peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,354 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-1128 EXP The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attack… Patch early 6.4 medium 8.1% 2010-03-26
CVE-2000-0242 EXP WindMail allows remote attackers to read arbitrary files or execute commands via shell metacharacters. Patch early 5.0 medium 8.1% 2000-03-25
CVE-2008-7248 EXP Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to… Patch early 6.8 medium 8.1% 2009-12-16
CVE-2018-10077 EXP XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to read arbitrary files via crafted… Patch early 4.9 medium 8.1% 2018-04-20
CVE-2009-5029 EXP Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possib… Patch early 6.8 medium 8.1% 2013-05-02
CVE-2007-3947 EXP request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as… Patch early 5.8 medium 8.1% 2007-07-24
CVE-2005-0698 EXP PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) G_PA… Patch early 4.6 medium 8.1% 2005-03-07
CVE-2014-8493 EXP ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to Forms/access_cwmp_1. Patch early 5.0 medium 8.1% 2014-11-20
CVE-2008-5062 EXP Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read arbitrary files via directory tr… Patch early 5.0 medium 8.1% 2008-11-13
CVE-2010-0303 EXP mystring.c in hybserv in IRCD-Hybrid (aka Hybrid2 IRC Services) 1.9.2 through 1.9.4 allows remote attackers to cause a denial of service (daemon crash… Patch early 5.0 medium 8.1% 2010-02-04
CVE-2011-1425 EXP xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to crea… Patch early 5.1 medium 8.1% 2011-04-04
CVE-1999-1069 EXP Directory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the ic… Patch early 5.0 medium 8.1% 1997-11-08
CVE-2001-0189 EXP Directory traversal vulnerability in LocalWEB2000 HTTP server allows remote attackers to read arbitrary commands via a .. (dot dot) attack in an HTTP… Patch early 5.0 medium 8.1% 2001-03-26
CVE-2002-1525 EXP Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (… Patch early 5.0 medium 8.1% 2003-04-02
CVE-2003-0748 EXP Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary fil… Patch early 5.0 medium 8.1% 2003-10-20
CVE-2003-0621 EXP The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modifie… Patch early 5.0 medium 8% 2003-12-01
CVE-2007-4583 EXP Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in ACTi Network Video Recorder (… Patch early 5.0 medium 8% 2007-08-29
CVE-2002-1031 EXP KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00 (null) chara… Patch early 5.0 medium 8% 2002-10-04
CVE-2000-0919 EXP Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. Patch early 5.0 medium 8% 2000-12-19
CVE-2001-1209 EXP Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. Patch early 5.0 medium 8% 2001-12-31
CVE-2006-3532 EXP PHP file inclusion vulnerability in includes/edit_new.php in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allows remote attackers to… Patch early 5.1 medium 8% 2006-07-12
CVE-2004-2519 EXP Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specifiers in the LANGUAGE parameter… Patch early 5.0 medium 8% 2004-12-31
CVE-2006-0755 EXP Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute… Patch early 5.6 medium 8% 2006-02-18
CVE-2004-2132 EXP Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary files via a .. (dot dot) in the… Patch early 5.0 medium 8% 2004-01-29
CVE-2005-1073 EXP Directory traversal vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to read arbitrary files via the read parameter. Patch early 5.0 medium 8% 2005-05-02
CVE-2017-13262 EXP In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. This could lead to remote inform… Patch early 6.5 medium 8% 2018-04-04
CVE-2007-5198 EXP Buffer overflow in the redir function in check_http.c in Nagios Plugins before 1.4.10, when running with the -f (follow) option, allows remote web ser… Patch early 6.8 medium 8% 2007-10-04
CVE-2000-0142 EXP The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417. Patch early 5.0 medium 8% 2000-02-11
CVE-2008-1888 EXP Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 8% 2008-04-18
CVE-2006-4897 EXP CMtextS 1.0 and earlier stores users_logins/admin.txt under the web document root with insufficient access control, which allows remote attackers to o… Patch early 5.0 medium 8% 2006-09-19
← previous page 69 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt