peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,612 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

169,057 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-2949 EXP Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change the location property of a frame via the String da… Patch early 6.8 medium 20.5% 2008-06-30
CVE-2000-0676 EXP Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a… Patch early 5.0 medium 20.5% 2000-10-20
CVE-2008-0237 EXP The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure Sav… Patch early 6.8 medium 20.5% 2008-01-11
CVE-1999-0681 EXP Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause… Patch early 5.0 medium 20.5% 2001-03-12
CVE-2024-38200 EXP Microsoft Office Spoofing Vulnerability Patch early 6.5 medium 20.5% 2024-08-12
CVE-2016-3717 EXP The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image. Patch early 5.5 medium 20.4% 2016-05-05
CVE-2013-1451 EXP Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, doe… Patch early 4.0 medium 20.4% 2013-01-29
CVE-2010-0740 EXP The ssl3_get_record function in ssl/s3_pkt.c in OpenSSL 0.9.8f through 0.9.8m allows remote attackers to cause a denial of service (crash) via a malfo… Patch early 5.0 medium 20.4% 2010-03-26
CVE-2014-5258 EXP Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitrary files… Patch early 4.0 medium 20.3% 2014-11-06
CVE-2004-0791 EXP Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a… Patch early 5.0 medium 20.3% 2005-04-12
CVE-2008-6825 EXP Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to include and execute arbitrary… Patch early 6.8 medium 20.3% 2009-06-05
CVE-2005-1381 EXP Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) ca… Patch early 6.8 medium 20.2% 2005-05-03
CVE-2004-0502 EXP Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the original message,… Patch early 5.0 medium 20.2% 2004-08-18
CVE-2005-3559 EXP Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) in… Patch early 5.0 medium 20.2% 2005-11-16
CVE-2015-6908 EXP The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable ass… Patch early 5.0 medium 20% 2015-09-11
CVE-2004-2383 EXP Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from othe… Patch early 5.1 medium 20% 2004-12-31
CVE-1999-0107 EXP Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a lar… Patch early 5.0 medium 19.9% 1997-12-30
CVE-2018-1322 EXP An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x whi… Patch early 4.9 medium 19.9% 2018-03-20
CVE-2019-19742 EXP On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field. Patch early 4.8 medium 19.8% 2019-12-18
CVE-2005-3207 EXP The forms servlet (f90servlet) in Oracle Forms 4.5.10.22 allows remote attackers to cause a denial of service (TNS listener stop) via a userid paramet… Patch early 5.0 medium 19.8% 2005-10-14
CVE-2015-4148 EXP The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property i… Patch early 5.0 medium 19.8% 2015-06-09
CVE-2014-8768 EXP Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denia… Patch early 5.0 medium 19.8% 2014-11-20
CVE-2018-4934 EXP Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to informa… Patch early 6.5 medium 19.8% 2018-05-19
CVE-2011-2202 EXP The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, whi… Patch early 6.4 medium 19.7% 2011-06-16
CVE-2007-0247 EXP squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing respo… Patch early 5.0 medium 19.7% 2007-01-16
CVE-2013-2679 EXP Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitr… Patch early 6.1 medium 19.6% 2020-02-18
CVE-2013-7240 EXP Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary fi… Patch early 5.0 medium 19.6% 2014-01-03
CVE-2004-1306 EXP Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers t… Patch early 5.1 medium 19.6% 2004-12-31
CVE-2000-0168 EXP Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Dev… Patch early 5.0 medium 19.6% 2000-03-04
CVE-1999-1577 EXP Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands… Patch early 5.1 medium 19.5% 1999-10-31
← previous page 36 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt