peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,556 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-2566 EXP The SaveBarCode function in the Taltech Tal Bar Code ActiveX control allows remote attackers to cause a denial of service (disk consumption) by upload… Patch early 5.0 medium 2.7% 2007-05-09
CVE-2009-4192 EXP Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary files via a .… Patch early 5.0 medium 2.7% 2009-12-03
CVE-2010-1309 EXP Directory traversal vulnerability in Irmin CMS (formerly Pepsi CMS) 0.6 BETA2 allows remote attackers to read arbitrary files via a .. (dot dot) in th… Patch early 5.0 medium 2.7% 2010-04-08
CVE-2001-1075 EXP poprelayd script before 2.0 in Cobalt RaQ3 servers allows remote attackers to bypass authentication for relaying by causing a "POP login by user" stri… Patch early 5.0 medium 2.7% 2001-07-04
CVE-2019-14748 EXP An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries.… Patch early 5.4 medium 2.7% 2019-08-07
CVE-2014-8652 EXP Elipse E3 3.x and earlier allows remote attackers to cause a denial of service (application crash and plant outage) via a rapid series of HTTP request… Patch early 5.0 medium 2.7% 2014-11-10
CVE-2008-5431 EXP Teamtek Universal FTP Server 1.0.44 allows remote attackers to cause a denial of service via (1) a certain CWD command, (2) a long LIST command, or (3… Patch early 5.0 medium 2.7% 2008-12-11
CVE-2008-6674 EXP mailPage.asp in QuickerSite 1.8.5 allows remote attackers to flood e-mail accounts with messages via a large number of requests with a modified sEmail… Patch early 5.0 medium 2.7% 2009-04-08
CVE-2005-2769 EXP Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 2.7% 2005-09-02
CVE-2015-2701 EXP Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that chang… Patch early 6.8 medium 2.7% 2015-03-25
CVE-2012-2275 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in TestLink 1.9.3 and earlier allow remote attackers to hijack the authentication of users… Patch early 6.8 medium 2.7% 2012-09-15
CVE-2005-4485 EXP Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 2.7% 2005-12-22
CVE-2003-0736 EXP Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the… Patch early 6.8 medium 2.7% 2003-10-20
CVE-2008-6870 EXP Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) co… Patch early 5.0 medium 2.7% 2009-07-23
CVE-2007-4726 EXP Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. Patch early 5.0 medium 2.7% 2007-09-05
CVE-2005-2327 EXP Cross-site scripting (XSS) vulnerability in e107 0.617 and earlier allows remote attackers to inject arbitrary web script or HTML via nested [url] BBC… Patch early 4.3 medium 2.7% 2005-07-20
CVE-2011-1838 EXP Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to inject arbitrary web script or… Patch early 4.3 medium 2.7% 2011-05-20
CVE-2009-3151 EXP Directory traversal vulnerability in actions/downloadFile.php in Ultrize TimeSheet 1.2.2 allows remote attackers to read arbitrary files via a .. (dot… Patch early 5.0 medium 2.7% 2009-09-10
CVE-2007-4895 EXP Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the f parameter. Patch early 5.0 medium 2.7% 2007-09-14
CVE-2009-1519 EXP Directory traversal vulnerability in index.php in Pecio CMS 1.1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the language p… Patch early 5.0 medium 2.7% 2009-05-04
CVE-2006-0731 EXP WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolu… Patch early 4.0 medium 2.7% 2006-02-16
CVE-2007-5739 EXP Directory traversal vulnerability in component/flashupload/download.jsp in the FlashUpload component in Korean GHBoard allows remote attackers to read… Patch early 5.0 medium 2.7% 2007-10-30
CVE-2008-0489 EXP Directory traversal vulnerability in install.php in Clansphere 2007.4.4 allows remote attackers to include and execute arbitrary local files via a ..… Patch early 5.0 medium 2.7% 2008-01-30
CVE-2008-0559 EXP Multiple directory traversal vulnerabilities in Nilson's Blogger 0.11 allow remote attackers to include and execute arbitrary local files via a .. (do… Patch early 5.0 medium 2.7% 2008-02-04
CVE-2009-4816 EXP Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files via a .. (do… Patch early 5.0 medium 2.7% 2010-04-27
CVE-2010-4858 EXP Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the… Patch early 5.0 medium 2.7% 2011-10-05
CVE-2006-2747 EXP Directory traversal vulnerability in index.php in PhpMyDesktop|arcade 1.0 FINAL allows remote attackers to read arbitrary files or execute PHP code vi… Patch early 5.1 medium 2.7% 2006-06-01
CVE-2008-6586 EXP Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attackers to (1) hijack the authenti… Patch early 6.8 medium 2.7% 2009-04-03
CVE-2009-1750 EXP Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by uploading a file with an executab… Patch early 6.0 medium 2.7% 2009-05-22
CVE-2004-2287 EXP Directory traversal vulnerability in explorer.php in DSM Light Web File Browser 2.0 allows remote attackers to read arbitrary files via .. (dot dot) i… Patch early 5.0 medium 2.7% 2004-12-31
← previous page 193 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt