peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,355 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

322,095 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-5335 EXP Directory traversal vulnerability in Tiny Server 1.1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the URI of an H… Patch early 4.0 medium 6.5% 2012-10-08
CVE-2007-5320 EXP Multiple absolute path traversal vulnerabilities in Pegasus Imaging ImagXpress 8.0 allow remote attackers to (1) delete arbitrary files via the CacheF… Patch early 4.0 medium 6.5% 2007-10-09
CVE-2006-5758 EXP The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memo… Patch early 7.2 high 6.5% 2006-11-06
CVE-2007-1251 EXP Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0, when EVENTLOG is enabled, allows remote… Patch early 9.3 high 6.5% 2007-03-03
CVE-2007-2483 EXP Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, al… Patch early 6.8 medium 6.5% 2007-05-03
CVE-2006-0304 EXP Buffer overflow in Dual DHCP DNS Server 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary co… Patch early 7.5 high 6.5% 2006-01-19
CVE-2002-1001 EXP Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long… Patch early 7.5 high 6.5% 2002-10-04
CVE-2019-10963 EXP Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow se… Patch early 4.3 medium 6.5% 2019-10-08
CVE-2002-0206 EXP index.php in Francisco Burzi PHP-Nuke 5.3.1 and earlier, and possibly other versions before 5.5, allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 6.5% 2002-05-16
CVE-2012-6653 EXP Unspecified vulnerability in the All Video Gallery (all-video-gallery) plugin before 1.2.0 for WordPress has unspecified impact and attack vectors. Patch early 7.5 high 6.5% 2014-08-06
CVE-2016-10079 EXP SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP port 515. Patch early 7.5 high 6.5% 2017-02-01
CVE-2009-4142 EXP The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) inv… Patch early 4.3 medium 6.5% 2009-12-21
CVE-2018-10577 EXP An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10.… Patch early 8.8 high 6.5% 2018-05-02
CVE-2016-1910 EXP The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290. Patch early 5.3 medium 6.5% 2016-01-15
CVE-2013-2624 EXP Telean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive information through a special… Patch early 5.3 medium 6.5% 2020-02-03
CVE-2007-2832 EXP Cross-site scripting (XSS) vulnerability in the web application firewall in Cisco CallManager before 3.3(5)sr3, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3… Patch early 4.3 medium 6.5% 2007-05-24
CVE-2015-6995 EXP The Disk Images component in Apple iOS before 9.1 and OS X before 10.11.1 misparses images, which allows attackers to execute arbitrary code or cause… Patch early 6.8 medium 6.5% 2015-10-23
CVE-2001-1290 EXP admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify the configuration, gain privileg… Patch early 5.0 medium 6.5% 2001-06-28
CVE-2018-4386 EXP Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1… Patch early 8.8 high 6.5% 2019-04-03
CVE-2011-3336 EXP regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion. Patch early 7.5 high 6.5% 2020-02-12
CVE-2004-2677 EXP Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format… Patch early 7.5 high 6.5% 2004-12-31
CVE-2011-5166 EXP Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string to the (1) USER, (2) PASS, (3)… Patch early 7.5 high 6.5% 2012-09-15
CVE-2001-0466 EXP Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. Patch early 5.0 medium 6.5% 2001-06-18
CVE-2022-3766 EXP Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8. Patch early 6.1 medium 6.5% 2022-10-31
CVE-2001-0075 EXP Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename pa… Patch early 5.0 medium 6.5% 2001-02-12
CVE-2001-0293 EXP Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command. Patch early 5.0 medium 6.5% 2001-05-03
CVE-2001-0305 EXP Directory traversal vulnerability in store.cgi in Thinking Arts ES.One package allows remote attackers to read arbitrary files via a .. (dot dot) in t… Patch early 5.0 medium 6.5% 2001-05-03
CVE-2025-32023 EXP Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use… Patch early 7.0 high 6.5% 2025-07-07
CVE-2017-2476 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… Patch early 8.8 high 6.5% 2017-04-02
CVE-2010-2435 EXP Weborf HTTP Server 0.12.1 and earlier allows remote attackers to cause a denial of service (crash) via Unicode characters in a Connection HTTP header,… Patch early 5.0 medium 6.5% 2010-06-24
← previous page 290 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt