peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,608 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

205,927 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-11151 EXP A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files wit… Patch early 9.8 critical 16.3% 2017-08-08
CVE-2018-14485 EXP BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd. Patch early 9.8 critical 16.3% 2019-05-07
CVE-2006-0911 EXP NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumption) via crafted requests to Log… Patch early 5.0 medium 16.3% 2006-02-28
CVE-2009-4019 EXP mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with sub… Patch early 4.0 medium 16.3% 2009-11-30
CVE-2012-6649 EXP WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload. Patch early 9.8 critical 16.3% 2020-01-23
CVE-2015-4666 EXP Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files vi… Patch early 5.0 medium 16.2% 2015-08-13
CVE-2020-11749 EXP Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can tri… Patch early 9.0 critical 16.2% 2020-07-13
CVE-2004-0474 EXP Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an "http://" or "file://" argument to the topic parameter… Patch early 5.1 medium 16.2% 2004-07-07
CVE-2013-2571 EXP Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request… Patch early 9.8 critical 16.2% 2020-01-28
CVE-2000-1058 EXP Buffer overflow in OverView5 CGI program in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows remote attackers to cause a denial of servic… Patch early 5.0 medium 16.2% 2000-12-11
CVE-2017-10355 EXP Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected a… Patch early 5.3 medium 16.2% 2017-10-19
CVE-2006-4384 EXP Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via the COLOR_64 chunk in a… Patch early 5.1 medium 16.2% 2006-09-12
CVE-2018-11412 EXP In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circ… Patch early 5.9 medium 16.2% 2018-05-24
CVE-2021-36711 EXP WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled. Patch early 9.8 critical 16.1% 2022-07-16
CVE-2013-1603 EXP An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DC… Patch early 5.3 medium 16.1% 2020-01-28
CVE-2019-8375 EXP The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script… Patch early 9.8 critical 16.1% 2019-02-24
CVE-2009-1872 EXP Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web sc… Patch early 4.3 medium 16.1% 2009-08-18
CVE-2013-7137 EXP The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting th… Patch early 9.8 critical 16.1% 2014-01-26
CVE-2005-2103 EXP Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly e… Patch early 9.8 critical 16.1% 2005-08-16
CVE-2021-24276 EXP The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribu… Patch early 6.1 medium 16% 2021-05-05
CVE-2017-14016 EXP A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of… Patch early 6.3 medium 16% 2017-11-06
CVE-2015-8396 EXP Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GDC… Patch early 10.0 critical 16% 2016-01-12
CVE-2019-8045 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 9.8 critical 16% 2019-08-20
CVE-2004-2090 EXP Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture metho… Patch early 5.0 medium 16% 2004-02-07
CVE-2010-1658 EXP Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remote attackers to read arbitrary… Patch early 5.0 medium 16% 2010-05-03
CVE-2017-12785 EXP The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, is prone to a… Patch early 9.8 critical 16% 2017-08-22
CVE-2020-28351 EXP The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting… Patch early 6.1 medium 16% 2020-11-09
CVE-2024-8945 EXP A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulnerability affects unknown code o… Patch early 5.5 medium 16% 2024-09-17
CVE-2017-0060 EXP The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 201… Patch early 5.5 medium 15.9% 2017-03-17
CVE-2001-0336 EXP The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request. Patch early 5.0 medium 15.9% 2001-06-27
← previous page 83 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt