Free · no signup · updated from NVD

Which CVEs are actually being exploited?

Search the catalog with CVSS, EPSS and CISA KEV context. Know what to patch first before the next scanner export lands in your inbox.

CVE ID or keyword

Exact CVE IDs open the detail page. Keywords search the catalog.

4k+CVEs indexedKEVCISA statusEPSSexploit probability
Severity

4,385 CVEs

CVETitleSeverityEPSSCVSSProduct
CVE-2005-0877DNS Cache Poisoning Flaw in dnsmasq Versions Prior to 2.21High7.5thekelleys · dnsmasq
CVE-2007-3205PHP parse_str Function Vulnerable to Variable Overwrite AttacksMedium5.0hardened-php_project · hardened-php
CVE-2007-4723Ragnarok Online Control Panel vulnerable to directory traversal attacksHigh7.5ragnarok_online_control_panel_project · ragnaro…
CVE-2009-0796Apache HTTP Server users vulnerable to cross-site scripting attacksLow2.6apache · mod_perl
CVE-2009-1390Mutt allows spoofing of trusted servers via man-in-the-middle attacksMedium6.8mutt · mutt
CVE-2009-2299Hyperguard Web Application Firewall vulnerable to denial of service attacksMedium5.0hyperguard_web_application_firewall_project · h…
CVE-2009-2957Heap Overflow in dnsmasq TFTP Lets Remote Attackers Run CodeMedium6.8thekelleys · dnsmasq
CVE-2009-2958dnsmasq TFTP NULL Pointer DoS: Patch 2.50 and Harden ExposureMedium4.3thekelleys · dnsmasq
CVE-2009-3765Mutt SSL vulnerability allows man-in-the-middle attacks on SSL serversMedium6.8mutt · mutt
CVE-2009-3766Mutt SSL vulnerability affects users of versions before 1.5.19Medium6.8mutt · mutt
CVE-2009-3767OpenLDAP vulnerable to SSL certificate spoofing attacksMedium4.3openldap · openldap
CVE-2011-1176Apache mpm-itk Module Vulnerable to Privilege EscalationMedium4.3mpm-itk_project · mpm-itk
CVE-2011-2523vsftpd backdoor affects Linux users on port 6200/tcpCritical9.8vsftpd_project · vsftpd
CVE-2011-2688Apache HTTP Server mod_authnz_external module vulnerable to SQL injection attacksHigh7.5mod_authnz_external_project · mod_authnz_extern…
CVE-2012-3411Dnsmasq Traffic Amplification via Prohibited Interface RepliesMedium5.0thekelleys · dnsmasq
CVE-2012-3526Apache HTTP Server mod_rpaf module vulnerable to denial of service attacksMedium5.0thomas_eibner · mod_rpaf
CVE-2012-4001Apache mod_pagespeed module vulnerable to unauthorized HTTP requestsMedium5.0google · mod_pagespeed
CVE-2012-4360Apache HTTP Server mod_pagespeed module vulnerable to cross-site scripting attacksMedium4.3google · mod_pagespeed
CVE-2012-4542Linux Kernel SG_IO ioctl Authorization Bypass via Overlapping SCSI OpcodesMedium4.6linux · linux_kernel
CVE-2013-0198Dnsmasq TCP DNS Query Amplification via Prohibited InterfacesMedium5.0thekelleys · dnsmasq

How it works

From CVE ID to prioritised fix

1

Search or filter

Look up a CVE ID directly, or filter by severity, KEV status and EPSS to narrow the list.

2

Read the context

Each entry includes CVSS, EPSS, CWE, affected products, exploit references and triage notes.

3

Prioritise fixes

Use KEV and EPSS together to decide what to patch first — then validate exposure in your stack.

Signals

More than a CVSS number

KEV + EPSS in one view

Theoretical severity and real-world exploit probability side by side — so you stop chasing CVSS alone.

Vendor context

CPE strings and product names are searchable, so you can find every issue affecting apache, fortinet or your stack.

Exploit intelligence

Exploit reference counts, emergent threat flags and why-exploitable summaries from Trusteed triage.

Questions

How to read CVE intelligence

Need to see what is actually exposed on your perimeter? Start with a free scan.

Scan my attack surface →

Entries are built from NVD catalog data enriched with EPSS scores, CISA KEV status, exploit references and Trusteed triage signals. The free tool shows the same intelligence layer we use inside the platform — without requiring a login.

Also try the free SSL certificate check.

Knowing the CVE is step one. Finding it on your perimeter is step two.

Map external assets, match products to CVEs and track fixes continuously with Trusteed CTEM.