peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,997 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-6459 EXP Anon Proxy Server 0.100, and probably 0.101, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the host parameter… Patch early 6.8 medium 2.9% 2007-12-20
CVE-2014-8654 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway hardware 1.0 with f… Patch early 6.8 medium 2.9% 2014-11-06
CVE-2018-15918 EXP An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive… Patch early 5.4 medium 2.9% 2018-09-05
CVE-2011-4813 EXP Directory traversal vulnerability in clientarea.php in WHMCompleteSolution (WHMCS) 3.x.x allows remote attackers to read arbitrary files via an invali… Patch early 5.0 medium 2.9% 2011-12-14
CVE-2000-0739 EXP Directory traversal vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to read arbitrary file… Patch early 5.0 medium 2.9% 2000-10-20
CVE-2003-1089 EXP index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names, which reveals the path in a PH… Patch early 5.0 medium 2.9% 2003-12-31
CVE-2003-1162 EXP index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id, forum_id, and… Patch early 5.0 medium 2.9% 2003-12-31
CVE-2004-2636 EXP TinyWeb 1.9 allows remote attackers to read source code of scripts via "/./" in the URL. Patch early 5.0 medium 2.9% 2004-12-31
CVE-2005-1645 EXP Keyvan1 ImageGallery stores the image.mdb database under the web document root with insufficient access control, which allows remote attackers to obta… Patch early 5.0 medium 2.9% 2005-05-18
CVE-2005-2956 EXP ATutor 1.5.1, and possibly earlier versions, stores temporary chat logs under the web document root with insufficient access control and predictable f… Patch early 5.0 medium 2.9% 2005-09-16
CVE-2005-3432 EXP MiniGal 2 (MG2) 0.5.1 allows remote attackers to list password protected images via a request to index.php with the list parameter set to * (wildcard)… Patch early 5.0 medium 2.9% 2005-11-02
CVE-2005-3728 EXP Idetix Software Systems Revize CMS stores conf/revize.xml under the web document root with insufficient access control, which allows remote attackers… Patch early 5.0 medium 2.9% 2005-11-21
CVE-2005-4423 EXP Unrestricted file upload vulnerability in PHPFM before 0.2.3 allows remote authenticated users to execute arbitrary code by uploading a file with an e… Patch early 6.5 medium 2.9% 2005-12-20
CVE-2006-2763 EXP SQL injection vulnerability in Pre News Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) index.ph… Patch early 6.4 medium 2.9% 2006-06-02
CVE-2012-2237 EXP Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web… Patch early 6.1 medium 2.9% 2019-12-17
CVE-2007-1152 EXP Multiple directory traversal vulnerabilities in Pyrophobia 2.1.3.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) act or… Patch early 5.0 medium 2.9% 2007-03-02
CVE-2018-0745 EXP The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an information disclosure vulnerabilit… Patch early 4.7 medium 2.9% 2018-01-04
CVE-2007-0697 EXP index2.php in ACGVannu 1.3 and earlier allows remote attackers to change the password or profile of a user via a modified id parameter, related to tem… Patch early 6.4 medium 2.9% 2007-02-03
CVE-2005-2467 EXP Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML v… Patch early 5.8 medium 2.9% 2005-12-31
CVE-2006-6158 EXP Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpde… Patch early 6.8 medium 2.9% 2006-11-28
CVE-2000-1224 EXP Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters… Patch early 5.0 medium 2.9% 2000-11-23
CVE-2012-5905 EXP Buffer overflow in KnFTPd 1.0.0 allows remote authenticated users to cause a denial of service (crash) via a long string in a FEAT command. Patch early 4.0 medium 2.9% 2012-11-17
CVE-2006-5811 EXP PHP remote file inclusion vulnerability in library/translation.inc.php in OpenEMR 2.8.1, with register_globals enabled, allows remote attackers to exe… Patch early 6.8 medium 2.9% 2006-11-08
CVE-2006-6044 EXP PHP remote file inclusion vulnerability in gallery_top.inc.php in PHPQuickGallery 1.9 and earlier allows remote attackers to execute arbitrary PHP cod… Patch early 6.8 medium 2.9% 2006-11-22
CVE-2006-2252 EXP Cross-site scripting vulnerability in submit.php in OpenFAQ 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter. Patch early 6.4 medium 2.9% 2006-05-09
CVE-2012-2741 EXP Cross-site scripting (XSS) vulnerability in public_html/lists/admin/ in phpList before 2.10.18 allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 2.9% 2012-09-06
CVE-2010-2676 EXP Multiple directory traversal vulnerabilities in index.php in Open Web Analytics (OWA) 1.2.3 might allow remote attackers to read arbitrary files via d… Patch early 5.0 medium 2.9% 2010-07-08
CVE-2006-6643 EXP Fightersoft Multimedia Star FTP server 1.10 allows remote attackers to cause a denial of service (crash) via multiple RETR commands with long argument… Patch early 5.0 medium 2.9% 2006-12-20
CVE-2015-2838 EXP Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authen… Patch early 6.8 medium 2.9% 2015-04-03
CVE-2005-1674 EXP Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG… Patch early 6.5 medium 2.9% 2005-05-19
← previous page 185 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt