peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,986 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

206,106 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-5465 EXP Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress allows remote attackers to re… Patch early 5.0 medium 13.5% 2014-09-03
CVE-2006-3210 EXP Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers to conduct PHP remote file inc… Patch early 5.1 medium 13.5% 2006-06-24
CVE-2011-0421 EXP The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argume… Patch early 4.3 medium 13.5% 2011-03-20
CVE-2005-1267 EXP The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attacker… Patch early 5.0 medium 13.5% 2005-06-10
CVE-2015-7241 EXP XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01. Patch early 9.8 critical 13.5% 2017-09-06
CVE-2017-16934 EXP The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content… Patch early 9.8 critical 13.5% 2017-11-24
CVE-2019-8647 EXP A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.4, tvOS 12.4, watchOS 5.3. A remote attacker may b… Patch early 9.8 critical 13.5% 2019-12-18
CVE-2005-0815 EXP Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corr… Patch early 6.4 medium 13.4% 2005-05-02
CVE-2016-9269 EXP Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_B… Patch early 9.9 critical 13.4% 2017-02-21
CVE-2005-3737 EXP Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute arbitrary code via a SVG file… Patch early 5.1 medium 13.4% 2005-11-22
CVE-1999-0196 EXP websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variabl… Patch early 5.0 medium 13.4% 1997-07-08
CVE-2017-1000373 EXP The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort()… Patch early 6.5 medium 13.4% 2017-06-19
CVE-2013-2683 EXP Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresse… Patch early 5.3 medium 13.4% 2020-02-06
CVE-2015-8556 EXP Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1. Patch early 10.0 critical 13.4% 2017-03-24
CVE-2016-9796 EXP Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port 30024. An at… Patch early 9.8 critical 13.4% 2016-12-03
CVE-2002-2062 EXP Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP si… Patch early 4.3 medium 13.3% 2002-12-31
CVE-2010-3709 EXP The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of… Patch early 4.3 medium 13.3% 2010-11-09
CVE-2019-8017 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 9.8 critical 13.3% 2019-08-20
CVE-2019-12477 EXP Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authe… Patch early 5.5 medium 13.3% 2019-06-07
CVE-2015-4153 EXP Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to include and execute arb… Patch early 5.0 medium 13.3% 2015-06-10
CVE-2007-3473 EXP The gdImageCreateXbm function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (cra… Patch early 4.3 medium 13.3% 2007-06-28
CVE-2020-35775 EXP CITSmart before 9.1.2.23 allows LDAP Injection. Patch early 9.8 critical 13.3% 2021-02-15
CVE-2013-4858 EXP Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) via a crafted .wav… Patch early 4.3 medium 13.3% 2013-12-30
CVE-2009-5114 EXP Directory traversal vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 5.0 medium 13.3% 2012-03-19
CVE-2015-2791 EXP The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a craft… Patch early 6.4 medium 13.3% 2015-03-30
CVE-2019-8613 EXP A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote attacker may… Patch early 9.8 critical 13.3% 2019-12-18
CVE-2007-4430 EXP Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routi… Patch early 5.0 medium 13.3% 2007-08-20
CVE-2011-1468 EXP Multiple memory leaks in the OpenSSL extension in PHP before 5.3.6 might allow remote attackers to cause a denial of service (memory consumption) via… Patch early 4.3 medium 13.3% 2011-03-20
CVE-2010-0442 EXP The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of se… Patch early 6.5 medium 13.3% 2010-02-02
CVE-2018-14335 EXP An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of th… Patch early 6.5 medium 13.2% 2018-07-24
← previous page 91 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt