peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,759 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

169,127 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-4787 EXP Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a URL with a hostname containing… Patch early 5.8 medium 13.6% 2008-10-29
CVE-2010-1352 EXP Directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote attackers to read arbitrary fi… Patch early 5.0 medium 13.6% 2010-04-12
CVE-2010-1491 EXP Directory traversal vulnerability in the MMS Blog (com_mmsblog) component 2.3.0 for Joomla! allows remote attackers to read arbitrary files and possib… Patch early 5.0 medium 13.6% 2010-04-23
CVE-2006-3121 EXP The peel_netstring function in cl_netstring.c in the heartbeat subsystem in High-Availability Linux before 1.2.5, and 2.0 before 2.0.7, allows remote… Patch early 5.0 medium 13.6% 2006-08-17
CVE-2006-0179 EXP The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary p… Patch early 5.0 medium 13.6% 2006-01-11
CVE-1999-0140 EXP Denial of service in RAS/PPTP on NT systems. Patch early 5.0 medium 13.6% 1999-06-30
CVE-2006-4227 EXP MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine… Patch early 6.5 medium 13.6% 2006-08-18
CVE-2014-5465 EXP Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress allows remote attackers to re… Patch early 5.0 medium 13.5% 2014-09-03
CVE-2006-3210 EXP Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers to conduct PHP remote file inc… Patch early 5.1 medium 13.5% 2006-06-24
CVE-2011-0421 EXP The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argume… Patch early 4.3 medium 13.5% 2011-03-20
CVE-2005-1267 EXP The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attacker… Patch early 5.0 medium 13.5% 2005-06-10
CVE-2005-0815 EXP Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corr… Patch early 6.4 medium 13.4% 2005-05-02
CVE-2005-3737 EXP Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute arbitrary code via a SVG file… Patch early 5.1 medium 13.4% 2005-11-22
CVE-1999-0196 EXP websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variabl… Patch early 5.0 medium 13.4% 1997-07-08
CVE-2017-1000373 EXP The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort()… Patch early 6.5 medium 13.4% 2017-06-19
CVE-2013-2683 EXP Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresse… Patch early 5.3 medium 13.4% 2020-02-06
CVE-2002-2062 EXP Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP si… Patch early 4.3 medium 13.3% 2002-12-31
CVE-2010-3709 EXP The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of… Patch early 4.3 medium 13.3% 2010-11-09
CVE-2019-12477 EXP Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authe… Patch early 5.5 medium 13.3% 2019-06-07
CVE-2015-4153 EXP Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to include and execute arb… Patch early 5.0 medium 13.3% 2015-06-10
CVE-2007-3473 EXP The gdImageCreateXbm function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (cra… Patch early 4.3 medium 13.3% 2007-06-28
CVE-2013-4858 EXP Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) via a crafted .wav… Patch early 4.3 medium 13.3% 2013-12-30
CVE-2009-5114 EXP Directory traversal vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 5.0 medium 13.3% 2012-03-19
CVE-2015-2791 EXP The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a craft… Patch early 6.4 medium 13.3% 2015-03-30
CVE-2007-4430 EXP Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routi… Patch early 5.0 medium 13.3% 2007-08-20
CVE-2011-1468 EXP Multiple memory leaks in the OpenSSL extension in PHP before 5.3.6 might allow remote attackers to cause a denial of service (memory consumption) via… Patch early 4.3 medium 13.3% 2011-03-20
CVE-2010-0442 EXP The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of se… Patch early 6.5 medium 13.3% 2010-02-02
CVE-2018-14335 EXP An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of th… Patch early 6.5 medium 13.2% 2018-07-24
CVE-2018-7921 EXP Huawei B315s-22 products with software of 21.318.01.00.26 have an information leak vulnerability. Unauthenticated adjacent attackers may exploit this… Patch early 6.5 medium 13.2% 2018-09-12
CVE-2002-1542 EXP SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a… Patch early 5.0 medium 13.2% 2003-03-31
← previous page 47 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt