peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,661 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

169,379 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-1061 EXP Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allow remote attackers to inject arbitrary we… Patch early 4.3 medium 7.4% 2008-02-28
CVE-2002-0937 EXP The Java Server Pages (JSP) engine in JRun allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that ca… Patch early 5.0 medium 7.4% 2002-10-04
CVE-2000-0180 EXP Sojourn search engine allows remote attackers to read arbitrary files via a .. (dot dot) attack. Patch early 5.0 medium 7.4% 2000-03-14
CVE-2008-6712 EXP The HTTP/XML-RPC service in Crysis 1.21 (game version 1.1.1.6156) and earlier allows remote attackers to cause a denial of service (crash) via a long… Patch early 5.0 medium 7.4% 2009-04-10
CVE-2003-0312 EXP Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request. Patch early 6.4 medium 7.4% 2003-06-16
CVE-2006-2277 EXP Multiple Apple Mac OS X 10.4 applications might allow context-dependent attackers to cause a denial of service (application crash) via a crafted OpenE… Patch early 5.0 medium 7.4% 2006-05-10
CVE-2008-5572 EXP Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to… Patch early 5.0 medium 7.4% 2008-12-15
CVE-2014-8655 EXP The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to bypass auth… Patch early 5.0 medium 7.4% 2014-11-06
CVE-2000-0149 EXP Zeus web server allows remote attackers to view the source code for CGI programs via a null character (%00) at the end of a URL. Patch early 5.0 medium 7.4% 2000-02-08
CVE-2004-0255 EXP Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and… Patch early 5.0 medium 7.4% 2004-11-23
CVE-2012-5930 EXP The pa_modify_accounts function in auth.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 does not require authentication for… Patch early 6.4 medium 7.4% 2012-12-24
CVE-2003-1304 EXP EarlyImpact ProductCart 1.0 through 2.0 stores database/EIPC.mdb under the web root with insufficient access control, which allows remote attackers to… Patch early 5.0 medium 7.4% 2003-12-31
CVE-2020-5295 EXP In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to read local fi… Patch early 4.8 medium 7.4% 2020-06-03
CVE-2005-0435 EXP awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog. Patch early 5.0 medium 7.4% 2005-05-02
CVE-2002-0535 EXP Cross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other users via (1) an [IMG] tag when… Patch early 5.0 medium 7.4% 2002-07-03
CVE-2014-8802 EXP The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote at… Patch early 5.0 medium 7.4% 2015-01-23
CVE-2017-0258 EXP The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windo… Patch early 4.7 medium 7.4% 2017-05-12
CVE-2014-5300 EXP Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 allows remote attackers to bypass the signature check, impersonate arbitrary users, and execut… Patch early 5.0 medium 7.4% 2014-10-08
CVE-2008-1054 EXP Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlier, and b… Patch early 6.4 medium 7.4% 2008-02-27
CVE-2000-0204 EXP The Trend Micro OfficeScan client allows remote attackers to cause a denial of service by making 5 connections to port 12345, which raises CPU utiliza… Patch early 5.0 medium 7.4% 2000-02-28
CVE-2004-2124 EXP The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a… Patch early 5.0 medium 7.4% 2004-12-31
CVE-2007-0613 EXP The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does not check for duplicate entrie… Patch early 5.0 medium 7.4% 2007-01-31
CVE-2016-1839 EXP The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2… Patch early 5.5 medium 7.3% 2016-05-20
CVE-2019-13237 EXP In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resource… Patch early 4.3 medium 7.3% 2019-08-27
CVE-2010-2809 EXP The default configuration of the <Button2> binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assist… Patch early 6.8 medium 7.3% 2010-08-19
CVE-2008-1278 EXP The RemotelyAnywhere.exe service in the Remotely Anywhere Server and Workstation 8.0.668 and earlier allows remote attackers to cause a denial of serv… Patch early 5.0 medium 7.3% 2008-03-10
CVE-2008-5280 EXP The Local ZIM Server in Zilab Chat and Instant Messaging (ZIM) Server 2.0 and 2.1 allows remote attackers to cause a denial of service (NULL pointer d… Patch early 5.0 medium 7.3% 2008-11-29
CVE-2008-1218 EXP Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to byp… Patch early 6.8 medium 7.3% 2008-03-10
CVE-2007-3151 EXP rpttop.htm in the web management interface in Packeteer PacketShaper 7.3.0g2 and 7.5.0g1 allows remote attackers to cause a denial of service (device… Patch early 5.0 medium 7.3% 2007-06-11
CVE-2004-0605 EXP Non-registered IRC users using (1) ircd-hybrid 7.0.1 and earlier, (2) ircd-ratbox 1.5.1 and earlier, or (3) ircd-ratbox 2.0rc6 and earlier do not have… Patch early 5.0 medium 7.3% 2004-12-06
← previous page 84 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt