peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,661 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

205,953 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-4288 EXP Microsoft Windows Media Player 11 (wmplayer.exe) allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted… Patch early 4.3 medium 14.8% 2007-08-09
CVE-2017-14243 EXP An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers to directly access administra… Patch early 9.8 critical 14.8% 2017-09-17
CVE-2012-5615 EXP Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different err… Patch early 5.0 medium 14.8% 2012-12-03
CVE-2013-5962 EXP Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows r… Patch early 5.1 medium 14.8% 2013-09-30
CVE-2014-8791 EXP project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object in… Patch early 6.0 medium 14.8% 2014-12-02
CVE-2008-1160 EXP ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attac… Patch early 9.8 critical 14.8% 2008-03-25
CVE-1999-0294 EXP All records in a WINS database can be deleted through SNMP for a denial of service. Patch early 5.0 medium 14.7% 1997-10-01
CVE-2002-0083 EXP Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. Patch early 9.8 critical 14.7% 2002-03-15
CVE-2026-58138 EXP Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrar… Patch early 9.8 critical 14.7% 2026-06-30
CVE-2011-1511 EXP Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Products Suite 2.1.1 and 3.0.1 allows remote attackers to execute arb… Patch early 6.4 medium 14.6% 2011-07-20
CVE-2010-2089 EXP The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-depend… Patch early 5.0 medium 14.6% 2010-05-27
CVE-2007-5728 EXP Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 14.6% 2007-10-30
CVE-2017-3528 EXP Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (lists of values, datepicker, etc… Patch early 5.4 medium 14.6% 2017-04-24
CVE-2010-5300 EXP Stack-based buffer overflow in Jzip 1.3 through 2.0.0.132900 allows remote attackers to cause a denial of service (crash) and possibly execute arbitra… Patch early 6.8 medium 14.6% 2014-06-11
CVE-2017-6972 EXP AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root… Patch early 9.8 critical 14.6% 2017-03-22
CVE-2006-3199 EXP Opera 9 allows remote attackers to cause a denial of service (crash) via an A tag with an href attribute with a URL containing a long hostname, which… Patch early 5.0 medium 14.6% 2006-06-23
CVE-2010-1081 EXP Directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for Core Joomla! allows remote at… Patch early 5.0 medium 14.6% 2010-03-23
CVE-2018-6409 EXP An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the… Patch early 5.3 medium 14.6% 2018-05-26
CVE-2006-5220 EXP Multiple PHP remote file inclusion vulnerabilities in WebYep 1.1.9, when register_globals is enabled, allow remote attackers to execute arbitrary PHP… Patch early 5.1 medium 14.6% 2006-10-10
CVE-2020-24223 EXP Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters. Patch early 6.1 medium 14.6% 2020-08-30
CVE-2023-5702 EXP A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic. Affected by this issue is some unknown functionality… Patch early 4.3 medium 14.5% 2023-10-23
CVE-2019-9649 EXP An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory trav… Patch early 5.3 medium 14.5% 2019-03-22
CVE-2017-2641 EXP In Moodle 2.x and 3.x, SQL injection can occur via user preferences. Patch early 9.8 critical 14.5% 2017-03-26
CVE-2016-0772 EXP The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, whic… Patch early 6.5 medium 14.5% 2016-09-02
CVE-2008-0411 EXP Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code v… Patch early 6.8 medium 14.5% 2008-02-28
CVE-2014-4170 EXP A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script,… Patch early 9.8 critical 14.5% 2020-02-13
CVE-2011-1081 EXP modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Nam… Patch early 5.0 medium 14.5% 2011-03-20
CVE-2018-9248 EXP FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header. Patch early 9.8 critical 14.5% 2018-04-04
CVE-2018-15141 EXP Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal t… Patch early 6.5 medium 14.5% 2018-08-13
CVE-2019-8044 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 9.8 critical 14.5% 2019-08-20
← previous page 87 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt