peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,587 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

169,049 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-3605 EXP Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Transition property on an uninitialized DXIm… Patch early 5.0 medium 24.3% 2006-07-18
CVE-2006-3898 EXP Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the Click method… Patch early 5.0 medium 24.3% 2006-07-27
CVE-2006-3512 EXP Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) by setting the Enabled property of a DXTFilter ActiveX… Patch early 5.0 medium 24.3% 2006-07-11
CVE-2006-3427 EXP Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL attribute on an uninitialized Di… Patch early 5.0 medium 24.3% 2006-07-07
CVE-2002-1700 EXP Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary scri… Patch early 4.3 medium 24.3% 2002-12-31
CVE-2016-5725 EXP Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write… Patch early 5.9 medium 24.1% 2017-01-19
CVE-2006-3101 EXP Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 24% 2006-06-21
CVE-2012-5611 EXP Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.… Patch early 6.5 medium 24% 2012-12-03
CVE-2020-9467 EXP Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function. Patch early 5.4 medium 23.8% 2020-03-26
CVE-2001-0205 EXP Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by inserting "..." into the requested p… Patch early 5.0 medium 23.6% 2001-05-03
CVE-2008-1126 EXP PHP remote file inclusion vulnerability in main.php in Barryvan Compo Manager 0.3 allows remote attackers to execute arbitrary PHP code via a URL in t… Patch early 6.8 medium 23.6% 2008-03-03
CVE-2013-3585 EXP Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information v… Patch early 5.0 medium 23.5% 2013-08-28
CVE-2010-4476 EXP The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and ear… Patch early 5.0 medium 23.5% 2011-02-17
CVE-2008-0566 EXP PHP remote file inclusion vulnerability in includes/smarty.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary… Patch early 6.8 medium 23.5% 2008-02-05
CVE-2018-8533 EXP An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a refere… Patch early 5.5 medium 23.4% 2018-10-10
CVE-2018-8532 EXP An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a refere… Patch early 5.5 medium 23.4% 2018-10-10
CVE-2018-8527 EXP An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a referen… Patch early 5.5 medium 23.4% 2018-10-10
CVE-2005-0452 EXP Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or… Patch early 4.3 medium 23.4% 2005-02-16
CVE-2011-4106 EXP TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute… Patch early 6.8 medium 23.3% 2013-10-26
CVE-2006-3897 EXP Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating a… Patch early 5.0 medium 23.3% 2006-07-27
CVE-2003-0002 EXP Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to exec… Patch early 6.8 medium 23.3% 2003-02-07
CVE-2013-5528 EXP Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users… Patch early 4.0 medium 23.3% 2013-10-11
CVE-1999-0980 EXP Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration reque… Patch early 5.0 medium 23.2% 2000-05-16
CVE-2008-0503 EXP Eval injection vulnerability in admin/op/disp.php in Netwerk Smart Publisher 1.0.1 allows remote attackers to execute arbitrary PHP code via the filed… Patch early 6.8 medium 23.2% 2008-01-31
CVE-2009-1287 EXP Cross-site scripting (XSS) vulnerability in Cisco Subscriber Edge Services Manager (SESM) allows remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 23.1% 2009-04-13
CVE-2006-2094 EXP Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, u… Patch early 5.1 medium 23.1% 2006-04-29
CVE-2011-2007 EXP Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service ou… Patch early 5.0 medium 23% 2011-10-12
CVE-2003-0446 EXP Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote atta… Patch early 4.3 medium 23% 2003-07-24
CVE-2021-44848 EXP In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the us… Patch early 5.3 medium 23% 2021-12-13
CVE-2017-0118 EXP Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT… Patch early 4.3 medium 23% 2017-03-17
← previous page 31 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt