peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,367 CVEs 1,739 on KEV 17,299 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

322,109 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-4515 EXP Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers… Patch early 6.8 medium 6.4% 2012-11-11
CVE-2007-0148 EXP Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary c… Patch early 6.8 medium 6.4% 2007-01-09
CVE-2009-4987 EXP admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative access by setting… Patch early 7.5 high 6.4% 2010-08-25
CVE-2011-4042 EXP An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute ar… Patch early 9.3 high 6.4% 2012-04-03
CVE-2020-7656 EXP jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that… Patch early 6.1 medium 6.4% 2020-05-19
CVE-2006-0138 EXP aMSN (aka Alvaro's Messenger) allows remote attackers to cause a denial of service (client hang and termination of client's instant-messaging session)… Patch early 5.0 medium 6.4% 2006-01-09
CVE-2008-4918 EXP Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote… Patch early 4.3 medium 6.4% 2008-11-04
CVE-2008-6996 EXP Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for remote attackers or malware to ca… Patch early 5.0 medium 6.4% 2009-08-19
CVE-2001-0566 EXP Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when SNMP is disa… Patch early 5.0 medium 6.4% 2001-08-14
CVE-2009-3717 EXP Heap-based buffer overflow in LucVil PatPlayer 3.9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long U… Patch early 9.3 high 6.4% 2009-10-16
CVE-2007-2827 EXP Heap-based buffer overflow in LEAD Technologies LEADTOOLS ISIS ActiveX Control (ltisi14E.ocx) 14.5.0.44 and earlier allows remote attackers to execute… Patch early 9.3 high 6.4% 2007-05-22
CVE-2007-2981 EXP Buffer overflow in a certain ActiveX control in LEAD Technologies LEADTOOLS Raster OCR Document Object Library (ltrdc14e.dll) 14.5.0.44 allows remote… Patch early 9.3 high 6.4% 2007-06-01
CVE-2006-6295 EXP PHP remote file inclusion vulnerability in includes/mx_common.php in the mx_tinies 1.3.0 Module for MxBB Portal 1.06 allows remote attackers to execut… Patch early 6.8 medium 6.4% 2006-12-05
CVE-2006-5714 EXP Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary files under the web root by app… Patch early 5.0 medium 6.4% 2006-11-04
CVE-2006-5715 EXP Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrary files under the web root by… Patch early 5.0 medium 6.4% 2006-11-04
CVE-2008-5965 EXP Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to check for t… Patch early 5.0 medium 6.4% 2009-01-26
CVE-2013-1464 EXP Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to injec… Patch early 4.3 medium 6.4% 2013-02-07
CVE-2000-0848 EXP Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header. Patch early 10.0 high 6.4% 2000-11-14
CVE-2018-15536 EXP /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extrac… Patch early 5.5 medium 6.4% 2018-08-24
CVE-2018-13110 EXP All ADB broadband gateways / routers based on the Epicentro platform are affected by a privilege escalation vulnerability where attackers can gain acc… Patch early 7.5 high 6.4% 2018-07-06
CVE-2008-7161 EXP Fortinet FortiGuard Fortinet FortiGate-1000 3.00 build 040075,070111 allows remote attackers to bypass URL filtering via fragmented GET or POST reques… Patch early 7.5 high 6.4% 2009-09-04
CVE-2015-1494 EXP The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site sc… Patch early 4.3 medium 6.4% 2015-02-17
CVE-2003-0371 EXP Buffer overflow in Prishtina FTP client 1.x allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a l… Patch early 7.5 high 6.4% 2003-06-16
CVE-2006-6847 EXP An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) b… Patch early 5.0 medium 6.4% 2006-12-31
CVE-2005-0872 EXP Cross-site scripting (XSS) vulnerability in calendar_scheduler.php in the Topic Calendar 1.0.1 module for phpBB allows remote attackers to inject arbi… Patch early 4.3 medium 6.4% 2005-05-02
CVE-2008-5281 EXP Heap-based buffer overflow in Titan FTP Server 6.05 build 550 allows remote attackers to execute arbitrary code via a long DELE command. Patch early 10.0 high 6.4% 2008-11-29
CVE-2008-5071 EXP Multiple eval injection vulnerabilities in itpm_estimate.php in Yoxel 1.23beta and earlier allow remote authenticated users to execute arbitrary PHP c… Patch early 9.0 high 6.4% 2008-11-14
CVE-2014-0997 EXP WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used in the Samsung SM-T310, Android… Patch early 7.5 high 6.4% 2017-09-26
CVE-2009-2966 EXP avp.exe in Kaspersky Internet Security 9.0.0.459 and Anti-Virus 9.0.0.463 allows remote attackers to cause a denial of service (CPU consumption and ne… Patch early 4.3 medium 6.4% 2009-08-25
CVE-2001-0198 EXP Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBE… Patch early 7.6 high 6.4% 2001-05-03
← previous page 292 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt