peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,999 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

321,001 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-4004 EXP Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated administrators to read arbitrary file… Patch early 4.9 medium 8.9% 2016-04-12
CVE-2009-4494 EXP AOLserver 4.5.1 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title,… Patch early 5.0 medium 8.9% 2010-01-13
CVE-1999-0985 EXP CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. Patch early 7.5 high 8.9% 1999-11-09
CVE-2008-1561 EXP Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of service (appli… Patch early 5.0 medium 8.9% 2008-03-31
CVE-2012-1010 EXP Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrar… Patch early 7.5 high 8.9% 2012-02-07
CVE-2021-41382 EXP Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface. Patch early 7.5 high 8.9% 2021-09-22
CVE-2003-0211 EXP Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections. Patch early 5.0 medium 8.9% 2003-05-05
CVE-2000-0017 EXP Buffer overflow in Linux linuxconf package allows remote attackers to gain root privileges via a long parameter. Patch early 10.0 high 8.9% 1999-12-21
CVE-2007-2363 EXP Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file. Patch early 8.5 high 8.9% 2007-04-30
CVE-2008-5642 EXP Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a… Patch early 5.0 medium 8.9% 2008-12-17
CVE-2013-3541 EXP Directory traversal vulnerability in cgi-bin/admin/fileread in AirLive WL2600CAM and possibly other camera models allows remote attackers to read arbi… Patch early 7.8 high 8.9% 2013-10-04
CVE-2018-5954 EXP phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect commands. Patch early 7.5 high 8.9% 2018-01-25
CVE-2017-15644 EXP SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000. Patch early 8.6 high 8.9% 2017-10-19
CVE-2010-2045 EXP Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Joomla! allows remote attackers to… Patch early 7.5 high 8.9% 2010-05-25
CVE-2006-2458 EXP Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code via (1) the asf_read_header f… Patch early 4.0 medium 8.9% 2006-05-18
CVE-2013-6830 EXP admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attackers to execute arbitrary command… Patch early 7.5 high 8.9% 2013-11-20
CVE-2019-2107 EXP In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code e… Patch early 8.8 high 8.9% 2019-07-08
CVE-2007-4338 EXP index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's na… Patch early 10.0 high 8.9% 2007-08-14
CVE-2002-0737 EXP Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a denial of service (resource exhau… Patch early 6.4 medium 8.9% 2002-08-12
CVE-2010-2300 EXP Use-after-free vulnerability in the Element::normalizeAttributes function in dom/Element.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 a… Patch early 10.0 high 8.9% 2010-06-15
CVE-2008-4324 EXP The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dere… Patch early 5.0 medium 8.9% 2008-09-29
CVE-2014-2575 EXP Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and… Patch early 6.5 medium 8.9% 2014-06-06
CVE-2010-1179 EXP Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… Patch early 9.3 high 8.9% 2010-03-29
CVE-2006-4160 EXP Multiple PHP remote file inclusion vulnerabilities in Tony Bibbs and Vincent Furia MVCnPHP 3.0 allow remote attackers to execute arbitrary PHP code vi… Patch early 7.5 high 8.9% 2006-08-16
CVE-2001-0899 EXP Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variable. Patch early 7.5 high 8.9% 2001-11-16
CVE-2010-0313 EXP The core_get_proxyauth_dn function in ns-slapd in Sun Java System Directory Server Enterprise Edition 7.0 allows remote attackers to cause a denial of… Patch early 5.0 medium 8.9% 2010-01-14
CVE-2012-4982 EXP Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary w… Patch early 5.8 medium 8.9% 2012-12-05
CVE-2016-8377 EXP An issue was discovered in Fatek Automation PLC WinProladder Version 3.11 Build 14701. A stack-based buffer overflow vulnerability exists when the sof… Patch early 8.0 high 8.9% 2017-02-13
CVE-2019-11269 EXP Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versi… Patch early 5.4 medium 8.9% 2019-06-12
CVE-2006-2555 EXP The parse_command function in Genecys 0.2 and earlier allows remote attackers to cause a denial of service (crash) via a command with a missing ":" (c… Patch early 5.0 medium 8.9% 2006-05-24
← previous page 227 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt