peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,157 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

399,157 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-10974 EXP Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an… Patch early 7.5 high 81.2% 2017-07-07
CVE-2016-8870 EXP The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has… Patch early 8.1 high 81.1% 2016-11-04
CVE-2011-0923 EXP The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code via a craf… Patch early 10.0 high 81.1% 2011-02-09
CVE-2013-4212 EXP Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via… Patch early 6.8 medium 81.1% 2013-12-07
CVE-2014-7862 EXP The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrato… Patch early 9.8 critical 81% 2018-01-04
CVE-2021-20034 EXP An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrar… Patch early 9.1 critical 81% 2021-09-27
CVE-2022-25148 EXP The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter f… Patch early 9.8 critical 80.9% 2022-02-24
CVE-2005-2535 EXP Buffer overflow in the Discovery Service in BrightStor ARCserve Backup 9.0 through 11.1 allows remote attackers to execute arbitrary commands via a la… Patch early 7.5 high 80.9% 2005-08-10
CVE-2010-0094 EXP Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remot… Patch early 7.5 high 80.8% 2010-04-01
CVE-2018-0758 EXP Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the… Patch early 7.5 high 80.8% 2018-01-04
CVE-2017-16666 EXP Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name of an uploaded PCAP file. NO… Patch early 8.8 high 80.8% 2018-01-05
CVE-2007-6203 EXP Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request… Patch early 4.3 medium 80.7% 2007-12-03
CVE-2010-3552 EXP Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect conf… Patch early 10.0 high 80.7% 2010-10-19
CVE-2016-6433 EXP The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands… Patch early 8.8 high 80.7% 2016-10-06
CVE-2019-10669 EXP An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/device/collectd.inc.php where use… Patch early 7.2 high 80.7% 2019-09-09
CVE-2014-9195 EXP Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-complia… Patch early 10.0 high 80.7% 2015-01-17
CVE-2018-12464 EXP A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated re… Patch early 10.0 critical 80.7% 2018-06-29
CVE-2015-7766 EXP PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a commen… Patch early 9.0 high 80.6% 2015-10-09
CVE-2024-20419 EXP A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to… Patch early 10.0 critical 80.6% 2024-07-17
CVE-2015-7808 EXP The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and… Patch early 7.5 high 80.6% 2015-11-24
CVE-2021-21425 EXP Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an unau… Patch early 9.3 critical 80.6% 2021-04-07
CVE-2011-5034 EXP Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, whi… Patch early 7.8 high 80.6% 2011-12-30
CVE-2020-13160 EXP AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution. Patch early 9.8 critical 80.6% 2020-06-09
CVE-2010-0805 EXP The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers… Patch early 9.3 high 80.5% 2010-03-31
CVE-2008-4397 EXP Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 a… Patch early 10.0 high 80.5% 2008-10-14
CVE-2013-4123 EXP client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port num… Patch early 5.0 medium 80.5% 2013-09-16
CVE-2009-1185 EXP udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NET… Patch early 7.2 high 80.4% 2009-04-17
CVE-2010-0361 EXP Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to… Patch early 10.0 high 80.4% 2010-01-20
CVE-2008-0244 EXP SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo a… Patch early 10.0 high 80.3% 2008-01-12
CVE-2004-0230 EXP TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to… Patch early 5.0 medium 80.3% 2004-08-18
← previous page 72 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt