peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,806 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

169,127 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2011-1471 EXP Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (CPU… Patch early 4.3 medium 13.2% 2011-03-20
CVE-2005-2710 EXP Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) ti… Patch early 5.1 medium 13.2% 2005-09-27
CVE-2012-5614 EXP Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a… Patch early 4.0 medium 13.2% 2012-12-03
CVE-2008-2952 EXP liblber/io.c in OpenLDAP 2.2.4 to 2.4.10 allows remote attackers to cause a denial of service (program termination) via crafted ASN.1 BER datagrams th… Patch early 5.0 medium 13.2% 2008-07-01
CVE-2016-8527 EXP Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). The vulnerability is present in… Patch early 6.1 medium 13.2% 2018-08-06
CVE-2006-4965 EXP Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTi… Patch early 5.0 medium 13.1% 2006-09-25
CVE-2008-0153 EXP telnetd.exe in Pragma TelnetServer 7.0.4.589 allows remote attackers to cause a denial of service (process crash and resource exhaustion) via a crafte… Patch early 5.0 medium 13.1% 2008-01-09
CVE-1999-0981 EXP Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local fi… Patch early 5.1 medium 13.1% 1999-12-08
CVE-2007-2926 EXP ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY… Patch early 4.3 medium 13.1% 2007-07-24
CVE-2016-0049 EXP Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows… Patch early 6.2 medium 13.1% 2016-02-10
CVE-2021-20031 EXP A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains… Patch early 6.1 medium 13% 2021-10-12
CVE-2006-2860 EXP PHP remote file inclusion vulnerability in Webspotblogging 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter… Patch early 6.4 medium 13% 2006-06-06
CVE-2015-1365 EXP Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to write to arbi… Patch early 5.0 medium 13% 2015-01-27
CVE-2006-3581 EXP Multiple stack-based buffer overflows in Audacious AdPlug 2.0 and earlier allow remote user-assisted attackers to execute arbitrary code via large (1)… Patch early 5.1 medium 13% 2006-07-13
CVE-2017-8871 EXP The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and C… Patch early 6.5 medium 13% 2017-06-12
CVE-2002-0289 EXP Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP request. Patch early 5.0 medium 13% 2002-05-31
CVE-2011-2780 EXP Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) i… Patch early 5.0 medium 13% 2011-07-19
CVE-2012-3571 EXP ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) vi… Patch early 6.1 medium 13% 2012-07-25
CVE-2013-4117 EXP Cross-site scripting (XSS) vulnerability in includes/CatGridPost.php in the Category Grid View Gallery plugin 2.3.1 for WordPress allows remote attack… Patch early 4.3 medium 13% 2013-07-16
CVE-2002-1209 EXP Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (d… Patch early 5.0 medium 12.9% 2002-11-04
CVE-2021-43062 EXP A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 an… Patch early 6.1 medium 12.9% 2022-02-02
CVE-2007-6244 EXP Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote attackers to inject a… Patch early 4.3 medium 12.9% 2007-12-20
CVE-2019-1245 EXP An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosu… Patch early 6.5 medium 12.9% 2019-09-11
CVE-2020-29395 EXP The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field. Patch early 6.1 medium 12.9% 2020-11-30
CVE-2011-2505 EXP libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns valu… Patch early 6.4 medium 12.9% 2011-07-14
CVE-2008-5587 EXP Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers… Patch early 4.3 medium 12.9% 2008-12-16
CVE-2003-1505 EXP Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a textarea in… Patch early 4.3 medium 12.9% 2003-12-31
CVE-2002-2073 EXP Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arb… Patch early 4.3 medium 12.9% 2002-12-31
CVE-2021-24926 EXP The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a… Patch early 6.1 medium 12.9% 2022-02-01
CVE-2012-2371 EXP Cross-site scripting (XSS) vulnerability in index.php in the WP-FaceThumb plugin 0.1 for WordPress allows remote attackers to inject arbitrary web scr… Patch early 4.3 medium 12.8% 2012-08-13
← previous page 48 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt