peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,208 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

169,612 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-25160 EXP A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x… Patch early 4.9 medium 6.6% 2021-03-30
CVE-2016-1595 EXP LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to con… Patch early 6.5 medium 6.6% 2016-04-22
CVE-2014-0999 EXP Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and hijack sessio… Patch early 5.0 medium 6.6% 2015-06-02
CVE-2022-34048 EXP Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter. Patch early 6.1 medium 6.6% 2022-07-20
CVE-2017-11332 EXP The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and applicat… Patch early 5.5 medium 6.6% 2017-07-31
CVE-2017-11359 EXP The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and applic… Patch early 5.5 medium 6.6% 2017-07-31
CVE-2016-6504 EXP epan/dissectors/packet-ncp2222.inc in the NDS dissector in Wireshark 1.12.x before 1.12.13 does not properly maintain a ptvc data structure, which all… Patch early 5.9 medium 6.6% 2016-08-06
CVE-2009-4089 EXP telepark.wiki 2.4.23 and earlier allows remote attackers to bypass authorization and (1) delete arbitrary pages via a modified pageID parameter to aja… Patch early 5.0 medium 6.6% 2009-11-29
CVE-2009-1517 EXP Multiple insecure method vulnerabilities in the Symantec.EasySetup.1 ActiveX control in EasySetupInt.dll 14.0.4.30167 in the EasySetup wizard in Syman… Patch early 4.3 medium 6.6% 2009-05-04
CVE-2017-0045 EXP Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allo… Patch early 5.5 medium 6.6% 2017-03-17
CVE-2013-1891 EXP In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed. Patch early 6.5 medium 6.6% 2022-06-24
CVE-2009-0113 EXP Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allows remote attackers to list ar… Patch early 5.0 medium 6.6% 2009-01-09
CVE-2009-3787 EXP files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files via the file parameter with "lo… Patch early 5.0 medium 6.6% 2009-10-26
CVE-2006-1832 EXP sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action. Patch early 5.0 medium 6.6% 2006-04-19
CVE-2014-4154 EXP ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows… Patch early 5.0 medium 6.6% 2014-07-16
CVE-2004-1540 EXP ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to acce… Patch early 5.0 medium 6.6% 2004-12-31
CVE-2006-1504 EXP Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0 (aka Arab Dynamic Portal or ADP) stable allow remote attackers to inject arbitr… Patch early 5.1 medium 6.6% 2006-03-30
CVE-2017-11552 EXP mpg321.c in mpg321 0.3.2-1 does not properly manage memory for use with libmad 0.15.1b, which allows remote attackers to cause a denial of service (me… Patch early 6.5 medium 6.6% 2017-08-01
CVE-2012-4999 EXP Mercury MR804 Router 8.0 3.8.1 Build 101220 Rel.53006nB allows remote attackers to cause a denial of service (service hang) via a crafted string in HT… Patch early 6.1 medium 6.6% 2012-09-19
CVE-2016-8025 EXP SQL injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to obtain produc… Patch early 6.2 medium 6.5% 2017-03-14
CVE-2001-0210 EXP Directory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the page pa… Patch early 5.0 medium 6.5% 2001-06-02
CVE-2001-0211 EXP Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform paramet… Patch early 5.0 medium 6.5% 2001-06-02
CVE-2005-2262 EXP Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper"… Patch early 5.1 medium 6.5% 2005-07-13
CVE-2017-9122 EXP The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumpti… Patch early 6.5 medium 6.5% 2017-06-12
CVE-2007-6290 EXP Multiple directory traversal vulnerabilities in js/get_js.php in SERWeb 2.0.0 dev1 and earlier allow remote attackers to read arbitrary files via a ..… Patch early 5.0 medium 6.5% 2007-12-10
CVE-2009-0886 EXP Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via a .. (dot… Patch early 5.0 medium 6.5% 2009-03-12
CVE-2004-2130 EXP Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbitrary script or HTML via the (… Patch early 4.3 medium 6.5% 2004-12-23
CVE-2000-0484 EXP Small HTTP Server ver 3.06 contains a memory corruption bug causing a memory overflow. The overflowed buffer crashes into a Structured Exception Handl… Patch early 5.0 medium 6.5% 2000-06-15
CVE-2007-2940 EXP Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary PHP code via a URL in the pacht… Patch early 6.8 medium 6.5% 2007-05-31
CVE-2009-1234 EXP Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a long series of start-tags with no… Patch early 4.3 medium 6.5% 2009-04-02
← previous page 96 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt