peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,240 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

321,946 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-1389 EXP Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote attackers to inject arbitrary we… Patch early 4.3 medium 6.8% 2015-05-28
CVE-2009-2557 EXP Directory traversal vulnerability in system/download.php in Admin News Tools 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in… Patch early 5.0 medium 6.8% 2009-07-21
CVE-2017-15639 EXP tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature. Patch early 6.5 medium 6.8% 2017-10-19
CVE-2008-1136 EXP The Utils::runScripts function in src/utils.cpp in vdccm 0.92 through 0.10.0 in SynCE (SynCE-dccm) allows remote attackers to execute arbitrary comman… Patch early 9.3 high 6.8% 2008-03-04
CVE-2006-5308 EXP Multiple PHP remote file inclusion vulnerabilities in Open Conference Systems (OCS) before 1.1.6 allow remote attackers to execute arbitrary PHP code… Patch early 7.5 high 6.8% 2006-10-17
CVE-2006-2875 EXP Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remote attacker… Patch early 7.5 high 6.8% 2006-06-07
CVE-2003-0488 EXP Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) the add_na… Patch early 5.1 medium 6.8% 2003-08-07
CVE-2015-3001 EXP SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which allows remote authenticated user… Patch early 5.0 medium 6.8% 2015-06-08
CVE-2006-4875 EXP Unrestricted file upload vulnerability in modules/galleryuploadfunction.php in Jupiter CMS allows remote attackers to upload picture files, and possib… Patch early 5.0 medium 6.8% 2006-09-19
CVE-2022-34127 EXP The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.php file parameter. Patch early 7.5 high 6.8% 2023-04-16
CVE-2009-1497 EXP Stack-based buffer overflow in srt2smi.exe in Gretech Online Movie Player (GOM Player) 2.1.16.4635 allows remote attackers to cause a denial of servic… Patch early 9.3 high 6.8% 2009-05-01
CVE-2010-2329 EXP Buffer overflow in Rosoft Audio Converter 4.4.4 allows remote attackers to execute arbitrary code via a long playlist entry in a .m3u file. Patch early 9.3 high 6.8% 2010-06-18
CVE-2006-6288 EXP Multiple buffer overflows in Niek Albers CoolPlayer 216 and earlier allow remote attackers to execute arbitrary code via (1) a playlist file with long… Patch early 4.6 medium 6.8% 2006-12-04
CVE-2017-2455 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… Patch early 8.8 high 6.8% 2017-04-02
CVE-2004-1567 EXP profile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the value for a… Patch early 7.5 high 6.8% 2004-12-31
CVE-2004-2172 EXP EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via a chosen plaintex… Patch early 7.5 high 6.8% 2004-12-31
CVE-2020-2229 EXP Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS)… Patch early 5.4 medium 6.8% 2020-08-12
CVE-2015-8740 EXP The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x before 2.0.1 does not validate the… Patch early 5.3 medium 6.8% 2016-01-04
CVE-2007-6493 EXP The IMWeb.IMWebControl.1 ActiveX control in IMWeb.dll 7.0.0.x, and possibly IMWebControl.dll, in iMesh 7.1.0.x and earlier allows remote attackers to… Patch early 10.0 high 6.8% 2007-12-20
CVE-2014-8657 EXP The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to cause a den… Patch early 5.0 medium 6.8% 2014-11-06
CVE-2009-4755 EXP Multiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via a long string in a malformed (… Patch early 9.3 high 6.8% 2010-03-29
CVE-2016-7644 EXP An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. Th… Patch early 7.8 high 6.8% 2017-02-20
CVE-2003-1137 EXP Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an as… Patch early 5.0 medium 6.8% 2003-10-27
CVE-2015-4040 EXP Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 through 3.1.1 allows remote aut… Patch early 4.0 medium 6.8% 2015-09-17
CVE-2007-6213 EXP Multiple directory traversal vulnerabilities in mod/chat/index.php in WebED 0.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in… Patch early 5.0 medium 6.8% 2007-12-04
CVE-2012-4334 EXP The ConnectDDNS method in the (1) STWConfigNVR 1.1.13.15 and (2) STWConfig 1.1.14.13 ActiveX controls in Samsung NET-i viewer 1.37.120316 allows remot… Patch early 10.0 high 6.8% 2012-08-14
CVE-2006-2437 EXP The viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to obtain the source code for… Patch early 5.0 medium 6.8% 2006-05-17
CVE-2008-1084 EXP Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP1, and Server 2008 allows loca… Patch early 7.2 high 6.8% 2008-04-08
CVE-2008-4050 EXP A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to (1) create and… Patch early 9.3 high 6.7% 2008-09-11
CVE-2007-0845 EXP admin/index.php in Advanced Poll 2.0.0 through 2.0.5-dev allows remote attackers to bypass authentication and gain administrator privileges by obtaini… Patch early 7.5 high 6.7% 2007-02-08
← previous page 283 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt