peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,692 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

205,558 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-0802 EXP Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might al… Patch early 5.0 medium 67.3% 2015-04-01
CVE-2012-0694 EXP SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code. Patch early 9.8 critical 67.3% 2019-10-29
CVE-2004-0176 EXP Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the… Patch early 5.0 medium 67.1% 2004-05-04
CVE-2019-13101 EXP An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead… Patch early 9.8 critical 67.1% 2019-08-08
CVE-2015-0816 EXP Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier… Patch early 5.0 medium 66.9% 2015-04-01
CVE-2016-7237 EXP Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Win… Patch early 6.5 medium 66.9% 2016-11-10
CVE-2019-6443 EXP An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read in read_sysvars in ntp_contro… Patch early 9.1 critical 66.9% 2019-01-16
CVE-2012-2962 EXP SQL injection vulnerability in d4d/statusFilter.php in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.2 allows remote authenticated us… Patch early 6.5 medium 66.8% 2012-07-30
CVE-2017-11394 EXP Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable install… Patch early 9.8 critical 66.8% 2017-08-03
CVE-2005-0478 EXP Multiple buffer overflows in TrackerCam 5.12 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (… Patch early 5.0 medium 66.5% 2005-03-30
CVE-2021-32172 EXP Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin. Patch early 9.8 critical 66.4% 2021-10-07
CVE-2014-6593 EXP Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.8.4 and 28.3.4 allows remote a… Patch early 4.0 medium 66.4% 2015-01-21
CVE-2021-37425 EXP Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobil… Patch early 9.1 critical 66.3% 2021-08-10
CVE-2012-2926 EXP Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, a… Patch early 9.1 critical 66.3% 2012-05-22
CVE-2007-3522 EXP Multiple PHP remote file inclusion vulnerabilities in sPHPell 1.01 allow remote attackers to execute arbitrary PHP code via a URL in the SpellIncPath… Patch early 6.8 medium 66.2% 2007-07-03
CVE-2017-6360 EXP QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors. Patch early 9.8 critical 66.1% 2017-03-23
CVE-2025-55315 EXP Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security fe… Patch early 9.9 critical 65.9% 2025-10-14
CVE-2019-10123 EXP SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an anonymous attacker t… Patch early 9.8 critical 65.9% 2019-05-31
CVE-2015-2295 EXP Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attackers… Patch early 6.8 medium 65.7% 2015-04-10
CVE-2017-14147 EXP An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its f… Patch early 9.8 critical 65.6% 2017-09-07
CVE-2001-1013 EXP Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html dir… Patch early 5.0 medium 65.6% 2001-09-12
CVE-2018-0767 EXP Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise… Patch early 5.3 medium 65.5% 2018-01-04
CVE-2002-1744 EXP Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the existence of arbi… Patch early 5.0 medium 65.2% 2002-12-31
CVE-2025-27218 EXP Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization. Patch early 5.3 medium 65% 2025-02-20
CVE-2016-10175 EXP The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user… Patch early 9.8 critical 65% 2017-01-30
CVE-2015-6973 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of a… Patch early 6.8 medium 64.8% 2015-09-16
CVE-1999-0278 EXP In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL. Patch early 5.0 medium 64.8% 1998-06-01
CVE-2008-0455 EXP Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and ear… Patch early 4.3 medium 64.8% 2008-01-25
CVE-2020-7115 EXP The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker coul… Patch early 9.8 critical 64.6% 2020-06-03
CVE-2010-4094 EXP The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier fo… Patch early 5.0 medium 64.5% 2010-10-26
← previous page 41 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt