peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,957 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-5716 EXP Directory traversal vulnerability in aff_news.php in FreeNews 2.1 allows remote attackers to include local files via a .. (dot dot) sequence in the ch… Patch early 5.0 medium 2.9% 2006-11-04
CVE-2007-0429 EXP DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to cause a denial of service (Int… Patch early 5.0 medium 2.9% 2007-01-23
CVE-2021-33562 EXP A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.8 medium 2.9% 2021-05-24
CVE-2000-1114 EXP Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+"… Patch early 5.0 medium 2.9% 2001-01-09
CVE-2006-3846 EXP PHP remote file inclusion vulnerability in extadminmenus.class.php in the MultiBanners 1.0.1 for Mambo allows remote attackers to execute arbitrary PH… Patch early 6.8 medium 2.9% 2006-07-25
CVE-2008-6045 EXP Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTC… Patch early 6.8 medium 2.9% 2009-02-03
CVE-2007-1427 EXP Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 5.0 medium 2.9% 2007-03-13
CVE-2005-4510 EXP Directory traversal vulnerability in server.np in NetPublish Server 7 allows remote attackers to read arbitrary files via "../" sequences in the templ… Patch early 5.0 medium 2.9% 2005-12-23
CVE-2007-4101 EXP Multiple PHP remote file inclusion vulnerabilities in Madoa Poll 1.1 allow remote attackers to execute arbitrary PHP code via the Madoa parameter to (… Patch early 6.8 medium 2.9% 2007-07-31
CVE-2006-6254 EXP administration/telecharger.php in Cahier de texte 2.0 allows remote attackers to obtain unparsed content (source code) of files via the chemin paramet… Patch early 4.3 medium 2.9% 2006-12-04
CVE-2004-1217 EXP Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathnam… Patch early 5.0 medium 2.9% 2005-01-10
CVE-2005-1002 EXP logwebftbs2000.exe in Logics Software File Transfer (LOG-FT) allows remote attackers to read arbitrary files via modified (1) VAR_FT_LANG and (2) VAR_… Patch early 5.0 medium 2.9% 2005-05-02
CVE-2005-3576 EXP ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the article number in tsurl parameter. Patch early 5.0 medium 2.9% 2005-11-16
CVE-2005-2044 EXP Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 2.9% 2005-06-16
CVE-2002-1865 EXP Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (2) Linksys Etherfast BEFW11S4… Patch early 5.0 medium 2.9% 2002-12-31
CVE-2008-0521 EXP Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to read arbitrary files via a .. (dot dot) in the uri par… Patch early 5.0 medium 2.9% 2008-01-31
CVE-2008-3087 EXP Directory traversal vulnerability in Kasseler CMS 1.3.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to in… Patch early 5.0 medium 2.9% 2008-07-09
CVE-2008-5598 EXP Directory traversal vulnerability in index.php in PHPmyGallery 1.51 gold allows remote attackers to list arbitrary directories via a .. (dot dot) in t… Patch early 5.0 medium 2.9% 2008-12-16
CVE-2009-4886 EXP Multiple directory traversal vulnerabilities in phpCommunity 2 2.1.8 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) file… Patch early 5.0 medium 2.9% 2010-06-11
CVE-2018-7701 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers to hijack the authentication… Patch early 6.5 medium 2.9% 2018-03-15
CVE-2017-11355 EXP Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML… Patch early 6.1 medium 2.9% 2017-08-02
CVE-2019-13234 EXP In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine. Patch early 6.1 medium 2.9% 2019-08-27
CVE-2019-13235 EXP In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form. Patch early 6.1 medium 2.9% 2019-08-27
CVE-2012-1935 EXP Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4.x before 4 RC4 allow remote attackers to inject arbitrary web… Patch early 4.3 medium 2.9% 2012-08-27
CVE-2007-5587 EXP Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 20… Patch early 6.9 medium 2.9% 2007-10-19
CVE-2007-0881 EXP PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL i… Patch early 6.8 medium 2.9% 2007-02-12
CVE-2010-1335 EXP Multiple PHP remote file inclusion vulnerabilities in Insky CMS 006-0111, when register_globals is enabled, allow remote attackers to execute arbitrar… Patch early 6.8 medium 2.9% 2010-04-09
CVE-2010-1934 EXP Multiple PHP remote file inclusion vulnerabilities in openMairie openPlanning 1.00, when register_globals is enabled, allow remote attackers to execut… Patch early 6.8 medium 2.9% 2010-05-12
CVE-2014-1664 EXP The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which allows attackers to obtain user… Patch early 5.0 medium 2.9% 2014-01-26
CVE-2007-3013 EXP SQL injection vulnerability in activeWeb contentserver before 5.6.2964 allows remote authenticated users with edit permission to execute arbitrary SQL… Patch early 6.5 medium 2.9% 2007-07-15
← previous page 183 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt