peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,354 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2000-0671 EXP Roxen web server earlier than 2.0.69 allows allows remote attackers to bypass access restrictions, list directory contents, and read source code by in… Patch early 5.0 medium 8% 2000-07-21
CVE-2012-0277 EXP Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitra… Patch early 6.8 medium 8% 2012-07-17
CVE-2008-5856 EXP Directory traversal vulnerability in scripts/export.php in ClaSS before 0.8.61 allows remote attackers to read arbitrary files via directory traversal… Patch early 5.0 medium 8% 2009-01-06
CVE-2017-1000367 EXP Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting i… Patch early 6.4 medium 8% 2017-06-05
CVE-2015-6972 EXP Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 8% 2015-09-16
CVE-2017-5798 EXP A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (f… Patch early 6.1 medium 8% 2018-02-15
CVE-2006-6047 EXP Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to include and execute arbitrary… Patch early 5.8 medium 8% 2006-11-22
CVE-2002-0741 EXP psyBNC 2.3 allows remote attackers to cause a denial of service (CPU consumption and resource exhaustion) by sending a PASS command with a long passwo… Patch early 5.0 medium 8% 2002-08-12
CVE-2013-5123 EXP The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perfor… Patch early 5.9 medium 8% 2019-11-05
CVE-2004-0580 EXP DHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly clear previously used buffer con… Patch early 5.0 medium 8% 2004-08-06
CVE-2008-0399 EXP Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arb… Patch early 6.8 medium 8% 2008-01-23
CVE-2000-0652 EXP IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which co… Patch early 5.0 medium 8% 2000-07-24
CVE-2004-2117 EXP Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via malformed HTTP requests such as (1) a GET request without the HTTP ve… Patch early 5.0 medium 8% 2004-01-24
CVE-2016-9813 EXP The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference… Patch early 5.5 medium 8% 2017-01-13
CVE-2012-0789 EXP Memory leak in the timezone functionality in PHP before 5.3.9 allows remote attackers to cause a denial of service (memory consumption) by triggering… Patch early 5.0 medium 8% 2012-02-14
CVE-2007-1060 EXP Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl are enabled,… Patch early 6.8 medium 8% 2007-02-22
CVE-2000-0705 EXP ntop running in web mode allows remote attackers to read arbitrary files via a .. (dot dot) attack. Patch early 5.0 medium 8% 2000-10-20
CVE-2000-1177 EXP bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows remote attackers to determine… Patch early 5.0 medium 8% 2001-01-09
CVE-2004-0293 EXP Directory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP request to (1) g… Patch early 5.0 medium 8% 2004-11-23
CVE-2004-0327 EXP Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequen… Patch early 5.0 medium 8% 2004-11-23
CVE-2015-2125 EXP Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote authenticated users to bypass intended access restricti… Patch early 4.0 medium 7.9% 2015-06-07
CVE-2004-2060 EXP ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request… Patch early 5.0 medium 7.9% 2004-12-31
CVE-2007-3505 EXP Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot… Patch early 6.4 medium 7.9% 2007-07-02
CVE-2001-0037 EXP Directory traversal vulnerability in HomeSeer before 1.4.29 allows remote attackers to read arbitrary files via a URL containing .. (dot dot) specifie… Patch early 5.0 medium 7.9% 2001-02-16
CVE-2001-0805 EXP Directory traversal vulnerability in ttawebtop.cgi in Tarantella Enterprise 3.00 and 3.01 allows remote attackers to read arbitrary files via a .. (do… Patch early 5.0 medium 7.9% 2001-12-06
CVE-2008-3851 EXP Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute arbitrary local files via a .… Patch early 5.0 medium 7.9% 2008-08-27
CVE-1999-1005 EXP Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter… Patch early 5.0 medium 7.9% 1999-12-19
CVE-2006-2156 EXP Directory traversal vulnerability in help/index.php in X7 Chat 2.0 and earlier allows remote attackers to include arbitrary files via .. (dot dot) seq… Patch early 6.4 medium 7.9% 2006-05-03
CVE-2009-1415 EXP lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows remote attackers to cause a denia… Patch early 4.3 medium 7.9% 2009-04-30
CVE-2006-2142 EXP PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and earlier allows remote attackers to execute arbitrary PHP code… Patch early 6.4 medium 7.9% 2006-05-02
← previous page 70 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt