peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,482 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

169,001 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-3153 EXP Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attacke… Patch early 6.4 medium 98.2% 2012-10-16
CVE-2014-5445 EXP Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote attackers or remot… Patch early 5.0 medium 98% 2014-12-04
CVE-2018-11784 EXP When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. r… Patch early 4.3 medium 97.7% 2018-10-04
CVE-2013-5211 EXP The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via f… Patch early 5.0 medium 97.5% 2014-01-02
CVE-2012-0392 EXP The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute ar… Patch early 6.8 medium 97.5% 2012-01-08
CVE-2012-2122 EXP sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12,… Patch early 5.1 medium 96.5% 2012-06-26
CVE-1999-0016 EXP Land IP denial of service. Patch early 5.0 medium 95.7% 1997-12-01
CVE-2011-0049 EXP Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers to read ar… Patch early 5.0 medium 95.4% 2011-02-04
CVE-2008-1447 EXP The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, a… Patch early 6.8 medium 95.2% 2008-07-08
CVE-2006-3918 EXP http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, an… Patch early 4.3 medium 95.1% 2006-07-28
CVE-2002-0840 EXP Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off"… Patch early 6.8 medium 95.1% 2002-10-11
CVE-2015-5531 EXP Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to sna… Patch early 5.0 medium 94.8% 2015-08-17
CVE-2013-2248 EXP Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and condu… Patch early 5.8 medium 94.7% 2013-07-20
CVE-2009-0580 EXP Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enume… Patch early 4.3 medium 94.4% 2009-06-05
CVE-2017-5753 EXP Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wit… Patch early 5.6 medium 93.8% 2018-01-04
CVE-2020-2096 EXP Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability. Patch early 6.1 medium 92.8% 2020-01-15
CVE-2019-8943 EXP WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an a… Patch early 6.5 medium 92.6% 2019-02-20
CVE-2016-0492 EXP Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows rem… Patch early 6.4 medium 92.1% 2016-01-21
CVE-2010-1870 EXP The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly oth… Patch early 5.0 medium 92% 2010-08-17
CVE-2007-0450 EXP Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_prox… Patch early 5.0 medium 90.8% 2007-03-16
CVE-2011-3368 EXP The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with us… Patch early 5.0 medium 90.7% 2011-10-05
CVE-2022-44268 EXP ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded t… Patch early 6.5 medium 89.9% 2023-02-06
CVE-2018-7358 EXP ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerability, whi… Patch early 6.5 medium 89.6% 2018-11-14
CVE-2006-0026 EXP Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary cod… Patch early 6.5 medium 89.3% 2006-07-11
CVE-2016-2107 EXP The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which a… Patch early 5.9 medium 89.1% 2016-05-05
CVE-2016-6210 EXP sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username doe… Patch early 5.9 medium 88.9% 2017-02-13
CVE-2004-1520 EXP Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command. Patch early 4.6 medium 88.5% 2004-12-31
CVE-2003-0718 EXP The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and… Patch early 5.0 medium 87.9% 2004-11-03
CVE-2018-7357 EXP ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerability, whi… Patch early 6.5 medium 87.9% 2018-11-14
CVE-2017-5487 EXP wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restr… Patch early 5.3 medium 87.3% 2017-01-15
← previous page 8 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt