peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,041 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

321,045 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-2024 EXP Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors… Patch early 4.0 medium 8.7% 2006-04-25
CVE-2000-1023 EXP The Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers to modify domain name informati… Patch early 7.5 high 8.6% 2000-12-11
CVE-2009-0177 EXP vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6.5.1 build 126130, 6.5.1 and earlier; VMware Player… Patch early 5.0 medium 8.6% 2009-01-20
CVE-2005-1112 EXP IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code… Patch early 5.0 medium 8.6% 2005-05-02
CVE-2002-1222 EXP Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of ser… Patch early 7.1 high 8.6% 2002-10-28
CVE-2012-0788 EXP The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of… Patch early 5.0 medium 8.6% 2012-02-14
CVE-2008-0418 EXP Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addon… Patch early 4.3 medium 8.6% 2008-02-08
CVE-2008-5334 EXP PHP remote file inclusion vulnerability in includes/common.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 10.0 high 8.6% 2008-12-05
CVE-2012-6708 EXP jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a… Patch early 6.1 medium 8.6% 2018-01-18
CVE-2009-2620 EXP src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote at… Patch early 5.0 medium 8.6% 2009-07-29
CVE-2017-11154 EXP Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to c… Patch early 7.2 high 8.6% 2017-08-08
CVE-2022-46604 EXP An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP fil… Patch early 8.8 high 8.6% 2023-02-02
CVE-1999-0060 EXP Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Conf… Patch early 5.0 medium 8.6% 1998-03-16
CVE-2008-3432 EXP Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and 6.3 allows user-assisted attackers to execute arbitrary co… Patch early 6.8 medium 8.6% 2008-10-10
CVE-2005-4135 EXP Direct static code injection vulnerability in includes/newtopic.php in SimpleBBS 1.1 and earlier allows remote attackers to execute arbitrary commands… Patch early 7.5 high 8.6% 2005-12-09
CVE-2023-33145 EXP Microsoft Edge (Chromium-based) Information Disclosure Vulnerability Patch early 6.5 medium 8.6% 2023-06-14
CVE-2010-3133 EXP Untrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and 1.2.0 through 1.2.10 allows local users, and possibly remote attackers, to e… Patch early 9.3 high 8.6% 2010-08-26
CVE-2002-0552 EXP Multiple buffer overflows in Melange Chat server 2.02 allow remote or local attackers to cause a denial of service (crash) and possibly execute arbitr… Patch early 7.5 high 8.6% 2002-07-03
CVE-2003-0328 EXP EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service (crash) and… Patch early 7.5 high 8.6% 2003-06-09
CVE-2005-2961 EXP Buffer overflow in the get_string_ahref function for ProZilla 1.3.7.4 and possibly earlier, with the -ftpsearch option enabled, allows remote servers… Patch early 7.5 high 8.6% 2005-10-05
CVE-2007-2776 EXP AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, whi… Patch early 10.0 high 8.6% 2007-05-21
CVE-2011-4715 EXP Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlier allows r… Patch early 5.0 medium 8.6% 2011-12-08
CVE-2020-9372 EXP The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to b… Patch early 7.8 high 8.6% 2020-03-04
CVE-2007-4737 EXP Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code… Patch early 7.5 high 8.6% 2007-09-06
CVE-2017-6367 EXP In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology involves a long Host header and an… Patch early 7.5 high 8.6% 2017-03-14
CVE-2005-0879 EXP PHP remote file include vulnerability in (1) content.php and (2) index.php for Vortex Portal allows remote attackers to execute arbitrary PHP code via… Patch early 7.5 high 8.6% 2005-05-02
CVE-2020-5752 EXP Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands w… Patch early 7.8 high 8.6% 2020-05-21
CVE-2009-1549 EXP AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto." Patch early 7.5 high 8.6% 2009-05-06
CVE-2008-7124 EXP zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain ad… Patch early 7.5 high 8.6% 2009-08-31
CVE-2010-3039 EXP /usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated… Patch early 6.8 medium 8.6% 2010-11-09
← previous page 233 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt