulnerability in Adobe Device Central CS5 3.0.0(376), 3.0.1.0 (3027), and probably other versions allows local users, and possib… Patch early 9.3 high 13.6% 2010-08-27
CVE-2010-3153 EXP Untrusted search path vulnerability in Adobe InDesign CS4 6.0, InDesign CS5 7.0.2 and earlier, Adobe InDesign Server CS5 7.0.2 and earlier, and Adobe… Patch early 9.3 high 13.6% 2010-08-27
CVE-2008-4310 EXP httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CP… Patch early 7.8 high 13.6% 2008-12-09
CVE-2014-5465 EXP Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress allows remote attackers to re… Patch early 5.0 medium 13.5% 2014-09-03
CVE-2002-1444 EXP The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exceptio… Patch early 2.6 low 13.5% 2002-08-15
← previous page 220 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt