peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,899 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

12,664 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-2784 EXP Multiple directory traversal vulnerabilities in dit.cms 1.3, when register_globals is enabled, allow remote attackers to include and execute arbitrary… Patch early 9.3 high 3.7% 2009-08-17
CVE-2006-2100 EXP Directory traversal vulnerability in Magic ISO 5.0 Build 0166 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an… Patch early 7.8 high 3.7% 2006-04-29
CVE-2006-2102 EXP Directory traversal vulnerability in PowerISO 2.9 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image. Patch early 7.8 high 3.7% 2006-04-29
CVE-2007-1303 EXP Directory traversal vulnerability in rb.cgi in RRDBrowse 1.6 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the fil… Patch early 7.8 high 3.7% 2007-03-07
CVE-2006-5092 EXP PHP remote file inclusion vulnerability in navigation/menu.php in A-Blog 2 allows remote attackers to execute arbitrary PHP code via a URL in the navi… Patch early 7.5 high 3.7% 2006-09-29
CVE-2006-7132 EXP Directory traversal vulnerability in pmd-config.php in PHPMyDesk 1.0beta allows remote attackers to include arbitrary local files via the pmdlang para… Patch early 10.0 high 3.7% 2007-03-06
CVE-2007-1080 EXP Multiple heap-based buffer overflows in TurboFTP 5.30 Build 572 allow remote servers to cause a denial of service via (1) long filename in a response… Patch early 7.8 high 3.7% 2007-02-22
CVE-2007-4740 EXP The HPRevolutionRegistryManager ActiveX control in Hp.Revolution.RegistryManager.dll 1 in Telecom Italy Alice Messenger allows remote attackers to cre… Patch early 9.3 high 3.7% 2007-09-06
CVE-2007-2642 EXP Directory traversal vulnerability in galeria.php in R2K Gallery 1.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang2 pa… Patch early 7.8 high 3.7% 2007-05-13
CVE-2017-5123 EXP Insufficient data validation in waitid allowed an user to escape sandboxes on Linux. Patch early 8.8 high 3.7% 2021-11-02
CVE-2017-8841 EXP Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350… Patch early 8.1 high 3.7% 2017-06-05
CVE-2009-4147 EXP The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear the (1) LD_LIBMAP, (2) LD_LIBRA… Patch early 7.2 high 3.7% 2009-12-02
CVE-2018-4083 EXP An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Touch Bar Support" component. It allows a… Patch early 7.8 high 3.7% 2018-04-03
CVE-2000-0641 EXP Savant web server allows remote attackers to execute arbitrary commands via a long GET request. Patch early 7.5 high 3.7% 2000-07-08
CVE-2017-6896 EXP Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to admin privi… Patch early 8.8 high 3.7% 2017-03-14
CVE-2007-2430 EXP shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by placing file contents and dir… Patch early 7.8 high 3.7% 2007-05-02
CVE-2019-7303 EXP A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64… Patch early 7.5 high 3.7% 2019-04-23
CVE-2008-4243 EXP Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote… Patch early 7.8 high 3.7% 2008-09-25
CVE-2008-7010 EXP Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a direct request to admin/regis… Patch early 10.0 high 3.7% 2009-08-19
CVE-2007-1100 EXP Directory traversal vulnerability in download.php in Ahmet Sacan Pickle before 20070301 allows remote attackers to read arbitrary files via a .. (dot… Patch early 7.8 high 3.7% 2007-02-26
CVE-2006-0418 EXP Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a crafted username. Patch early 7.5 high 3.7% 2006-01-25
CVE-2007-2473 EXP SQL injection vulnerability in stylesheet.php in CMS Made Simple 1.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the t… Patch early 7.5 high 3.7% 2007-05-02
CVE-2000-0306 EXP Buffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message. Patch early 10.0 high 3.7% 2001-03-12
CVE-2019-17624 EXP "" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sending ct.c_char 1000 times, an att… Patch early 7.8 high 3.7% 2019-10-16
CVE-2006-4036 EXP PHP remote file inclusion vulnerability in includes/usercp_register.php in ZoneMetrics ZoneX Publishers Gold Edition 1.0.3 and earlier allows remote a… Patch early 7.5 high 3.7% 2006-08-09
CVE-2006-4853 EXP SQL injection vulnerability in kategorix.asp in Haberx 1.02 through 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter… Patch early 7.5 high 3.7% 2006-09-19
CVE-2005-4039 EXP Directory traversal vulnerability in arhiva.php in Web4Future Portal Solutions News Portal allows remote attackers to read arbitrary files via the dir… Patch early 7.8 high 3.7% 2005-12-06
CVE-2008-3879 EXP The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to… Patch early 9.3 high 3.7% 2008-09-02
CVE-2006-6094 EXP Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) catID parameter to a… Patch early 7.5 high 3.7% 2006-11-24
CVE-2002-1482 EXP SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrat… Patch early 10.0 high 3.7% 2003-04-22
← previous page 216 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt