peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,646 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

399,646 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2013-3215 EXP vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function. Patch early 9.8 critical 68.8% 2020-01-29
CVE-2007-0785 EXP PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote attackers to execute arbitrary… Patch early 7.5 high 68.8% 2007-02-06
CVE-2008-0960 EXP SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Ses… Patch early 10.0 high 68.8% 2008-06-10
CVE-2014-6039 EXP ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000. Patch early 7.5 high 68.8% 2020-01-13
CVE-2006-1255 EXP Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause a denial of service (applicat… Patch early 10.0 high 68.8% 2006-03-19
CVE-2007-2545 EXP Multiple PHP remote file inclusion vulnerabilities in Persism CMS 0.9.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 68.8% 2007-05-09
CVE-2000-0886 EXP IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating sys… Patch early 7.5 high 68.7% 2000-12-19
CVE-2023-40028 EXP Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload… Patch early 4.9 medium 68.7% 2023-08-15
CVE-2017-8670 EXP Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current… Patch early 7.5 high 68.7% 2017-08-08
CVE-2012-5687 EXP Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and… Patch early 7.8 high 68.7% 2012-11-01
CVE-2007-4313 EXP PHP remote file inclusion vulnerability in public_includes/pub_blocks/activecontent.php in Php Blue Dragon CMS 3.0.0 allows remote attackers to execut… Patch early 6.8 medium 68.7% 2007-08-13
CVE-2004-0567 EXP The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows S… Patch early 7.5 high 68.7% 2004-12-31
CVE-2009-2990 EXP Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitr… Patch early 9.3 high 68.7% 2009-10-19
CVE-2007-3057 EXP PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attackers to exec… Patch early 6.8 medium 68.7% 2007-06-06
CVE-2018-10594 EXP Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS… Patch early 9.8 critical 68.6% 2018-06-26
CVE-2015-7611 EXP Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified ve… Patch early 8.1 high 68.6% 2016-06-07
CVE-2009-2227 EXP Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrary code via a crafted request t… Patch early 10.0 high 68.6% 2009-06-26
CVE-2019-9053 EXP An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-ba… Patch early 8.1 high 68.6% 2019-03-26
CVE-2020-13951 EXP Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack. Patch early 7.5 high 68.6% 2020-09-30
CVE-2018-11646 EXP webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKit, as use… Patch early 7.5 high 68.6% 2018-06-01
CVE-2005-0684 EXP Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET reque… Patch early 10.0 high 68.5% 2005-04-25
CVE-2016-6195 EXP SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remot… Patch early 9.8 critical 68.5% 2016-08-30
CVE-2018-8631 EXP A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vu… Patch early 7.5 high 68.5% 2018-12-12
CVE-2017-11893 EXP ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the contex… Patch early 7.5 high 68.5% 2017-12-12
CVE-2017-9833 EXP /cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NO… Patch early 7.5 high 68.5% 2017-06-24
CVE-2001-0537 EXP HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being use… Patch early 9.3 high 68.5% 2001-07-21
CVE-2012-1195 EXP Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkMa… Patch early 7.5 high 68.4% 2012-02-18
CVE-2003-0727 EXP Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or h… Patch early 2.1 low 68.4% 2003-10-20
CVE-2006-0460 EXP Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error messages. Patch early 7.5 high 68.4% 2006-02-17
CVE-2015-1486 EXP The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a… Patch early 7.5 high 68.3% 2015-08-01
← previous page 90 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt