peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,733 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

205,579 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-5603 EXP The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors,… Patch early 6.5 medium 59.3% 2015-09-21
CVE-2008-5081 EXP The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause… Patch early 5.0 medium 59.2% 2008-12-17
CVE-2018-8770 EXP Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, contr… Patch early 5.3 medium 59.2% 2018-03-18
CVE-2019-0221 EXP The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is,… Patch early 6.1 medium 59.2% 2019-05-28
CVE-2008-2463 EXP The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Offic… Patch early 6.8 medium 59.1% 2008-07-07
CVE-2007-3386 EXP Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to… Patch early 4.3 medium 59% 2007-08-14
CVE-2008-0506 EXP include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows… Patch early 6.8 medium 58.9% 2008-01-31
CVE-2000-0574 EXP FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle… Patch early 5.0 medium 58.9% 2000-07-07
CVE-2006-2212 EXP Buffer overflow in KarjaSoft Sami FTP Server 2.0.2 and earlier allows remote attackers to execute arbitrary code via a long (1) USER or (2) PASS comma… Patch early 6.4 medium 58.9% 2006-05-05
CVE-2012-4347 EXP Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated users to r… Patch early 5.0 medium 58.8% 2012-12-05
CVE-2013-1559 EXP Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated… Patch early 4.0 medium 58.8% 2013-04-17
CVE-2019-5485 EXP NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository na… Patch early 10.0 critical 58.8% 2019-09-13
CVE-2002-0654 EXP Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .v… Patch early 5.0 medium 58.7% 2002-09-05
CVE-2004-1305 EXP The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers… Patch early 5.0 medium 58.6% 2004-12-23
CVE-2019-12347 EXP In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit… Patch early 6.1 medium 58.6% 2019-05-29
CVE-2018-0780 EXP Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compr… Patch early 5.3 medium 58.6% 2018-01-04
CVE-2006-2237 EXP The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metacharac… Patch early 5.1 medium 58.4% 2006-05-08
CVE-2004-2115 EXP Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script… Patch early 6.8 medium 58.4% 2004-12-31
CVE-2007-1355 EXP Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 throug… Patch early 4.3 medium 58.2% 2007-05-21
CVE-2019-6111 EXP An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent… Patch early 5.9 medium 58.2% 2019-01-31
CVE-2006-0848 EXP The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to execute arbitrary commands by tr… Patch early 5.1 medium 58.1% 2006-02-22
CVE-2019-14931 EXP An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote… Patch early 9.8 critical 58.1% 2019-10-28
CVE-2000-0408 EXP IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions… Patch early 5.0 medium 58% 2000-05-11
CVE-2008-0081 EXP Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to… Patch early 9.8 critical 57.9% 2008-01-16
CVE-2018-7314 EXP SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429. Patch early 9.8 critical 57.8% 2018-02-22
CVE-2019-10475 EXP A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages… Patch early 6.1 medium 57.7% 2019-10-23
CVE-2018-6605 EXP SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHov… Patch early 9.8 critical 57.7% 2018-02-05
CVE-2014-5377 EXP ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct… Patch early 5.0 medium 57.5% 2014-09-04
CVE-2016-8582 EXP A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve da… Patch early 9.8 critical 57.4% 2016-10-28
CVE-2017-6526 EXP An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected admi… Patch early 9.8 critical 57.4% 2017-03-09
← previous page 44 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt