peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,157 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-1375 EXP Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sensitive memory via a large value… Patch early 5.0 medium 8.2% 2007-03-10
CVE-2006-0922 EXP CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results… Patch early 5.0 medium 8.1% 2006-02-28
CVE-2009-3704 EXP ZoIPer 2.22, and possibly other versions before 2.24 Library 5324, allows remote attackers to cause a denial of service (crash) via a SIP INVITE reque… Patch early 5.0 medium 8.1% 2009-10-16
CVE-2001-0705 EXP Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via… Patch early 5.0 medium 8.1% 2001-09-20
CVE-2004-1620 EXP CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML c… Patch early 5.0 medium 8.1% 2004-10-21
CVE-2002-0112 EXP Etype Eserv 2.97 allows remote attackers to view password protected files via /./ in the URL. Patch early 5.0 medium 8.1% 2002-03-25
CVE-2007-0197 EXP Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a lo… Patch early 6.8 medium 8.1% 2007-01-11
CVE-2000-0921 EXP Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot do… Patch early 5.0 medium 8.1% 2000-12-19
CVE-2001-0295 EXP Directory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly read files via a "dir *./../.." c… Patch early 5.0 medium 8.1% 2001-05-03
CVE-2001-0924 EXP Directory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary files via a .. (dot dot) in t… Patch early 5.0 medium 8.1% 2001-11-22
CVE-2006-1470 EXP OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an… Patch early 5.0 medium 8.1% 2006-06-27
CVE-2009-0497 EXP Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\ (dot dot back… Patch early 5.0 medium 8.1% 2009-02-10
CVE-2012-0389 EXP Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in MailEnable Professional, Enterprise, and Premium 4.26 and earlier, 5.x before 5.… Patch early 4.3 medium 8.1% 2012-01-24
CVE-2004-1937 EXP Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbitrary files via .. sequences in… Patch early 5.0 medium 8.1% 2004-12-31
CVE-2004-2640 EXP Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequence… Patch early 5.0 medium 8.1% 2004-12-31
CVE-2017-3132 EXP A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the… Patch early 6.1 medium 8.1% 2017-09-12
CVE-2009-4050 EXP Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 allows remote attackers to read arbitrary files via directory traversal sequen… Patch early 5.0 medium 8.1% 2009-11-23
CVE-2002-2084 EXP Directory traversal vulnerability in index.php of Portix 0.4.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) l and (2… Patch early 5.0 medium 8.1% 2002-12-31
CVE-2005-4208 EXP Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id… Patch early 5.0 medium 8.1% 2005-12-13
CVE-2008-0625 EXP Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attackers to execute arbitrary code vi… Patch early 4.3 medium 8.1% 2008-02-06
CVE-2001-1408 EXP Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 5.0 medium 8.1% 2001-07-05
CVE-2008-1119 EXP Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .… Patch early 5.0 medium 8.1% 2008-03-03
CVE-2003-0277 EXP Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot… Patch early 5.0 medium 8.1% 2003-06-16
CVE-2004-1951 EXP xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) aud… Patch early 5.0 medium 8.1% 2004-12-31
CVE-2004-2184 EXP Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write arbitrary files via "../" or "..… Patch early 6.4 medium 8.1% 2004-12-31
CVE-2004-1699 EXP SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter… Patch early 5.0 medium 8.1% 2004-09-21
CVE-2004-0269 EXP SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive inf… Patch early 6.4 medium 8.1% 2004-11-23
CVE-2016-9018 EXP Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlaye… Patch early 5.5 medium 8.1% 2016-10-28
CVE-2006-4955 EXP Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via… Patch early 5.0 medium 8.1% 2006-09-23
CVE-2007-3006 EXP Buffer overflow in Acoustica MP3 CD Burner 4.32 allows user-assisted remote attackers to execute arbitrary code via a .asx playlist file with a REF el… Patch early 6.8 medium 8.1% 2007-06-04
← previous page 68 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt