peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,573 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-2357 EXP Directory traversal vulnerability in EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. Patch early 5.0 medium 3.1% 2005-08-16
CVE-2005-4160 EXP Directory traversal vulnerability in getdox.php in Torrential 1.2 allows remote attackers to read arbitrary files via "../" sequences in the query str… Patch early 5.0 medium 3.1% 2005-12-11
CVE-2005-4250 EXP Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via the language parameter. Patch early 5.0 medium 3.1% 2005-12-14
CVE-2009-4688 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Shopping Cart Selling Website Script allow remote attackers to inject arbitrar… Patch early 4.3 medium 3.1% 2010-03-10
CVE-2013-4898 EXP Unrestricted file upload vulnerability in the user profile page feature in the Timeline Plugin 4.2.5p9 for SocialEngine allows remote authenticated us… Patch early 6.5 medium 3.1% 2014-01-29
CVE-2023-34927 EXP Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows… Patch early 6.5 medium 3.1% 2023-06-22
CVE-2020-35437 EXP Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI. Patch early 6.1 medium 3.1% 2020-12-26
CVE-2019-1344 EXP An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memory, aka 'Windows Code Integrit… Patch early 5.5 medium 3.1% 2019-10-10
CVE-2004-1585 EXP Flash Messaging 5.2.0g (rev 1.1.2) and earlier allows remote attackers to cause a denial of service (application crash) via certain wide characters. Patch early 5.0 medium 3.1% 2004-12-31
CVE-2004-1727 EXP BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address. Patch early 5.0 medium 3.1% 2004-08-20
CVE-2005-0568 EXP Soldier of Fortune II 1.03 gold allows remote attackers to cause a denial of service (application crash) via a large cl_guid value, which results in a… Patch early 5.0 medium 3.1% 2005-05-02
CVE-2005-0848 EXP Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, S… Patch early 5.0 medium 3.1% 2005-05-02
CVE-2005-2791 EXP BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, allows remote attackers to cause a denial of service (refuse… Patch early 5.0 medium 3.1% 2005-09-02
CVE-2023-3897 EXP Username enumeration is possible through Bypassing CAPTCHA in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local use… Patch early 4.8 medium 3.1% 2023-07-25
CVE-2020-28249 EXP Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note. Patch early 6.1 medium 3.1% 2020-11-06
CVE-2004-2045 EXP The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (dev… Patch early 5.0 medium 3.1% 2004-12-31
CVE-2004-2120 EXP Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET requests without the HTTP versio… Patch early 5.0 medium 3.1% 2004-01-23
CVE-1999-1130 EXP Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the sourc… Patch early 5.0 medium 3.1% 1999-07-30
CVE-2001-0693 EXP WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20). Patch early 5.0 medium 3.1% 2001-09-20
CVE-2013-5756 EXP Directory traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a .. (dot dot) in the p… Patch early 4.0 medium 3.1% 2014-08-03
CVE-2008-6201 EXP Directory traversal vulnerability in help.php in the eskuel module in KwsPHP 1.3.456, as available before 20080416, allows remote attackers to execute… Patch early 6.8 medium 3.1% 2009-02-20
CVE-2005-1800 EXP Cross-site scripting (XSS) vulnerability in Jaws Glossary gadget 0.4 to 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the t… Patch early 4.3 medium 3.1% 2005-05-28
CVE-2017-11330 EXP The DivFixppCore::avi_header_fix function in DivFix++Core.cpp in DivFix++ v0.34 allows remote attackers to cause a denial of service (invalid memory w… Patch early 5.5 medium 3.1% 2017-07-31
CVE-2009-2890 EXP Cross-site scripting (XSS) vulnerability in results.php in PHP Scripts Now Riddles allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 3.1% 2009-08-20
CVE-2008-4366 EXP Unrestricted file upload vulnerability in the image upload component in Camera Life 2.6.2b4 allows remote authenticated users to execute arbitrary cod… Patch early 6.5 medium 3.1% 2008-09-30
CVE-2008-6914 EXP Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users to execute arbitrary code by up… Patch early 6.5 medium 3.1% 2009-08-07
CVE-2008-7185 EXP GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlist (.pls) file with a long Titl… Patch early 4.3 medium 3.1% 2009-09-08
CVE-2007-1127 EXP Directory traversal vulnerability in enc/stylecss.php in shopkitplus allows remote attackers to read arbitrary files via a .. (dot dot) in the changet… Patch early 6.4 medium 3.1% 2007-02-27
CVE-2008-3407 EXP phpLinkat 0.1 allows remote attackers to bypass authentication and access unspecified pages under admin/ by sending a login=right cookie. Patch early 5.0 medium 3.1% 2008-07-31
CVE-2007-5982 EXP Multiple cross-site scripting (XSS) vulnerabilities in X7 Chat 2.0.4, 2.0.5, and possibly other versions allow remote attackers to inject arbitrary we… Patch early 4.3 medium 3.1% 2007-11-15
← previous page 175 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt