peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,999 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

321,001 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-2591 EXP A vulnerability classified as critical has been found in TEM FLEX-1085 1.6.0. Affected is an unknown function of the file /sistema/flash/reboot. The m… Patch early 7.5 high 8.9% 2022-08-01
CVE-2009-3658 EXP Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory… Patch early 8.8 high 8.9% 2009-10-09
CVE-2012-1563 EXP Joomla! before 2.5.3 allows Admin Account Creation. Patch early 7.5 high 8.9% 2020-01-15
CVE-2013-6890 EXP denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (inc… Patch early 5.0 medium 8.9% 2013-12-23
CVE-2008-0364 EXP Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; on Windows… Patch early 5.0 medium 8.9% 2008-01-18
CVE-2006-4131 EXP Multiple buffer overflows in ArcSoft MMS Composer 1.5.5.6, and possibly earlier, and 2.0.0.13, and possibly earlier, allow remote attackers to cause a… Patch early 7.5 high 8.9% 2006-08-14
CVE-2006-5472 EXP PHP remote file inclusion vulnerability in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 8.9% 2006-10-24
CVE-2017-7042 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 8.8 high 8.9% 2017-07-20
CVE-2008-3293 EXP Directory traversal vulnerability in download.php in EZWebAlbum allows remote attackers to read arbitrary files via the dlfilename parameter. Patch early 5.0 medium 8.9% 2008-07-24
CVE-2014-4874 EXP BMC Track-It! 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment page. Patch early 4.0 medium 8.9% 2014-10-10
CVE-2014-3225 EXP Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files vi… Patch early 4.0 medium 8.9% 2014-05-14
CVE-2011-1715 EXP Directory traversal vulnerability in framework/source/resource/qx/test/part/delay.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2… Patch early 5.0 medium 8.9% 2011-04-18
CVE-2008-0485 EXP Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV… Patch early 9.3 high 8.9% 2008-02-05
CVE-2007-2872 EXP Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of servic… Patch early 6.8 medium 8.9% 2007-06-04
CVE-2011-0761 EXP Perl 5.10.x allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) by leveraging an ability… Patch early 5.0 medium 8.9% 2011-05-13
CVE-2006-4829 EXP Multiple cross-site scripting (XSS) vulnerabilities in David Czarnecki Blojsom 2.31 allow remote attackers to inject arbitrary web script or HTML via… Patch early 6.8 medium 8.9% 2006-09-15
CVE-2014-9000 EXP Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to… Patch early 6.5 medium 8.9% 2014-11-20
CVE-2019-19743 EXP On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal. Patch early 6.5 medium 8.9% 2019-12-16
CVE-2006-3104 EXP users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals the install… Patch early 5.0 medium 8.9% 2006-06-21
CVE-2007-5253 EXP c32web.exe in McMurtrey/Whitaker Cart32 before 6.4 allows remote attackers to read arbitrary files via the ImageName parameter in a GetImage action, b… Patch early 5.0 medium 8.9% 2007-10-06
CVE-2006-2175 EXP PHP remote file inclusion vulnerability in FtrainSoft Fast Click 2.3.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 6.4 medium 8.9% 2006-05-04
CVE-2013-0145 EXP Buffer overflow in the TFTPD service in Serva32 2.1.0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrar… Patch early 5.0 medium 8.9% 2013-05-20
CVE-2004-1444 EXP Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ com… Patch early 5.0 medium 8.9% 2004-12-31
CVE-2018-19287 EXP XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (… Patch early 6.1 medium 8.9% 2018-11-15
CVE-2007-0976 EXP Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary code via a long DVD_TOOLS.OpenDVD… Patch early 10.0 high 8.9% 2007-02-16
CVE-2009-0134 EXP Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers t… Patch early 9.3 high 8.9% 2009-01-16
CVE-2007-3619 EXP Directory traversal vulnerability in login.php in Maia Mailguard 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 5.0 medium 8.9% 2007-07-09
CVE-2002-2072 EXP java.security.AccessController in Sun Java Virtual Machine (JVM) in JRE 1.2.2 and 1.3.1 allows remote attackers to cause a denial of service (JVM cras… Patch early 5.0 medium 8.9% 2002-12-31
CVE-2014-4937 EXP Directory traversal vulnerability in includes/bookx_export.php BookX plugin 1.7 for WordPress allows remote attackers to read arbitrary files via a ..… Patch early 5.0 medium 8.9% 2014-07-11
CVE-1999-0283 EXP The Java Web Server would allow remote users to obtain the source code for CGI programs. Patch early 10.0 high 8.9% 1999-01-01
← previous page 228 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt