peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,415 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-0513 EXP Directory traversal vulnerability in pkmslogout in Tivoli Web Server Plug-in 5.1.0.10 in Tivoli Access Manager (TAM) 5.1 allows remote attackers to re… Patch early 5.0 medium 9.5% 2006-02-06
CVE-2002-2015 EXP PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the ca… Patch early 7.5 high 9.5% 2002-12-31
CVE-2007-4504 EXP Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allows remote attackers to read ar… Patch early 5.0 medium 9.5% 2007-08-23
CVE-2018-18924 EXP The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" because reje… Patch early 8.8 high 9.5% 2018-11-04
CVE-2010-3847 EXP elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGI… Patch early 6.9 medium 9.5% 2011-01-07
CVE-2000-0639 EXP The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbit… Patch early 7.5 high 9.5% 2000-06-11
CVE-2014-9181 EXP Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in… Patch early 5.0 medium 9.5% 2014-12-02
CVE-2009-2109 EXP Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (… Patch early 5.0 medium 9.5% 2009-06-18
CVE-2005-4557 EXP dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attacker… Patch early 5.0 medium 9.5% 2005-12-28
CVE-2020-5811 EXP An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary f… Patch early 6.5 medium 9.5% 2020-12-30
CVE-2015-2862 EXP Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1… Patch early 4.0 medium 9.5% 2015-07-20
CVE-2005-1532 EXP Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, whi… Patch early 7.5 high 9.5% 2005-05-12
CVE-2010-3676 EXP storage/innobase/dict/dict0crea.c in mysqld in Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (assertio… Patch early 4.0 medium 9.5% 2011-01-11
CVE-2010-1474 EXP Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote attackers to read arbitrary files… Patch early 6.8 medium 9.5% 2010-04-19
CVE-2010-1475 EXP Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows remote attackers to read arbitra… Patch early 6.8 medium 9.5% 2010-04-19
CVE-2010-1722 EXP Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to read arbitrary files and poss… Patch early 6.8 medium 9.5% 2010-05-04
CVE-2005-3934 EXP Buffer overflow in Symantec pcAnywhere 11.0.1, 11.5.1, and all other 32-bit versions allows remote attackers to cause a denial of service (application… Patch early 7.8 high 9.5% 2005-12-01
CVE-2006-3879 EXP Integer overflow in the loadChunk function in loaders/load_gt2.c in libmikmod in Mikmod Sound System 3.2.2 allows remote attackers to cause a denial o… Patch early 5.0 medium 9.5% 2006-07-27
CVE-2006-3192 EXP PHP remote file inclusion vulnerability in Ad Manager Pro 2.6 allows remote attackers to execute arbitrary PHP code via a URL in the (1) ipath paramet… Patch early 7.5 high 9.5% 2006-06-23
CVE-2007-2456 EXP Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root pa… Patch early 7.5 high 9.5% 2007-05-02
CVE-2018-11523 EXP upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files. Patch early 9.8 critical 9.5% 2018-05-29
CVE-2015-7259 EXP ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid username and password pairs, w… Patch early 8.8 high 9.5% 2017-08-24
CVE-2007-1415 EXP Multiple PHP remote file inclusion vulnerabilities in PMB Services 3.0.13 and earlier allow remote attackers to execute arbitrary PHP code via a URL i… Patch early 7.5 high 9.5% 2007-03-12
CVE-2010-1718 EXP Directory traversal vulnerability in archeryscores.php in the Archery Scores (com_archeryscores) component 1.0.6 for Joomla! allows remote attackers t… Patch early 6.8 medium 9.5% 2010-05-04
CVE-2002-1178 EXP Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (… Patch early 5.0 medium 9.5% 2002-10-11
CVE-2008-3332 EXP Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via the… Patch early 6.5 medium 9.5% 2008-07-27
CVE-2000-0883 EXP The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allo… Patch early 5.0 medium 9.5% 2000-11-14
CVE-2012-6151 EXP Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT requests, allows remote attackers to cause a denial of s… Patch early 4.3 medium 9.5% 2013-12-13
CVE-1999-0926 EXP Apache allows remote attackers to conduct a denial of service via a large number of MIME headers. Patch early 10.0 high 9.4% 1999-09-03
CVE-2002-0068 EXP Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an ftp:// URL… Patch early 7.5 high 9.4% 2002-03-08
← previous page 225 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt