peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,696 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-9144 EXP Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metacharacters in the ping field (s… Patch early 7.5 high 8.6% 2014-12-05
CVE-2010-1685 EXP Stack-based buffer overflow in CursorArts ZipWrangler 1.20 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing a… Patch early 9.3 high 8.6% 2010-05-04
CVE-2007-6584 EXP Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot)… Patch early 6.4 medium 8.6% 2007-12-28
CVE-2008-0379 EXP Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to c… Patch early 9.3 high 8.6% 2008-01-22
CVE-2010-3306 EXP Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%… Patch early 5.0 medium 8.6% 2010-09-24
CVE-2008-6833 EXP Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and execute arbitrary local files… Patch early 10.0 high 8.6% 2009-06-22
CVE-2012-0406 EXP The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a deni… Patch early 7.8 high 8.6% 2012-04-20
CVE-2000-0906 EXP Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to read arbitrary files via a .. (d… Patch early 5.0 medium 8.6% 2000-12-19
CVE-2002-0955 EXP Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execute arbitra… Patch early 7.5 high 8.6% 2002-10-04
CVE-2006-0888 EXP index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unspecified denial of service by r… Patch early 2.6 low 8.5% 2006-02-25
CVE-2010-1132 EXP The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute… Patch early 9.3 high 8.5% 2010-03-27
CVE-2007-2536 EXP PicoZip allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous fil… Patch early 7.8 high 8.5% 2007-05-09
CVE-2015-1482 EXP Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connecti… Patch early 5.0 medium 8.5% 2015-02-04
CVE-2014-3437 EXP The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requ… Patch early 7.5 high 8.5% 2014-11-07
CVE-2002-2314 EXP Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which cause… Patch early 5.0 medium 8.5% 2002-12-31
CVE-2006-3970 EXP PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows remote attackers to execute arb… Patch early 7.5 high 8.5% 2006-08-01
CVE-2005-2455 EXP Greasemonkey before 0.3.5 allows remote web servers to (1) read arbitrary files via a GET request to a file:// URL in the GM_xmlhttpRequest API functi… Patch early 5.0 medium 8.5% 2005-08-04
CVE-2012-5329 EXP Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application crash) via a long string in an A… Patch early 4.0 medium 8.5% 2012-10-08
CVE-2001-0495 EXP Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack. Patch early 5.0 medium 8.5% 2001-06-27
CVE-2008-4409 EXP libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a de… Patch early 5.0 medium 8.5% 2008-10-03
CVE-2010-4617 EXP Directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers to read arbitrary files via dir… Patch early 6.8 medium 8.5% 2010-12-29
CVE-2000-0187 EXP EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metachar… Patch early 7.5 high 8.5% 2000-02-27
CVE-2008-0396 EXP Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Ente… Patch early 7.8 high 8.5% 2008-01-23
CVE-2017-2800 EXP A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate vali… Patch early 9.8 critical 8.5% 2017-05-24
CVE-2009-4501 EXP The zbx_get_next_field function in libs/zbxcommon/str.c in Zabbix Server before 1.6.8 allows remote attackers to cause a denial of service (crash) via… Patch early 5.0 medium 8.5% 2009-12-31
CVE-2008-1262 EXP The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote… Patch early 10.0 high 8.5% 2008-03-10
CVE-2007-2364 EXP Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the ro… Patch early 7.5 high 8.5% 2007-04-30
CVE-2014-0242 EXP mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type h… Patch early 7.5 high 8.5% 2019-12-09
CVE-2006-1831 EXP Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows remote attackers to execute a… Patch early 7.5 high 8.5% 2006-04-19
CVE-2007-0684 EXP PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute arbitrary PHP code via a URL i… Patch early 7.5 high 8.5% 2007-02-03
← previous page 243 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt