peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,733 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

169,103 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-9648 EXP An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command alon… Patch early 5.3 medium 14.3% 2019-03-22
CVE-2011-1071 EXP The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause… Patch early 5.1 medium 14.3% 2011-04-08
CVE-2021-45901 EXP The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists… Patch early 5.3 medium 14.3% 2022-02-10
CVE-2002-0976 EXP Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xm… Patch early 6.4 medium 14.3% 2002-09-24
CVE-2003-0562 EXP Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long… Patch early 5.0 medium 14.3% 2003-08-27
CVE-2019-13383 EXP In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a username is valid by reading the HT… Patch early 5.3 medium 14.2% 2019-07-16
CVE-2013-3179 EXP Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 allows remote attackers to inject arbitra… Patch early 4.3 medium 14.2% 2013-09-11
CVE-2006-1172 EXP Stack-based buffer overflow in the createPKCS10 function in Cryptomathic Cenroll ActiveX Control 1.1.0.0 allows remote attackers to execute arbitrary… Patch early 5.0 medium 14.2% 2006-05-09
CVE-2013-1597 EXP A Directory Traversal vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via a specially crafted GET request, which could let a malicio… Patch early 6.5 medium 14.2% 2020-01-24
CVE-2018-0891 EXP ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and… Patch early 4.3 medium 14.2% 2018-03-14
CVE-2011-4451 EXP libs/Wakka.class.php in WikkaWiki 1.3.1 and 1.3.2, when the spam_logging option is enabled, allows remote attackers to write arbitrary PHP code to the… Patch early 4.3 medium 14.2% 2012-09-05
CVE-2012-2138 EXP The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to cop… Patch early 5.0 medium 14.1% 2012-07-09
CVE-2017-0211 EXP An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Se… Patch early 5.5 medium 14.1% 2017-04-12
CVE-2019-6445 EXP An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can cause a NULL pointer dereference and ntpd crash in ntp_control.c, relate… Patch early 6.5 medium 14.1% 2019-01-16
CVE-2022-29593 EXP relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post requests without the need for authen… Patch early 5.9 medium 14% 2022-07-14
CVE-2010-0944 EXP Directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to read arbitrary files via a ..… Patch early 5.0 medium 14% 2010-03-08
CVE-2010-1304 EXP Directory traversal vulnerability in userstatus.php in the User Status (com_userstatus) component 1.21.16 for Joomla! allows remote attackers to read… Patch early 5.0 medium 14% 2010-04-08
CVE-2015-2068 EXP Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to injec… Patch early 4.3 medium 14% 2015-02-24
CVE-2015-6176 EXP Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism… Patch early 4.3 medium 14% 2015-12-09
CVE-2010-1308 EXP Directory traversal vulnerability in the SVMap (com_svmap) component 1.1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot d… Patch early 5.0 medium 14% 2010-04-08
CVE-2006-2557 EXP PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newsportal (TRanx rebuilded), allows… Patch early 6.4 medium 14% 2006-05-24
CVE-2008-5551 EXP The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by inj… Patch early 4.3 medium 14% 2008-12-12
CVE-2010-1659 EXP Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote attackers to read arbitrar… Patch early 5.0 medium 14% 2010-05-03
CVE-2000-1112 EXP Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that c… Patch early 4.6 medium 14% 2001-01-09
CVE-2007-4965 EXP Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (applicati… Patch early 5.8 medium 14% 2007-09-18
CVE-2021-24286 EXP The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, l… Patch early 6.1 medium 13.9% 2021-05-14
CVE-2013-3526 EXP Cross-site scripting (XSS) vulnerability in js/ta_loaded.js.php in the Traffic Analyzer plugin, possibly 3.3.2 and earlier, for WordPress allows remot… Patch early 4.3 medium 13.9% 2013-05-10
CVE-2008-1933 EXP Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to overwrite arbitrary files via the… Patch early 4.3 medium 13.9% 2008-04-25
CVE-2008-2666 EXP Multiple directory traversal vulnerabilities in PHP 5.2.6 and earlier allow context-dependent attackers to bypass safe_mode restrictions by creating a… Patch early 5.0 medium 13.9% 2008-06-20
CVE-2005-1275 EXP Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of servic… Patch early 5.0 medium 13.9% 2005-04-25
← previous page 45 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt