peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,237 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-4332 EXP Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values… Patch early 7.5 high 7% 2010-12-22
CVE-2005-1903 EXP Buffer overflow in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to execute arbitrary code via a long CREATE comma… Patch early 2.1 low 7% 2005-06-02
CVE-2003-0765 EXP The IN_MIDI.DLL plugin 3.01 and earlier, as used in Winamp 2.91, allows remote attackers to execute arbitrary code via a MIDI file with a large "Track… Patch early 7.5 high 7% 2003-09-17
CVE-2001-0838 EXP Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -… Patch early 7.5 high 7% 2001-12-06
CVE-2007-2249 EXP include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_ids POST par… Patch early 6.5 medium 7% 2007-04-25
CVE-2006-3636 EXP Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspe… Patch early 6.8 medium 6.9% 2006-09-06
CVE-2017-17097 EXP gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated reques… Patch early 9.8 critical 6.9% 2018-01-02
CVE-2007-1041 EXP Multiple stack-based buffer overflows in S&H Computer Systems News Rover 12.1 Rev 1 allow remote attackers to execute arbitrary code via a .nzb file w… Patch early 9.3 high 6.9% 2007-02-21
CVE-2016-1838 EXP The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and… Patch early 5.5 medium 6.9% 2016-05-20
CVE-2014-1637 EXP Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which allows remote attackers to down… Patch early 5.0 medium 6.9% 2014-01-22
CVE-2013-2171 EXP The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEASE-p4 does not properly determi… Patch early 6.9 medium 6.9% 2013-07-02
CVE-2005-2813 EXP Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00"… Patch early 5.0 medium 6.9% 2005-09-07
CVE-2023-2636 EXP The AN_GradeBook WordPress plugin through 5.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL… Patch early 8.8 high 6.9% 2023-07-17
CVE-2000-0571 EXP LocalWEB HTTP server 1.2.0 allows remote attackers to cause a denial of service via a long GET request. Patch early 6.4 medium 6.9% 2000-07-05
CVE-2001-1044 EXP Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which cou… Patch early 7.5 high 6.9% 2001-01-11
CVE-2002-1427 EXP The print_html_to_file function in edit.cgi for Easy Homepage Creator 1.0 does not check user credentials, which allows remote attackers to modify hom… Patch early 7.5 high 6.9% 2003-04-11
CVE-2004-1724 EXP The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execut… Patch early 7.5 high 6.9% 2004-08-18
CVE-2005-1366 EXP Pico Server (pServ) 3.2 and earlier allows remote attackers to obtain the source code for CGI scripts via "dirname/../cgi-bin" in a URL. Patch early 7.5 high 6.9% 2005-05-16
CVE-2007-1455 EXP Multiple absolute path traversal vulnerabilities in Fantastico, as used with cPanel 10.x, allow remote authenticated users to include and execute arbi… Patch early 9.0 high 6.9% 2007-03-14
CVE-2008-4194 EXP The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of service (daemon crash) via a long… Patch early 5.0 medium 6.9% 2008-09-24
CVE-2008-6793 EXP The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute arbitrary commands via shell met… Patch early 6.8 medium 6.9% 2009-05-07
CVE-2011-3713 EXP cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error… Patch early 5.0 medium 6.9% 2011-09-23
CVE-2019-8765 EXP Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Processing maliciously crafted web… Patch early 8.8 high 6.9% 2019-12-18
CVE-2005-4799 EXP Multiple cross-site scripting (XSS) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow remote attackers to inject arbitr… Patch early 5.1 medium 6.9% 2005-12-31
CVE-2004-0242 EXP X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command. Patch early 5.0 medium 6.9% 2004-11-23
CVE-2026-25895 EXP FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote att… Patch early 9.8 critical 6.9% 2026-02-09
CVE-2004-1854 EXP Buffer overflow in the logging function in Picophone 1.63 and earlier allows remote attackers to execute arbitrary code via a large packet. Patch early 7.5 high 6.9% 2004-03-24
CVE-2004-2037 EXP Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute a… Patch early 7.5 high 6.9% 2004-03-24
CVE-2002-1828 EXP Savant Webserver 3.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request with a negative Content-Length value. Patch early 5.0 medium 6.9% 2002-12-31
CVE-2005-0788 EXP LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request. Patch early 5.0 medium 6.9% 2005-03-14
← previous page 289 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt