peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,734 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-0497 EXP Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\ (dot dot back… Patch early 5.0 medium 8.1% 2009-02-10
CVE-2006-1470 EXP OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an… Patch early 5.0 medium 8.1% 2006-06-27
CVE-2018-4241 EXP An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchO… Patch early 7.8 high 8.1% 2018-06-08
CVE-2012-0389 EXP Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in MailEnable Professional, Enterprise, and Premium 4.26 and earlier, 5.x before 5.… Patch early 4.3 medium 8.1% 2012-01-24
CVE-2024-50477 EXP Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentica… Patch early 9.8 critical 8.1% 2024-10-28
CVE-1999-1533 EXP Eicon Technology Diva LAN ISDN modem allows a remote attacker to cause a denial of service (hang) via a long password argument to the login.htm file i… Patch early 7.5 high 8.1% 1999-11-07
CVE-2019-9623 EXP Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php. Patch early 9.8 critical 8.1% 2019-03-07
CVE-2014-7288 EXP Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell c… Patch early 9.0 high 8.1% 2015-02-01
CVE-2004-1937 EXP Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbitrary files via .. sequences in… Patch early 5.0 medium 8.1% 2004-12-31
CVE-2004-2640 EXP Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequence… Patch early 5.0 medium 8.1% 2004-12-31
CVE-2015-6787 EXP Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service or possibly have other impact v… Patch early 10.0 high 8.1% 2015-12-06
CVE-1999-0950 EXP Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories. Patch early 10.0 high 8.1% 1999-10-28
CVE-2017-3132 EXP A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the… Patch early 6.1 medium 8.1% 2017-09-12
CVE-2009-4202 EXP Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include a… Patch early 7.5 high 8.1% 2009-12-04
CVE-2014-9304 EXP Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrativ… Patch early 7.5 high 8.1% 2014-12-07
CVE-2009-4050 EXP Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 allows remote attackers to read arbitrary files via directory traversal sequen… Patch early 5.0 medium 8.1% 2009-11-23
CVE-2002-2084 EXP Directory traversal vulnerability in index.php of Portix 0.4.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) l and (2… Patch early 5.0 medium 8.1% 2002-12-31
CVE-2005-4208 EXP Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id… Patch early 5.0 medium 8.1% 2005-12-13
CVE-2019-7671 EXP Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may a… Patch early 9.0 critical 8.1% 2019-06-05
CVE-2002-1014 EXP Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary code via an… Patch early 7.5 high 8.1% 2002-10-04
CVE-2008-0625 EXP Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attackers to execute arbitrary code vi… Patch early 4.3 medium 8.1% 2008-02-06
CVE-2008-3318 EXP admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrar… Patch early 7.5 high 8.1% 2008-07-25
CVE-2008-1119 EXP Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .… Patch early 5.0 medium 8.1% 2008-03-03
CVE-2001-1408 EXP Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 5.0 medium 8.1% 2001-07-05
CVE-2003-0277 EXP Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot… Patch early 5.0 medium 8.1% 2003-06-16
CVE-2004-1951 EXP xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) aud… Patch early 5.0 medium 8.1% 2004-12-31
CVE-2004-2184 EXP Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write arbitrary files via "../" or "..… Patch early 6.4 medium 8.1% 2004-12-31
CVE-2004-1699 EXP SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter… Patch early 5.0 medium 8.1% 2004-09-21
CVE-2026-1830 EXP The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insuffici… Patch early 9.8 critical 8.1% 2026-04-09
CVE-2004-0269 EXP SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive inf… Patch early 6.4 medium 8.1% 2004-11-23
← previous page 253 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt