peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,921 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-02

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-0409 EXP CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit… Patch early 6.4 medium 5.7% 2005-02-14
CVE-2018-17441 EXP An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to sto… Patch early 6.1 medium 5.7% 2018-10-08
CVE-2018-17443 EXP An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateSite endpoint is vulnerable to… Patch early 6.1 medium 5.7% 2018-10-08
CVE-2006-7141 EXP Absolute path traversal vulnerability in Oracle Database Server, when utl_file_dir is set to a wildcard value or "CREATE ANY DIRECTORY to PUBLIC" priv… Patch early 6.0 medium 5.7% 2007-03-07
CVE-2017-14085 EXP Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to q… Patch early 5.3 medium 5.7% 2017-10-06
CVE-2007-1126 EXP Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a .. (dot dot) in the template parame… Patch early 5.0 medium 5.6% 2007-02-27
CVE-1999-0746 EXP A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service. Patch early 5.0 medium 5.6% 1999-08-16
CVE-1999-0804 EXP Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths. Patch early 5.0 medium 5.6% 1999-06-01
CVE-2007-1571 EXP PHP remote file inclusion vulnerability in includes/base.php in Radical Designs Activist Mobilization Platform (AMP) 3.2, when register_globals is ena… Patch early 6.8 medium 5.6% 2007-03-21
CVE-2007-2089 EXP Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and Joomla! allow remote attacker… Patch early 6.8 medium 5.6% 2007-04-18
CVE-2018-12095 EXP A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod para… Patch early 5.4 medium 5.6% 2018-06-11
CVE-2006-3751 EXP PHP remote file inclusion vulnerability in popups/ImageManager/config.inc.php in the HTMLArea3 Addon Component (com_htmlarea3_xtd-c) for ImageManager… Patch early 6.8 medium 5.6% 2006-07-21
CVE-2012-1933 EXP Multiple PHP remote file inclusion vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4 before RC4, when register_globals is enabled, allow remote att… Patch early 6.8 medium 5.6% 2012-08-27
CVE-2011-4614 EXP PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x before 4.5.9, 4… Patch early 6.8 medium 5.6% 2012-02-18
CVE-2013-4094 EXP The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated… Patch early 6.5 medium 5.6% 2013-06-28
CVE-2008-3493 EXP vncviewer.exe in RealVNC Windows Client 4.1.2.0 allows remote VNC servers to cause a denial of service (application crash) via a crafted frame buffer… Patch early 5.0 medium 5.6% 2008-08-06
CVE-2022-39291 EXP ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are subject to a vulnerability which… Patch early 5.4 medium 5.6% 2022-10-07
CVE-2021-35323 EXP Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login. Patch early 6.1 medium 5.6% 2021-10-19
CVE-1999-0116 EXP Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka S… Patch early 5.0 medium 5.6% 1996-09-19
CVE-2005-2787 EXP comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter. Patch early 5.0 medium 5.6% 2005-09-02
CVE-2008-5272 EXP Multiple directory traversal vulnerabilities in Fred Stuurman SyndeoCMS 2.6.0 allow remote authenticated users to read arbitrary files via a .. (dot d… Patch early 4.0 medium 5.6% 2008-11-28
CVE-2005-3301 EXP Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via c… Patch early 4.3 medium 5.6% 2005-10-24
CVE-2008-6884 EXP Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to include and execute arbitrary… Patch early 6.8 medium 5.6% 2009-07-31
CVE-2007-4902 EXP Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allows remote attacker… Patch early 6.4 medium 5.6% 2007-09-17
CVE-2010-3906 EXP Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) f an… Patch early 4.3 medium 5.6% 2010-12-17
CVE-2009-4775 EXP Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash) via format str… Patch early 4.3 medium 5.6% 2010-04-21
CVE-2016-1415 EXP Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of service (application crash) via a c… Patch early 5.5 medium 5.6% 2016-09-03
CVE-2007-5294 EXP PHP remote file inclusion vulnerability in core/aural.php in IDMOS 1.0-beta (aka Phoenix) allows remote attackers to execute arbitrary PHP code via a… Patch early 6.8 medium 5.6% 2007-10-09
CVE-2006-7055 EXP PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in… Patch early 6.8 medium 5.6% 2007-02-24
CVE-2008-3714 EXP Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_str… Patch early 4.3 medium 5.6% 2008-08-19
← previous page 103 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt