peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,733 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

205,579 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-0277 EXP Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execu… Patch early 5.0 medium 61.9% 2005-05-02
CVE-2007-1061 EXP SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote a… Patch early 6.8 medium 61.8% 2007-02-22
CVE-2016-1209 EXP The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in… Patch early 9.8 critical 61.6% 2016-05-14
CVE-2017-8835 EXP SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7… Patch early 9.8 critical 61.6% 2017-06-05
CVE-2007-3632 EXP Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a… Patch early 6.8 medium 61.5% 2007-07-10
CVE-2018-16836 EXP Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbit… Patch early 9.8 critical 61.4% 2018-09-11
CVE-2005-2087 EXP Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a… Patch early 5.0 medium 61.4% 2005-07-05
CVE-2018-6329 EXP It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a remote at… Patch early 9.8 critical 61.2% 2018-03-14
CVE-2017-5941 EXP An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to ach… Patch early 9.8 critical 61% 2017-02-09
CVE-2019-7304 EXP Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issu… Patch early 9.8 critical 60.8% 2019-04-23
CVE-2018-7756 EXP RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit) devices does not require authentication for sessions on TCP port 1999, which allows remot… Patch early 9.8 critical 60.7% 2018-03-15
CVE-2013-1428 EXP Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated… Patch early 6.5 medium 60.7% 2013-04-26
CVE-2013-4074 EXP The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 in… Patch early 5.0 medium 60.6% 2013-06-09
CVE-2018-3639 EXP Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes… Patch early 5.5 medium 60.6% 2018-05-22
CVE-2006-5198 EXP The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers… Patch early 4.0 medium 60.4% 2006-11-14
CVE-2004-0184 EXP Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP pack… Patch early 5.0 medium 60.3% 2004-05-04
CVE-2017-15222 EXP Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code. Patch early 9.8 critical 60.3% 2017-10-24
CVE-2015-8399 EXP Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdef… Patch early 4.3 medium 60.2% 2016-04-11
CVE-2010-2333 EXP LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a… Patch early 5.0 medium 60.2% 2010-06-18
CVE-2021-24499 EXP The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks,… Patch early 9.8 critical 60.1% 2021-08-09
CVE-2007-4744 EXP PHP remote file inclusion vulnerability in environment.php in AnyInventory 1.9.1 and 2.0, when register_globals is enabled, allows remote attackers to… Patch early 6.8 medium 60.1% 2007-09-06
CVE-2014-100002 EXP Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot… Patch early 5.0 medium 59.9% 2015-01-13
CVE-2013-3763 EXP Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to aff… Patch early 5.5 medium 59.8% 2013-07-17
CVE-2011-4404 EXP The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Up… Patch early 5.0 medium 59.7% 2011-11-19
CVE-2011-4317 EXP The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch i… Patch early 4.3 medium 59.6% 2011-11-30
CVE-2013-5880 EXP Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.0, 12.2.1, and 12.2.2 allows r… Patch early 5.0 medium 59.6% 2014-01-15
CVE-2013-7108 EXP Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote au… Patch early 5.5 medium 59.5% 2014-01-15
CVE-2013-5795 EXP Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 1… Patch early 5.0 medium 59.5% 2014-01-15
CVE-2007-3813 EXP PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitrary PHP c… Patch early 4.3 medium 59.4% 2007-07-17
CVE-2012-2576 EXP SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWi… Patch early 9.8 critical 59.4% 2017-12-20
← previous page 43 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt