peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,208 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

169,612 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-4535 EXP Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending a / (slash) character to the URI. Patch early 5.0 medium 6.7% 2009-12-31
CVE-2016-9951 EXP An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `RespawnCommand` or `ProcCmdline` fiel… Patch early 6.5 medium 6.7% 2016-12-17
CVE-2007-6561 EXP Multiple stack-based buffer overflows in PDFLib allow user-assisted remote attackers to execute arbitrary code via a long filename argument to the PDF… Patch early 5.7 medium 6.7% 2007-12-28
CVE-2011-3187 EXP The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in reque… Patch early 4.3 medium 6.7% 2011-08-29
CVE-2004-0164 EXP KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message t… Patch early 5.0 medium 6.7% 2004-03-03
CVE-2009-4665 EXP Directory traversal vulnerability in CuteSoft_Client/CuteEditor/Load.ashx in CuteSoft Components Cute Editor for ASP.NET allows remote attackers to re… Patch early 5.0 medium 6.7% 2010-03-05
CVE-2017-2364 EXP An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. The issue involves the "WebKit" co… Patch early 6.5 medium 6.7% 2017-02-20
CVE-2009-0744 EXP Apple Safari 4 Beta build 528.16 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a feeds: UR… Patch early 5.0 medium 6.7% 2009-02-27
CVE-2006-2284 EXP Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarol… Patch early 6.8 medium 6.7% 2006-05-10
CVE-2007-2486 EXP Directory traversal vulnerability in download.asp in Motobit 1.3 and 1.5 (aka PStruh-CZ) allows remote attackers to read arbitrary files via a .. (dot… Patch early 5.0 medium 6.6% 2007-05-03
CVE-2003-0802 EXP Nokia Electronic Documentation (NED) 5.0 allows remote attackers to obtain a directory listing of the WebLogic web root, and the physical path of the… Patch early 5.0 medium 6.6% 2003-10-06
CVE-1999-0431 EXP Linux 2.2.3 and earlier allow a remote attacker to perform an IP fragmentation attack, causing a denial of service. Patch early 5.0 medium 6.6% 1999-03-01
CVE-2008-7006 EXP Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backup… Patch early 5.0 medium 6.6% 2009-08-19
CVE-2008-2419 EXP Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary co… Patch early 4.3 medium 6.6% 2008-05-23
CVE-2013-4861 EXP Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated users to read a… Patch early 6.5 medium 6.6% 2020-01-28
CVE-2009-0659 EXP Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 allows remote attackers to have an unknown impact via a STATS line with a… Patch early 5.0 medium 6.6% 2009-02-20
CVE-2014-9597 EXP The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause… Patch early 6.8 medium 6.6% 2015-01-21
CVE-1999-1082 EXP Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "......" (modified dot dot) att… Patch early 5.0 medium 6.6% 1999-10-08
CVE-2018-19136 EXP DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter. Patch early 6.1 medium 6.6% 2018-11-09
CVE-2010-2246 EXP feh before 1.8, when the --wget-timestamp option is enabled, might allow remote attackers to execute arbitrary commands via shell metacharacters in a… Patch early 5.1 medium 6.6% 2011-05-26
CVE-2006-4827 EXP Multiple PHP remote file inclusion vulnerabilities in Vmist Downstat 1.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 5.1 medium 6.6% 2006-09-15
CVE-2008-2382 EXP The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to ca… Patch early 5.0 medium 6.6% 2008-12-24
CVE-2017-16787 EXP The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read arbitrary files by leveraging… Patch early 6.5 medium 6.6% 2017-12-15
CVE-2007-1359 EXP Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-url… Patch early 6.8 medium 6.6% 2007-03-08
CVE-2007-1522 EXP Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal cha… Patch early 6.8 medium 6.6% 2007-03-20
CVE-2015-2071 EXP Directory traversal vulnerability in cm/newui/blog/export.jsp in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote authenticated users to r… Patch early 4.0 medium 6.6% 2015-02-24
CVE-2002-0588 EXP PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters t… Patch early 5.0 medium 6.6% 2002-06-18
CVE-2002-1422 EXP admbrowse.php in FUDforum before 2.2.0 allows remote attackers to create or delete files via URL-encoded pathnames in the cur and dest parameters. Patch early 5.0 medium 6.6% 2003-04-11
CVE-2002-1429 EXP Cross-site scripting vulnerability in board.php of endity.com ShoutBOX allows remote attackers to inject arbitrary HTML into the shoutbox page via the… Patch early 5.0 medium 6.6% 2003-04-11
CVE-2022-48197 EXP Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, TreeView component and the YUI Jav… Patch early 6.1 medium 6.6% 2023-01-02
← previous page 95 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt