peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,986 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

206,106 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-3109 EXP Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), al… Patch early 4.3 medium 13.7% 2006-06-21
CVE-2013-3631 EXP NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.php, aka the "Advanced | Execut… Patch early 6.0 medium 13.7% 2013-11-02
CVE-2013-3724 EXP The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash and service… Patch early 5.0 medium 13.7% 2013-08-01
CVE-2013-2765 EXP The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process… Patch early 5.0 medium 13.7% 2013-07-15
CVE-2009-4491 EXP thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or… Patch early 9.8 critical 13.7% 2010-01-13
CVE-2003-0078 EXP ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding… Patch early 5.0 medium 13.7% 2003-03-03
CVE-2019-6971 EXP An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packet to the router management web… Patch early 9.8 critical 13.7% 2019-06-19
CVE-2019-6442 EXP An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, rel… Patch early 6.5 medium 13.7% 2019-01-16
CVE-2003-0447 EXP The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via an argument t… Patch early 5.1 medium 13.7% 2003-07-24
CVE-2017-16353 EXP GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file… Patch early 6.5 medium 13.7% 2017-11-01
CVE-2002-1603 EXP GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /),… Patch early 5.0 medium 13.7% 2002-02-13
CVE-2007-0562 EXP Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (applicat… Patch early 4.3 medium 13.7% 2007-01-30
CVE-2002-1484 EXP DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other sy… Patch early 9.8 critical 13.7% 2003-04-22
CVE-2002-1487 EXP The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by sending the raw messages (1) 2… Patch early 5.0 medium 13.6% 2003-04-02
CVE-2007-2052 EXP Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the… Patch early 5.0 medium 13.6% 2007-04-16
CVE-2002-1522 EXP Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute ar… Patch early 5.0 medium 13.6% 2003-04-02
CVE-2006-2686 EXP PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[AA_INC_PAT… Patch early 6.4 medium 13.6% 2006-05-31
CVE-2020-11027 EXP In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to… Patch early 6.1 medium 13.6% 2020-04-30
CVE-2010-1312 EXP Directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote attackers to read arbitrary f… Patch early 5.0 medium 13.6% 2010-04-08
CVE-2010-1340 EXP Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote attackers to read arbitrary f… Patch early 5.0 medium 13.6% 2010-04-09
CVE-2010-1534 EXP Directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (d… Patch early 5.0 medium 13.6% 2010-04-26
CVE-2010-1858 EXP Directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote attackers to read arbitrary files… Patch early 5.0 medium 13.6% 2010-05-07
CVE-2008-4787 EXP Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a URL with a hostname containing… Patch early 5.8 medium 13.6% 2008-10-29
CVE-2010-1352 EXP Directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote attackers to read arbitrary fi… Patch early 5.0 medium 13.6% 2010-04-12
CVE-2010-1491 EXP Directory traversal vulnerability in the MMS Blog (com_mmsblog) component 2.3.0 for Joomla! allows remote attackers to read arbitrary files and possib… Patch early 5.0 medium 13.6% 2010-04-23
CVE-2006-3121 EXP The peel_netstring function in cl_netstring.c in the heartbeat subsystem in High-Availability Linux before 1.2.5, and 2.0 before 2.0.7, allows remote… Patch early 5.0 medium 13.6% 2006-08-17
CVE-2006-0179 EXP The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary p… Patch early 5.0 medium 13.6% 2006-01-11
CVE-2015-0565 EXP NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible. Patch early 10.0 critical 13.6% 2020-02-25
CVE-1999-0140 EXP Denial of service in RAS/PPTP on NT systems. Patch early 5.0 medium 13.6% 1999-06-30
CVE-2006-4227 EXP MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine… Patch early 6.5 medium 13.6% 2006-08-18
← previous page 90 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt