peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,295 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-1999-1081 EXP Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files. Patch early 5.0 medium 3.4% 2002-01-15
CVE-2022-4953 EXP The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be use… Patch early 6.1 medium 3.4% 2023-08-14
CVE-2002-2149 EXP Buffer overflow in Lucent Access Point 300, 600, and 1500 Service Routers allows remote attackers to cause a denial of service (reboot) via a long HTT… Patch early 5.0 medium 3.4% 2002-12-31
CVE-2003-1173 EXP Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking all of the se… Patch early 5.0 medium 3.4% 2003-12-31
CVE-2004-1194 EXP Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname… Patch early 5.0 medium 3.4% 2005-01-10
CVE-2004-2129 EXP SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow… Patch early 5.0 medium 3.4% 2004-12-31
CVE-2003-1292 EXP PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbitrary remote files via a URL in… Patch early 5.0 medium 3.4% 2003-12-31
CVE-2005-2892 EXP Directory traversal vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to read arbitrary files via… Patch early 5.0 medium 3.4% 2005-09-14
CVE-2006-6924 EXP bitweaver 1.3.1 and earlier allows remote attackers to obtain sensitive information via a sort_mode=-98 query string to (1) blogs/list_blogs.php, (2)… Patch early 5.0 medium 3.4% 2007-01-13
CVE-2012-1059 EXP Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce Online Merchant 3.0.2 allows re… Patch early 4.3 medium 3.4% 2012-02-14
CVE-2007-6630 EXP The Url_init function in utils/url.c in Netembryo 0.0.4, when used by LScube Feng, allows remote attackers to cause a denial of service (NULL derefere… Patch early 5.0 medium 3.4% 2008-01-04
CVE-2002-2071 EXP Compaq Tru64 4.0 d allows remote attackers to cause a denial of service in (1) telnet, (2) FTP, (3) ypbind, (4) rpc.lockd, (5) snmp, (6) ttdbserverd,… Patch early 5.0 medium 3.4% 2002-12-31
CVE-2006-0175 EXP Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 3.4% 2006-01-11
CVE-2000-0394 EXP NetProwler 3.0 allows remote attackers to cause a denial of service by sending malformed IP packets that trigger NetProwler's Man-in-the-Middle signat… Patch early 5.0 medium 3.4% 2000-05-18
CVE-2003-0706 EXP Unknown vulnerability in mah-jong 1.5.6 and earlier allows remote attackers to cause a denial of service (tight loop). Patch early 5.0 medium 3.4% 2003-09-17
CVE-2014-2647 EXP Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communications Broker) before 11.14 allows… Patch early 4.3 medium 3.4% 2014-10-19
CVE-2011-4090 EXP Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation. Patch early 6.1 medium 3.4% 2019-11-26
CVE-2006-4714 EXP PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier, when register_globa… Patch early 5.1 medium 3.4% 2006-09-12
CVE-2005-2239 EXP oftpd 0.3.7 allows remote attackers to cause a denial of service via a USER command with a large number of null (\0) characters. Patch early 5.0 medium 3.4% 2005-07-12
CVE-2008-4741 EXP Directory traversal vulnerability in index.php in FAR-PHP 1.00, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via… Patch early 5.0 medium 3.4% 2008-10-27
CVE-2009-2533 EXP rmserver in RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allows remote attackers to cause a denial of service (daemon exit) via mul… Patch early 5.0 medium 3.4% 2009-07-20
CVE-2008-6929 EXP Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file wi… Patch early 6.5 medium 3.4% 2009-08-11
CVE-2009-1446 EXP Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by upl… Patch early 6.5 medium 3.4% 2009-04-27
CVE-2021-45425 EXP Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScript codes. Patch early 6.1 medium 3.4% 2021-12-28
CVE-2004-1908 EXP McFreeScan.CoMcFreeScan.1 ActiveX object in Mcafee FreeScan allows remote attackers to obtain sensitive information via the GetSpecialFolderLocation f… Patch early 5.0 medium 3.4% 2004-12-31
CVE-2005-1329 EXP owOfflineCC.asp in OneWorldStore allows remote attackers to obtain sensitive information by modifying the idOrder parameter. Patch early 5.0 medium 3.4% 2005-05-02
CVE-2006-1209 EXP PHP Advanced Transfer Manager 1.00 through 1.30 stores sensitive information, including password hashes, under the web root with insufficient access c… Patch early 5.0 medium 3.4% 2006-03-14
CVE-2019-9650 EXP An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event. Patch early 6.1 medium 3.4% 2019-03-11
CVE-2012-6500 EXP Directory traversal vulnerability in download.lib.php in Pragyan CMS 3.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot… Patch early 5.0 medium 3.4% 2013-01-12
CVE-2007-1472 EXP Variable overwrite vulnerability in groupit/base/groupit.start.inc in Groupit 2.00b5 allows remote attackers to conduct remote file inclusion attacks… Patch early 6.8 medium 3.4% 2007-03-16
← previous page 157 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt