peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,121 CVEs 1,733 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-0479 EXP Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz NewsPad 1.02 allows remote attackers to list arbitrary directories, and .txt and… Patch early 5.0 medium 3.9% 2008-01-29
CVE-2008-0480 EXP Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary directories, and .txt and .zi… Patch early 5.0 medium 3.9% 2008-01-29
CVE-2008-0481 EXP Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .… Patch early 5.0 medium 3.9% 2008-01-29
CVE-2007-0707 EXP Stack-based buffer overflow in GOM Player 2.0.12.3375 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI… Patch early 6.8 medium 3.9% 2007-02-04
CVE-2017-13754 EXP Cross-site scripting (XSS) vulnerability in the "advanced settings - time server" module in Wibu-Systems CodeMeter before 6.50b allows remote attacker… Patch early 5.4 medium 3.9% 2017-09-07
CVE-2010-2543 EXP Cross-site scripting (XSS) vulnerability in include/top_graph_header.php in Cacti before 0.8.7g allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 3.9% 2010-08-23
CVE-2006-2254 EXP Buffer overflow in filecpnt.exe in FileCOPA 1.01 allows remote attackers to cause a denial of service (application crash) via a username with a large… Patch early 5.0 medium 3.9% 2006-05-09
CVE-2001-0821 EXP The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive d… Patch early 5.0 medium 3.9% 2001-12-06
CVE-2002-1445 EXP Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent pa… Patch early 4.3 medium 3.9% 2002-08-12
CVE-2015-2517 EXP The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012… Patch early 6.9 medium 3.9% 2015-09-09
CVE-2007-4711 EXP Multiple cross-site scripting (XSS) vulnerabilities in Toms Gaestebuch 1.00 allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 4.3 medium 3.9% 2007-09-05
CVE-2011-5211 EXP Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 3.9% 2012-10-22
CVE-2018-10068 EXP The jDownloads extension before 3.2.59 for Joomla! has XSS. Patch early 6.1 medium 3.9% 2018-04-12
CVE-2017-11548 EXP The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service (memory corruption) via a cr… Patch early 5.5 medium 3.9% 2017-07-31
CVE-2000-1036 EXP Directory traversal vulnerability in Extent RBS ISP web server allows remote attackers to read sensitive information via a .. (dot dot) attack on the… Patch early 5.0 medium 3.9% 2000-12-11
CVE-2002-1042 EXP Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Win… Patch early 5.0 medium 3.9% 2002-10-04
CVE-2013-3661 EXP The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2… Patch early 4.9 medium 3.9% 2013-05-24
CVE-2006-4294 EXP Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the f… Patch early 5.0 medium 3.8% 2006-09-09
CVE-2006-4062 EXP PHP remote file inclusion vulnerability in usr/extensions/get_tree.inc.php in Dmitry Sheiko SAPID Shop 1.2 and earlier allows remote attackers to exec… Patch early 5.1 medium 3.8% 2006-08-10
CVE-2023-32750 EXP Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The… Patch early 6.5 medium 3.8% 2023-06-08
CVE-2013-3575 EXP hpdiags/frontend2/help/pageview.php in HP Insight Diagnostics 9.4.0.4710 does not properly restrict PHP include or require statements, which allows re… Patch early 5.0 medium 3.8% 2013-06-14
CVE-2012-2939 EXP Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute arbitrary code by uploading a… Patch early 6.5 medium 3.8% 2012-05-27
CVE-2006-1214 EXP UnrealIRCd 3.2.3 allows remote attackers to cause an unspecified denial of service by causing a linked server to send malformed TKL Q:Line commands, a… Patch early 5.0 medium 3.8% 2006-03-14
CVE-2007-0113 EXP Buffer overflow in Packeteer PacketShaper PacketWise 8.x allows remote authenticated users to cause a denial of service (reset or reboot) via (1) a lo… Patch early 6.8 medium 3.8% 2007-01-09
CVE-2013-7233 EXP Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows r… Patch early 6.8 medium 3.8% 2013-12-30
CVE-2007-4442 EXP Stack-based buffer overflow in the logging function in the Unreal engine, possibly 2003 and 2004, as used in the internal web server, allows remote at… Patch early 5.0 medium 3.8% 2007-08-21
CVE-2004-1973 EXP DiGi Web Server allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request that contains a large number of / (slas… Patch early 5.0 medium 3.8% 2004-04-27
CVE-2004-2029 EXP The Util_DecodeHTTPAuth function in BNBT BitTorrent Tracker Beta 7.5 Release 2 and earlier allows remote attackers to cause a denial of service (crash… Patch early 5.0 medium 3.8% 2004-05-22
CVE-2004-2035 EXP MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of tra… Patch early 5.0 medium 3.8% 2004-05-26
CVE-2012-4867 EXP Directory traversal vulnerability in modules/com_vtiger_workflow/sortfieldsjson.php in vtiger CRM 5.1.0 allows remote attackers to read arbitrary file… Patch early 5.0 medium 3.8% 2012-09-06
← previous page 138 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt