peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,879 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2000-0350 EXP A debugging feature in NetworkICE ICEcap 2.0.23 and earlier is enabled, which allows a remote attacker to bypass the weak authentication and post unen… Patch early 5.0 medium 7.9% 2000-05-17
CVE-2003-1191 EXP chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML in the Name field, which preven… Patch early 5.0 medium 7.9% 2003-10-29
CVE-2001-0307 EXP Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP req… Patch early 7.5 high 7.9% 2001-05-03
CVE-2008-3447 EXP The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop) via a malformed ZIP archive, p… Patch early 5.0 medium 7.9% 2008-08-04
CVE-2009-4679 EXP Directory traversal vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.5 for Joomla! allows remote attackers to include a… Patch early 7.5 high 7.9% 2010-03-08
CVE-2022-39290 EXP ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by mod… Patch early 8.0 high 7.9% 2022-10-07
CVE-2016-4469 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to hijack the authentication of… Patch early 8.8 high 7.9% 2016-07-28
CVE-2000-0664 EXP AnalogX SimpleServer:WWW 1.06 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack that uses the %2E URL enc… Patch early 5.0 medium 7.9% 2000-07-26
CVE-2007-3266 EXP Directory traversal vulnerability in webif.cgi in ifnet WEBIF allows remote attackers to include and execute arbitrary local files a .. (dot dot) in t… Patch early 9.0 high 7.9% 2007-06-19
CVE-2017-9747 EXP The ieee_archive_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow r… Patch early 7.8 high 7.9% 2017-06-19
CVE-2017-9748 EXP The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow re… Patch early 7.8 high 7.9% 2017-06-19
CVE-2020-27422 EXP In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link t… Patch early 9.8 critical 7.9% 2020-11-16
CVE-2014-3004 EXP The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) att… Patch early 4.3 medium 7.9% 2014-06-11
CVE-2015-1265 EXP Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a denial of service or possibly have other impact v… Patch early 7.5 high 7.9% 2015-05-20
CVE-2013-5696 EXP inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows… Patch early 6.8 medium 7.9% 2013-09-23
CVE-2006-0701 EXP readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters. Patch early 5.0 medium 7.9% 2006-02-15
CVE-2002-0330 EXP Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to execute arbitrary script and stea… Patch early 7.5 high 7.9% 2002-06-25
CVE-2005-0305 EXP CRLF injection vulnerability in users.php in Siteman 1.1.10 and earlier allows remote attackers to add arbitrary users and gain privileges via the lin… Patch early 7.5 high 7.9% 2005-05-02
CVE-2018-7653 EXP In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter. Patch early 6.1 medium 7.9% 2018-03-04
CVE-2006-2059 EXP action_public/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary PHP code via a sea… Patch early 5.0 medium 7.9% 2006-04-26
CVE-2000-0634 EXP The web administration interface for CommuniGate Pro 3.2.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. Patch early 5.0 medium 7.9% 2000-04-03
CVE-2000-0925 EXP The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, whic… Patch early 5.0 medium 7.9% 2000-12-19
CVE-2000-1181 EXP Real Networks RealServer 7 and earlier allows remote attackers to obtain portions of RealServer's memory contents, possibly including sensitive inform… Patch early 5.0 medium 7.9% 2001-01-09
CVE-2002-0107 EXP Web administration interface in CacheFlow CacheOS 4.0.13 and earlier allows remote attackers to obtain sensitive information via a series of GET reque… Patch early 5.0 medium 7.9% 2002-03-25
CVE-1999-1050 EXP Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the… Patch early 5.0 medium 7.9% 1999-11-12
CVE-2000-0924 EXP Directory traversal vulnerability in search.cgi CGI script in Armada Master Index allows remote attackers to read arbitrary files via a .. (dot dot) a… Patch early 5.0 medium 7.9% 2000-12-19
CVE-2019-11660 EXP Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability coul… Patch early 7.8 high 7.8% 2019-09-13
CVE-2006-4824 EXP PHP remote file inclusion vulnerability in lib/activeutil.php in Quicksilver Forums (QSF) 1.2.1 and earlier allows remote attackers to execute arbitra… Patch early 7.5 high 7.8% 2006-09-15
CVE-2006-4918 EXP Multiple PHP remote file inclusion vulnerabilities in Simple Discussion Board 0.1.0 allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 7.5 high 7.8% 2006-09-21
CVE-2003-0290 EXP Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is… Patch early 5.0 medium 7.8% 2003-06-16
← previous page 260 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt