peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,317 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-6000 EXP KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a denial of service (crash) via large HTTP cookie parameters. Patch early 5.0 medium 3.3% 2007-11-15
CVE-2009-4451 EXP Unrestricted file upload vulnerability in upper.php in kandalf upper 0.1 allows remote attackers to execute arbitrary code by uploading a file with an… Patch early 6.8 medium 3.3% 2009-12-29
CVE-2009-4819 EXP Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitrary code by uploading a file w… Patch early 6.8 medium 3.3% 2010-04-27
CVE-2010-0390 EXP Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mim… Patch early 6.8 medium 3.3% 2010-01-26
CVE-2008-6528 EXP NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to the URL, which accesses the alt… Patch early 5.0 medium 3.3% 2009-03-26
CVE-2010-4863 EXP Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 3.3% 2011-10-05
CVE-2006-4458 EXP Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers to include… Patch early 6.4 medium 3.3% 2006-08-31
CVE-2008-6900 EXP Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allows remote authenticated users… Patch early 6.5 medium 3.3% 2009-08-06
CVE-2015-1674 EXP The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly validate an unspecified… Patch early 4.6 medium 3.3% 2015-05-13
CVE-2001-1347 EXP Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using globa… Patch early 4.6 medium 3.3% 2001-05-24
CVE-2010-3314 EXP Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1… Patch early 4.3 medium 3.3% 2010-09-22
CVE-2004-2675 EXP ArGoSoft FTP Server before 1.4.1.6 allows remote authenticated users to cause a denial of service (crash) via a SITE PASS command with a long password… Patch early 6.8 medium 3.3% 2004-12-31
CVE-2017-11831 EXP Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,… Patch early 4.7 medium 3.3% 2017-11-15
CVE-2009-4612 EXP Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inje… Patch early 4.3 medium 3.3% 2010-01-13
CVE-2012-1464 EXP Dashboard Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the installation path via a request with a trailing "?" c… Patch early 5.0 medium 3.3% 2012-03-19
CVE-2012-1466 EXP The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code of NtDecision script files with… Patch early 5.0 medium 3.3% 2012-03-19
CVE-2002-1945 EXP Buffer overflow in SmartMail Server 1.0 Beta 10 allows remote attackers to cause a denial of service (crash) via a long request to (1) TCP port 25 (SM… Patch early 5.0 medium 3.3% 2002-12-31
CVE-2003-1158 EXP Multiple buffer overflows in the FTP service in Plug and Play Web Server 1.0002c allow remote attackers to cause a denial of service (crash) via long… Patch early 5.0 medium 3.3% 2003-12-31
CVE-2017-6443 EXP Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web script or HTML via the W_AD1 pa… Patch early 6.1 medium 3.3% 2017-03-15
CVE-2006-6203 EXP Directory traversal vulnerability in startdown.php in the Flyspray ME 1.0.1 (com_flyspray) component for Mambo allows remote attackers to read arbitra… Patch early 5.0 medium 3.3% 2006-12-01
CVE-2012-1258 EXP cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow… Patch early 6.5 medium 3.3% 2020-01-09
CVE-2008-3208 EXP Simple DNS Plus 4.1, 5.0, and possibly other versions before 5.1.101 allows remote attackers to cause a denial of service via multiple DNS reply packe… Patch early 5.0 medium 3.3% 2008-07-18
CVE-2013-3514 EXP Multiple directory traversal vulnerabilities in OpenX before 2.8.10 revision 82710 allow remote administrators to read arbitrary files via a .. (dot d… Patch early 4.3 medium 3.3% 2014-05-14
CVE-2008-2648 EXP Unrestricted file upload vulnerability in upload/uploader.html in meBiblio 0.4.7 allows remote attackers to execute arbitrary code by uploading a .php… Patch early 6.8 medium 3.3% 2008-06-10
CVE-2008-6617 EXP Unrestricted file upload vulnerability in adm/visual/upload.php in SiteXS CMS 0.1.1 allows remote attackers to execute arbitrary code by uploading a f… Patch early 6.8 medium 3.3% 2009-04-06
CVE-2008-6814 EXP Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earlier for Mambo allows remote at… Patch early 6.8 medium 3.3% 2009-05-28
CVE-2008-7157 EXP Unrestricted file upload vulnerability in EkinBoard 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading an avatar file wi… Patch early 6.8 medium 3.3% 2009-09-02
CVE-2022-41358 EXP A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a cra… Patch early 5.4 medium 3.3% 2022-10-20
CVE-2001-0038 EXP Offline Explorer 1.4 before Service Release 2 allows remote attackers to read arbitrary files by specifying the drive letter (e.g. C:) in the requeste… Patch early 5.0 medium 3.3% 2001-02-16
CVE-2001-0452 EXP BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls com… Patch early 5.0 medium 3.3% 2001-06-27
← previous page 160 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt