peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,553 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-0687 EXP process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote attackers to include arb… Patch early 5.0 medium 2.8% 2006-02-15
CVE-2006-4068 EXP The pswd.js script relies on the client to calculate whether a username and password match hard-coded hashed values for a server, and uses a hashing s… Patch early 5.0 medium 2.8% 2006-08-10
CVE-2012-1664 EXP Multiple cross-site scripting (XSS) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to inject arbitrary web script or… Patch early 4.3 medium 2.8% 2015-05-20
CVE-2014-4717 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote attackers to… Patch early 6.8 medium 2.8% 2014-07-03
CVE-2009-1514 EXP Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a throw statement w… Patch early 5.0 medium 2.8% 2009-05-04
CVE-2010-5240 EXP Multiple untrusted search path vulnerabilities in Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 allow local users to gain privileges via a Trojan hors… Patch early 6.9 medium 2.8% 2012-09-07
CVE-2007-2900 EXP Multiple PHP remote file inclusion vulnerabilities in Scallywag 2005-04-25 allow remote attackers to execute arbitrary PHP code via a URL in the path… Patch early 6.8 medium 2.8% 2007-05-30
CVE-2007-6585 EXP PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to execute arbitrary PHP code via… Patch early 6.8 medium 2.8% 2007-12-28
CVE-2005-1423 EXP Directory traversal vulnerability in the mail program in 602LAN SUITE 2004.0.05.0413 allows remote attackers to cause a denial of service and determin… Patch early 6.4 medium 2.8% 2005-05-03
CVE-2014-2922 EXP The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.1.0 does not properly handle an objec… Patch early 6.4 medium 2.8% 2014-04-21
CVE-2014-5090 EXP admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location f… Patch early 6.5 medium 2.8% 2014-08-06
CVE-2014-9001 EXP reminders/index.php in Incredible PBX 11 2.0.6.5.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1)… Patch early 6.5 medium 2.8% 2014-11-20
CVE-2003-1430 EXP Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an… Patch early 5.0 medium 2.8% 2003-12-31
CVE-2006-5428 EXP rpc.php in Cerberus Helpdesk 3.2.1 does not verify a client's privileges for a display_get_requesters operation, which allows remote attackers to bypa… Patch early 5.0 medium 2.8% 2006-10-20
CVE-2007-4330 EXP PHP remote file inclusion vulnerability in shoutbox.php in Shoutbox 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the root pa… Patch early 6.8 medium 2.8% 2007-08-14
CVE-2017-9516 EXP Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file. Patch early 5.4 medium 2.8% 2017-06-08
CVE-2012-0031 EXP scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possi… Patch early 4.6 medium 2.8% 2012-01-18
CVE-2001-0163 EXP Cisco AP340 base station produces predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections. Patch early 4.6 medium 2.8% 2001-01-01
CVE-2007-5173 EXP PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote attackers to execute arbitrary… Patch early 6.8 medium 2.8% 2007-10-03
CVE-2006-2947 EXP Dmx Forum 2.1a allows remote attackers to obtain username and password information via a direct request to pops/edit.php with a modified membre parame… Patch early 5.0 medium 2.8% 2006-06-12
CVE-2007-6397 EXP Multiple directory traversal vulnerabilities in index.php in Flat PHP Board 1.2 and earlier allow remote attackers to (1) create arbitrary files via a… Patch early 5.0 medium 2.8% 2007-12-17
CVE-2009-4088 EXP Multiple directory traversal vulnerabilities in telepark.wiki 2.4.23 and earlier allow remote attackers to read arbitrary files via directory traversa… Patch early 6.8 medium 2.8% 2009-11-29
CVE-2009-3561 EXP Directory traversal vulnerability in Xerver HTTP Server 4.32 allows remote attackers to read arbitrary files via a full pathname with a drive letter i… Patch early 5.0 medium 2.8% 2009-10-05
CVE-2007-0311 EXP Texas Imperial Software WFTPD and WFTPD Pro Server 3.25 and earlier allow remote attackers to cause a denial of service (application crash) via a long… Patch early 5.0 medium 2.8% 2007-01-18
CVE-2006-6045 EXP Multiple PHP remote file inclusion vulnerabilities in Comdev One Admin Pro 4.1 allow remote attackers to execute arbitrary PHP code via a URL in the p… Patch early 6.8 medium 2.8% 2006-11-22
CVE-2007-0135 EXP PHP remote file inclusion vulnerability in inc/init.inc.php in Aratix 0.2.2 beta 11 and earlier, when register_globals is enabled, allows remote attac… Patch early 6.8 medium 2.8% 2007-01-09
CVE-2015-4039 EXP Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitra… Patch early 5.4 medium 2.8% 2020-01-06
CVE-2004-0033 EXP admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command. Patch early 5.0 medium 2.8% 2004-01-20
CVE-2004-1830 EXP error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (… Patch early 5.0 medium 2.8% 2004-03-18
CVE-2013-7382 EXP VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for the (1) VDAD and (2) VDCL users… Patch early 5.0 medium 2.8% 2014-05-17
← previous page 189 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt