peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,032 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-1786 EXP PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive infor… Patch early 5.0 medium 2.8% 2004-01-04
CVE-2004-2374 EXP BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php, which includes the pathname… Patch early 5.0 medium 2.8% 2004-12-31
CVE-2019-17504 EXP An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vulnerability allows remote attack… Patch early 6.1 medium 2.8% 2019-10-11
CVE-2018-1563 EXP IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site scripting. This vulnerability… Patch early 5.4 medium 2.8% 2018-07-20
CVE-2009-4627 EXP Directory traversal vulnerability in sources/_template_parser.php in Moa Gallery 1.2.0 and earlier allows remote attackers to read arbitrary files via… Patch early 5.0 medium 2.8% 2010-01-18
CVE-2006-6758 EXP Directory traversal vulnerability in Http explorer 1.02 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the URI. Patch early 5.0 medium 2.8% 2006-12-27
CVE-2007-5306 EXP ELSEIF CMS Beta 0.6 allows remote attackers to obtain sensitive information (full path) via unspecified vectors to utilisateurs/votesresultats.php. Patch early 5.0 medium 2.8% 2007-10-09
CVE-2013-2623 EXP Cross-site Scripting (XSS) in Telaen before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the "f_email" parameter in index.… Patch early 6.1 medium 2.8% 2020-02-03
CVE-2005-0345 EXP viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protected forums v… Patch early 5.0 medium 2.8% 2005-05-02
CVE-2009-3149 EXP Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a… Patch early 4.3 medium 2.8% 2009-09-10
CVE-2007-2202 EXP PHP remote file inclusion vulnerability in inc_ACVS/SOAP/Transport.php in Accueil et Conseil en Visites et Sejours Web Services (ACVSWS) PHP5 (ACVSWS_… Patch early 6.8 medium 2.8% 2007-04-24
CVE-2019-1148 EXP An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who suc… Patch early 5.5 medium 2.8% 2019-08-14
CVE-2019-1153 EXP An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who suc… Patch early 5.5 medium 2.8% 2019-08-14
CVE-2008-2969 EXP Directory traversal vulnerability in download.php in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allows remote attackers to read… Patch early 5.0 medium 2.8% 2008-07-02
CVE-2008-4758 EXP Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local files via a .. (dot dot) in the fi… Patch early 5.0 medium 2.8% 2008-10-28
CVE-2007-2009 EXP PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 6.8 medium 2.8% 2007-04-12
CVE-2007-3608 EXP Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certain files via unspecified vector… Patch early 5.0 medium 2.8% 2007-07-06
CVE-2007-6400 EXP Directory traversal vulnerability in download_file.php in PolDoc CMS (aka PDDMS) 0.96 allows remote attackers to read arbitrary files via a .. (dot do… Patch early 5.0 medium 2.8% 2007-12-17
CVE-2012-1112 EXP Directory traversal vulnerability in Open-Realty CMS 2.5.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (… Patch early 6.8 medium 2.8% 2012-09-06
CVE-2013-4240 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to hijack… Patch early 6.8 medium 2.8% 2014-04-02
CVE-2009-1808 EXP Microsoft Windows XP SP3 allows local users to cause a denial of service (system crash) by making an SPI_SETDESKWALLPAPER SystemParametersInfo call wi… Patch early 4.9 medium 2.8% 2009-05-28
CVE-2006-6604 EXP Directory traversal vulnerability in downloaddetails.php in TorrentFlux 2.2 allows remote authenticated users to read arbitrary files via .. (dot dot)… Patch early 6.5 medium 2.8% 2006-12-15
CVE-2016-4315 EXP Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requ… Patch early 5.7 medium 2.8% 2017-02-17
CVE-2003-1499 EXP Directory traversal vulnerability in index.php in Bytehoard 0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the infolder par… Patch early 5.0 medium 2.8% 2003-12-31
CVE-2008-0361 EXP Directory traversal vulnerability in agregar_info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local file… Patch early 4.3 medium 2.8% 2008-01-18
CVE-2019-10893 EXP CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to Stored/Persistent XSS for Adm… Patch early 4.8 medium 2.8% 2019-04-18
CVE-2013-2945 EXP SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to execute arbitrary SQL command… Patch early 6.5 medium 2.8% 2014-04-02
CVE-2004-0374 EXP Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensitive SQL information via an HT… Patch early 6.4 medium 2.8% 2004-05-04
CVE-2007-1577 EXP Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) i… Patch early 5.0 medium 2.8% 2007-03-21
CVE-2008-7008 EXP HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a direct request to admin/backup/… Patch early 5.0 medium 2.8% 2009-08-19
← previous page 187 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt