peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,157 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

169,235 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2011-1143 EXP epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (NULL pointer… Patch early 4.3 medium 8.6% 2011-03-03
CVE-2000-0508 EXP rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request. Patch early 5.0 medium 8.6% 1994-12-19
CVE-2006-4877 EXP Variable overwrite vulnerability in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to overwrite arbitrary program variables via… Patch early 5.0 medium 8.6% 2006-09-19
CVE-2007-6584 EXP Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot)… Patch early 6.4 medium 8.6% 2007-12-28
CVE-2010-3306 EXP Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%… Patch early 5.0 medium 8.6% 2010-09-24
CVE-2000-0906 EXP Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to read arbitrary files via a .. (d… Patch early 5.0 medium 8.6% 2000-12-19
CVE-2015-1482 EXP Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connecti… Patch early 5.0 medium 8.5% 2015-02-04
CVE-2002-2314 EXP Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which cause… Patch early 5.0 medium 8.5% 2002-12-31
CVE-2005-2455 EXP Greasemonkey before 0.3.5 allows remote web servers to (1) read arbitrary files via a GET request to a file:// URL in the GM_xmlhttpRequest API functi… Patch early 5.0 medium 8.5% 2005-08-04
CVE-2012-5329 EXP Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application crash) via a long string in an A… Patch early 4.0 medium 8.5% 2012-10-08
CVE-2001-0495 EXP Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack. Patch early 5.0 medium 8.5% 2001-06-27
CVE-2008-4409 EXP libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a de… Patch early 5.0 medium 8.5% 2008-10-03
CVE-2010-4617 EXP Directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers to read arbitrary files via dir… Patch early 6.8 medium 8.5% 2010-12-29
CVE-2009-4501 EXP The zbx_get_next_field function in libs/zbxcommon/str.c in Zabbix Server before 1.6.8 allows remote attackers to cause a denial of service (crash) via… Patch early 5.0 medium 8.5% 2009-12-31
CVE-2007-4976 EXP Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to in… Patch early 6.5 medium 8.5% 2007-09-19
CVE-2010-3203 EXP Directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot… Patch early 5.0 medium 8.5% 2010-09-03
CVE-2008-5715 EXP Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long string… Patch early 5.0 medium 8.5% 2008-12-24
CVE-2008-4558 EXP Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary code via an XSPF playlist file… Patch early 6.8 medium 8.5% 2008-10-15
CVE-2006-0891 EXP Multiple directory traversal vulnerabilities in NOCC Webmail 1.0 allow remote attackers to include arbitrary files via .. (dot dot) sequences and a tr… Patch early 5.0 medium 8.5% 2006-02-25
CVE-2007-4533 EXP Format string vulnerability in the Say command in sv_main.cpp in Vavoom 1.24 and earlier allows remote attackers to execute arbitrary code via format… Patch early 6.8 medium 8.5% 2007-08-25
CVE-2014-2880 EXP Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows rem… Patch early 5.8 medium 8.5% 2014-04-17
CVE-2007-1521 EXP Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the… Patch early 6.8 medium 8.5% 2007-03-20
CVE-2019-10848 EXP Computrols CBAS 18.0.0 allows Username Enumeration. Patch early 5.3 medium 8.5% 2019-05-24
CVE-2009-1789 EXP mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted… Patch early 4.3 medium 8.5% 2009-05-26
CVE-2000-1025 EXP eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that contains the… Patch early 5.0 medium 8.5% 2000-12-11
CVE-2005-4558 EXP IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable valu… Patch early 6.5 medium 8.5% 2005-12-28
CVE-2018-7737 EXP In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.php. NOTE: the software maintain… Patch early 5.3 medium 8.5% 2018-03-06
CVE-2010-1302 EXP Directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! allows remote attackers to read… Patch early 5.0 medium 8.5% 2010-04-07
CVE-2013-3597 EXP servlet/CollectionListServlet in SearchBlox before 7.5 build 1 allows remote attackers to read usernames and passwords via a getList action. Patch early 5.0 medium 8.5% 2013-08-28
CVE-2005-4095 EXP Directory traversal vulnerability in connector.php in the fckeditor2rc2 addon in DoceboLMS 2.0.4 allows remote attackers to list arbitrary files and d… Patch early 5.0 medium 8.5% 2005-12-08
← previous page 69 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt