peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,143 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

206,198 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-11153 EXP Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain ad… Patch early 9.8 critical 12.2% 2017-08-08
CVE-2007-0908 EXP The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a nu… Patch early 5.0 medium 12.2% 2007-02-13
CVE-2016-1741 EXP The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or… Patch early 9.8 critical 12.2% 2016-03-24
CVE-2017-5358 EXP Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbitrary code via the server argu… Patch early 9.8 critical 12.1% 2017-03-15
CVE-2017-14955 EXP Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to… Patch early 5.9 medium 12.1% 2017-10-02
CVE-2018-19040 EXP The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir parameter of an mrelocator_getdir… Patch early 5.3 medium 12.1% 2019-01-31
CVE-1999-0006 EXP Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command. Patch early 9.8 critical 12.1% 1998-07-14
CVE-2010-0295 EXP lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a deni… Patch early 5.0 medium 12.1% 2010-02-03
CVE-2019-1244 EXP An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosu… Patch early 6.5 medium 12.1% 2019-09-11
CVE-2006-1834 EXP Integer signedness error in Opera before 8.54 allows remote attackers to execute arbitrary code via long values in a stylesheet attribute, which pass… Patch early 5.1 medium 12.1% 2006-04-19
CVE-2007-0017 EXP Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and t… Patch early 6.8 medium 12.1% 2007-01-03
CVE-2006-4208 EXP Directory traversal vulnerability in wp-db-backup.php in Skippy WP-DB-Backup plugin for WordPress 1.7 and earlier allows remote authenticated users wi… Patch early 5.0 medium 12.1% 2006-08-17
CVE-2001-0054 EXP Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a str… Patch early 5.0 medium 12% 2001-02-16
CVE-2009-4017 EXP PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, whi… Patch early 5.0 medium 12% 2009-11-24
CVE-2012-5533 EXP The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via… Patch early 5.0 medium 12% 2012-11-24
CVE-2016-9722 EXP IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended… Patch early 4.2 medium 12% 2018-01-10
CVE-2014-5289 EXP Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request. Patch early 9.8 critical 12% 2019-12-27
CVE-2022-38580 EXP Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF). Patch early 9.8 critical 12% 2022-10-25
CVE-2004-2104 EXP Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, vi… Patch early 5.0 medium 11.9% 2004-12-31
CVE-2014-8673 EXP Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPl… Patch early 9.8 critical 11.9% 2020-01-07
CVE-2011-5252 EXP Open redirect vulnerability in Users/Account/LogOff in Orchard 1.0.x before 1.0.21, 1.1.x before 1.1.31, 1.2.x before 1.2.42, and 1.3.x before 1.3.10… Patch early 5.8 medium 11.9% 2013-01-12
CVE-2009-1284 EXP Buffer overflow in BibTeX 0.99 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a long .bib bibliogra… Patch early 5.0 medium 11.9% 2009-04-09
CVE-2004-1488 EXP wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web… Patch early 5.0 medium 11.9% 2005-04-27
CVE-2012-3793 EXP Integer overflow in Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attac… Patch early 5.0 medium 11.9% 2012-06-25
CVE-2021-33990 EXP Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue be… Patch early 9.8 critical 11.9% 2023-04-16
CVE-2008-1270 EXP mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrar… Patch early 5.0 medium 11.9% 2008-03-10
CVE-2017-17739 EXP The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an atta… Patch early 9.8 critical 11.9% 2017-12-18
CVE-2004-2043 EXP Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allo… Patch early 5.0 medium 11.9% 2004-05-01
CVE-2010-1981 EXP Directory traversal vulnerability in the Fabrik (com_fabrik) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot d… Patch early 6.8 medium 11.9% 2010-05-19
CVE-2006-5846 EXP Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a .. (… Patch early 6.4 medium 11.9% 2006-11-10
← previous page 96 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt