peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,157 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

205,748 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-3605 EXP Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Transition property on an uninitialized DXIm… Patch early 5.0 medium 24.3% 2006-07-18
CVE-2006-3898 EXP Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the Click method… Patch early 5.0 medium 24.3% 2006-07-27
CVE-2006-3899 EXP Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the stringToBina… Patch early 5.0 medium 24.3% 2006-07-27
CVE-2002-1700 EXP Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary scri… Patch early 4.3 medium 24.3% 2002-12-31
CVE-2016-5725 EXP Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write… Patch early 5.9 medium 24.1% 2017-01-19
CVE-2024-25830 EXP F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker… Patch early 9.8 critical 24% 2024-02-29
CVE-2017-8798 EXP Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspec… Patch early 9.8 critical 24% 2017-05-11
CVE-2006-3101 EXP Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 24% 2006-06-21
CVE-2012-5611 EXP Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.… Patch early 6.5 medium 24% 2012-12-03
CVE-2014-8322 EXP Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code… Patch early 9.8 critical 23.9% 2020-01-31
CVE-2020-9467 EXP Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function. Patch early 5.4 medium 23.8% 2020-03-26
CVE-2001-0205 EXP Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by inserting "..." into the requested p… Patch early 5.0 medium 23.6% 2001-05-03
CVE-2008-1126 EXP PHP remote file inclusion vulnerability in main.php in Barryvan Compo Manager 0.3 allows remote attackers to execute arbitrary PHP code via a URL in t… Patch early 6.8 medium 23.6% 2008-03-03
CVE-2024-27747 EXP File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Imag… Patch early 9.8 critical 23.6% 2024-03-01
CVE-2018-6396 EXP SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers action, or… Patch early 9.8 critical 23.6% 2018-02-17
CVE-2013-3585 EXP Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information v… Patch early 5.0 medium 23.5% 2013-08-28
CVE-2018-5997 EXP An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a path traversal vulnerability, it… Patch early 9.8 critical 23.5% 2018-01-25
CVE-2010-4476 EXP The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and ear… Patch early 5.0 medium 23.5% 2011-02-17
CVE-2008-0566 EXP PHP remote file inclusion vulnerability in includes/smarty.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary… Patch early 6.8 medium 23.5% 2008-02-05
CVE-2018-8527 EXP An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a referen… Patch early 5.5 medium 23.4% 2018-10-10
CVE-2018-8532 EXP An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a refere… Patch early 5.5 medium 23.4% 2018-10-10
CVE-2018-8533 EXP An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a refere… Patch early 5.5 medium 23.4% 2018-10-10
CVE-2005-0452 EXP Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or… Patch early 4.3 medium 23.4% 2005-02-16
CVE-2011-4106 EXP TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute… Patch early 6.8 medium 23.3% 2013-10-26
CVE-2006-3897 EXP Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating a… Patch early 5.0 medium 23.3% 2006-07-27
CVE-2003-0002 EXP Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to exec… Patch early 6.8 medium 23.3% 2003-02-07
CVE-2023-37629 EXP Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig… Patch early 9.8 critical 23.3% 2023-07-12
CVE-2013-5528 EXP Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users… Patch early 4.0 medium 23.3% 2013-10-11
CVE-2016-9682 EXP The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrati… Patch early 9.8 critical 23.3% 2017-02-22
CVE-2005-3120 EXP Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article… Patch early 9.8 critical 23.3% 2005-10-17
← previous page 68 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt