peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,486 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

399,486 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2013-5486 EXP Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows re… Patch early 10.0 high 76% 2013-09-23
CVE-2007-4880 EXP Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.… Patch early 10.0 high 75.9% 2007-09-28
CVE-2018-8065 EXP An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access violation on the syncbrs.exe me… Patch early 7.5 high 75.9% 2018-03-12
CVE-2008-1232 EXP Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers… Patch early 4.3 medium 75.9% 2008-08-04
CVE-2019-1937 EXP A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Di… Patch early 9.8 critical 75.9% 2019-08-21
CVE-2009-4140 EXP Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0.2.35 thro… Patch early 7.5 high 75.8% 2009-12-22
CVE-2006-2447 EXP SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafte… Patch early 5.1 medium 75.8% 2006-06-06
CVE-2012-5959 EXP Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… Patch early 10.0 high 75.8% 2013-01-31
CVE-2009-0837 EXP Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to execute arbitrary code via a lo… Patch early 10.0 high 75.8% 2009-03-10
CVE-2017-1092 EXP IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servers. IBM X… Patch early 9.8 critical 75.8% 2017-05-22
CVE-2010-2550 EXP The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Win… Patch early 10.0 high 75.7% 2010-08-11
CVE-2022-2884 EXP A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated… Patch early 9.9 critical 75.7% 2022-10-17
CVE-2004-0847 EXP The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted director… Patch early 9.8 critical 75.7% 2004-11-03
CVE-2014-9735 EXP The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not proper… Patch early 7.5 high 75.7% 2015-06-30
CVE-2011-2371 EXP Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey thro… Patch early 10.0 high 75.7% 2011-06-30
CVE-2022-1162 EXP A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7… Patch early 9.1 critical 75.6% 2022-04-04
CVE-2010-2729 EXP The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and… Patch early 9.3 high 75.6% 2010-09-15
CVE-2018-9160 EXP SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses. Patch early 9.8 critical 75.6% 2018-03-31
CVE-2022-32429 EXP An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 all… Patch early 9.8 critical 75.6% 2022-08-10
CVE-2010-3275 EXP libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an AMV file,… Patch early 9.3 high 75.5% 2011-03-28
CVE-2004-2086 EXP Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (c… Patch early 5.0 medium 75.5% 2004-02-06
CVE-2015-2080 EXP The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via il… Patch early 7.5 high 75.4% 2016-10-07
CVE-2015-1592 EXP Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw functi… Patch early 7.5 high 75.4% 2015-02-19
CVE-2023-3643 EXP A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/doc… Patch early 7.3 high 75.4% 2023-07-12
CVE-2020-25540 EXP ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on a remote server via GET reques… Patch early 7.5 high 75.3% 2020-09-14
CVE-2007-4279 EXP PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 75.3% 2007-08-09
CVE-2019-12255 EXP Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that lead… Patch early 9.8 critical 75.3% 2019-08-09
CVE-2004-0397 EXP Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attackers to execute arbitrary code vi… Patch early 7.5 high 75.3% 2004-07-07
CVE-2005-2668 EXP Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow r… Patch early 10.0 high 75.2% 2005-08-23
CVE-2001-0925 EXP The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP requ… Patch early 5.0 medium 75.2% 2001-03-12
← previous page 78 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt