peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,265 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

169,629 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2001-1490 EXP Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images. Patch early 5.0 medium 6.4% 2001-12-31
CVE-2006-2516 EXP mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite variables such as $xoopsOption['noc… Patch early 5.1 medium 6.4% 2006-05-22
CVE-2009-3643 EXP Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote attackers to cause a denial of service via a long argument to the (1) LIST and (2) NLST comman… Patch early 5.0 medium 6.4% 2009-10-09
CVE-2013-1463 EXP Cross-site scripting (XSS) vulnerability in js/tabletools/zeroclipboard.swf in the WP-Table Reloaded module before 1.9.4 for Wordpress allows remote a… Patch early 4.3 medium 6.4% 2013-02-07
CVE-2019-8927 EXP An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfi… Patch early 6.1 medium 6.3% 2019-05-17
CVE-2013-2682 EXP Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information. Patch early 4.3 medium 6.3% 2020-02-05
CVE-2006-6847 EXP An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) b… Patch early 5.0 medium 6.3% 2006-12-31
CVE-2007-6537 EXP Stack-based buffer overflow in the zfile_gunzip function in zfile.c in WinUAE 1.4.4 and earlier allows user-assisted remote attackers to execute arbit… Patch early 6.8 medium 6.3% 2007-12-27
CVE-2009-0572 EXP PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enab… Patch early 5.1 medium 6.3% 2009-02-13
CVE-2000-0146 EXP The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service via a long URL to the servlet… Patch early 5.0 medium 6.3% 2000-02-07
CVE-2017-2479 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affect… Patch early 6.5 medium 6.3% 2017-04-02
CVE-2014-3146 EXP Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) at… Patch early 6.1 medium 6.3% 2014-05-14
CVE-2013-1402 EXP DigiLIBE 3.4 and possibly other versions sends a redirect but does not exit, which allows remote attackers to obtain sensitive configuration informati… Patch early 5.0 medium 6.3% 2013-02-14
CVE-2011-4810 EXP Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read arbitrary files via the templat… Patch early 5.0 medium 6.3% 2011-12-14
CVE-2013-1937 EXP Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inje… Patch early 6.1 medium 6.3% 2013-04-16
CVE-2008-5919 EXP Directory traversal vulnerability in rss.php in WebSVN 2.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to overwrite arbitr… Patch early 6.8 medium 6.3% 2009-01-21
CVE-2022-39195 EXP A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c p… Patch early 6.1 medium 6.3% 2023-01-17
CVE-2013-1636 EXP Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin be… Patch early 4.3 medium 6.3% 2014-03-12
CVE-2019-8926 EXP An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp fi… Patch early 6.1 medium 6.3% 2019-05-17
CVE-2019-8928 EXP An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp via these GET… Patch early 6.1 medium 6.3% 2019-05-17
CVE-2014-9598 EXP The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial… Patch early 6.8 medium 6.3% 2015-01-21
CVE-2018-1185 EXP An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint versi… Patch early 6.7 medium 6.3% 2018-02-03
CVE-2020-6862 EXP V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page i… Patch early 5.3 medium 6.3% 2020-01-17
CVE-2013-6796 EXP The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, which triggers an LDAP anonymous b… Patch early 5.0 medium 6.3% 2014-10-26
CVE-2001-0778 EXP OmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20). Patch early 5.0 medium 6.3% 2001-10-18
CVE-2019-15083 EXP Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Usi… Patch early 6.1 medium 6.3% 2020-05-14
CVE-2005-1006 EXP Multiple cross-site scripting (XSS) vulnerabilities in SonicWALL SOHO 5.1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) th… Patch early 4.3 medium 6.3% 2005-05-02
CVE-2007-0649 EXP Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variable… Patch early 4.3 medium 6.3% 2007-02-01
CVE-2009-0250 EXP Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… Patch early 5.0 medium 6.3% 2009-01-22
CVE-2008-5885 EXP The Net Guys ASPired2Quote stores sensitive information under the web root with insufficient access control, which allows remote attackers to download… Patch early 5.0 medium 6.3% 2009-01-12
← previous page 99 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt