peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,734 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-1469 EXP Directory traversal vulnerability in the Ternaria Informatica JProject Manager (com_jprojectmanager) component 1.0 for Joomla! allows remote attackers… Patch early 6.8 medium 8.2% 2010-04-19
CVE-2010-1473 EXP Directory traversal vulnerability in the Advertising (com_advertising) component 0.25 for Joomla! allows remote attackers to read arbitrary files and… Patch early 6.8 medium 8.2% 2010-04-19
CVE-2010-1478 EXP Directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allows remote attackers to read arb… Patch early 6.8 medium 8.2% 2010-04-19
CVE-2009-0348 EXP The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently to a failed login attempt depe… Patch early 5.0 medium 8.2% 2009-01-29
CVE-2001-0766 EXP Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some character… Patch early 9.8 critical 8.2% 2001-10-18
CVE-2007-2570 EXP PHP remote file inclusion vulnerability in handlers/page/show.php in Wikivi5 allows remote attackers to execute arbitrary PHP code via a URL in the so… Patch early 7.5 high 8.2% 2007-05-09
CVE-2008-4748 EXP Format string vulnerability in the URI handler in KVirc 3.4.0, when set as the default application for processing IRC URIs, allows remote attackers to… Patch early 7.6 high 8.2% 2008-10-27
CVE-2007-3621 EXP Multiple CRLF injection vulnerabilities in callboth.php in AsteriDex 3.0 and earlier allow remote attackers to inject arbitrary shell commands via the… Patch early 7.5 high 8.2% 2007-07-09
CVE-2017-5881 EXP GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafte… Patch early 7.8 high 8.2% 2017-02-21
CVE-2019-18873 EXP FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user accoun… Patch early 9.0 critical 8.2% 2019-11-12
CVE-2017-9614 EXP The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and ap… Patch early 8.8 high 8.2% 2017-07-27
CVE-2006-0922 EXP CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results… Patch early 5.0 medium 8.1% 2006-02-28
CVE-2019-11369 EXP An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensiti… Patch early 8.8 high 8.1% 2019-06-03
CVE-2006-4849 EXP PHP remote file inclusion vulnerability in header.php in MobilePublisherPHP 1.5 RC2 and earlier allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 8.1% 2006-09-19
CVE-2003-0118 EXP SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attacker… Patch early 7.5 high 8.1% 2003-05-12
CVE-2009-3704 EXP ZoIPer 2.22, and possibly other versions before 2.24 Library 5324, allows remote attackers to cause a denial of service (crash) via a SIP INVITE reque… Patch early 5.0 medium 8.1% 2009-10-16
CVE-2007-3956 EXP TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which allows remote attackers to cause… Patch early 7.8 high 8.1% 2007-07-24
CVE-2018-11415 EXP SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indica… Patch early 6.1 medium 8.1% 2018-05-24
CVE-2001-0705 EXP Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via… Patch early 5.0 medium 8.1% 2001-09-20
CVE-2004-1620 EXP CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML c… Patch early 5.0 medium 8.1% 2004-10-21
CVE-2002-0112 EXP Etype Eserv 2.97 allows remote attackers to view password protected files via /./ in the URL. Patch early 5.0 medium 8.1% 2002-03-25
CVE-2006-4204 EXP Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execute arbitrary PHP code via a UR… Patch early 7.5 high 8.1% 2006-08-17
CVE-2006-4477 EXP Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute arbitrary PHP code via an empt… Patch early 7.5 high 8.1% 2006-08-31
CVE-2014-0983 EXP Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py in Oracle Vi… Patch early 6.9 medium 8.1% 2014-03-31
CVE-2013-4984 EXP The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain… Patch early 7.2 high 8.1% 2013-09-10
CVE-2007-1043 EXP Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config… Patch early 7.5 high 8.1% 2007-02-21
CVE-2000-0921 EXP Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot do… Patch early 5.0 medium 8.1% 2000-12-19
CVE-2001-0295 EXP Directory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly read files via a "dir *./../.." c… Patch early 5.0 medium 8.1% 2001-05-03
CVE-2001-0924 EXP Directory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary files via a .. (dot dot) in t… Patch early 5.0 medium 8.1% 2001-11-22
CVE-2006-6853 EXP Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary code via a long string in a cra… Patch early 10.0 high 8.1% 2006-12-31
← previous page 252 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt