peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,810 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-1543 EXP Directory traversal vulnerability in viewimg.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to list arbitrary directories via a .. (do… Patch early 5.0 medium 7.1% 2004-12-31
CVE-2008-6791 EXP PumpKIN TFTP Server 2.7.2.0 allows remote attackers to cause a denial of service via a write request with a long mode field. Patch early 5.0 medium 7.1% 2009-05-04
CVE-2008-3906 EXP CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response spl… Patch early 4.3 medium 7.1% 2008-09-04
CVE-2003-1166 EXP Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .… Patch early 5.0 medium 7.1% 2003-12-31
CVE-2004-2253 EXP Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page param… Patch early 5.0 medium 7.1% 2004-12-31
CVE-2008-6811 EXP Unrestricted file upload vulnerability in image_processing.php in the e-Commerce Plugin 3.4 and earlier for Wordpress allows remote attackers to execu… Patch early 6.8 medium 7.1% 2009-05-18
CVE-2005-1204 EXP Desktop Rover 3.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a crafted packet to TCP… Patch early 5.0 medium 7.1% 2005-05-02
CVE-2006-2230 EXP Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.4 might allow attackers to cause a denial of service via format string speci… Patch early 5.0 medium 7.1% 2006-05-05
CVE-2005-2640 EXP Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication… Patch early 5.0 medium 7.1% 2005-08-23
CVE-2002-0106 EXP BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP files that contain an MS-DOS dev… Patch early 5.0 medium 7.1% 2002-03-25
CVE-2012-0292 EXP The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Alt… Patch early 5.0 medium 7.1% 2012-03-08
CVE-2020-11700 EXP An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an attacker t… Patch early 6.5 medium 7.1% 2020-09-17
CVE-2008-3950 EXP Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iPhone 1.1.4 and 2.0 and iPod to… Patch early 5.0 medium 7.1% 2008-09-16
CVE-2014-2630 EXP Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via unknown vectors. Patch early 4.4 medium 7.1% 2014-08-12
CVE-2001-0298 EXP Buffer overflow in WebReflex 1.55 HTTPd allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP… Patch early 5.0 medium 7.1% 2001-05-03
CVE-2002-1830 EXP Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via a direct request to moderator.… Patch early 5.0 medium 7.1% 2002-12-31
CVE-2005-3982 EXP CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response s… Patch early 5.0 medium 7.1% 2005-12-04
CVE-2003-1459 EXP Multiple PHP remote file inclusion vulnerabilities in ttCMS 2.2 and ttForum allow remote attackers to execute arbitrary PHP code via the (1) template… Patch early 6.8 medium 7.1% 2003-12-31
CVE-2006-2583 EXP PHP remote file inclusion vulnerability in nucleus/libs/PLUGINADMIN.php in Nucleus 3.22 and earlier allows remote attackers to execute arbitrary PHP c… Patch early 5.1 medium 7.1% 2006-05-25
CVE-2014-5521 EXP plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in… Patch early 6.5 medium 7.1% 2014-09-02
CVE-2004-1020 EXP The addslashes function in PHP 4.3.9 does not properly escape a NULL (/0) character, which may allow remote attackers to read arbitrary files in PHP a… Patch early 5.0 medium 7.1% 2005-01-10
CVE-2007-6347 EXP PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Shop Evaluation 3.3.2, and (4) Sh… Patch early 6.8 medium 7.1% 2007-12-13
CVE-2007-2401 EXP CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitra… Patch early 4.3 medium 7.1% 2007-06-25
CVE-2001-0177 EXP WebMaster ConferenceRoom 1.8.1 allows remote attackers to cause a denial of service via a buddy relationship between the IRC server and a server clone… Patch early 5.0 medium 7.1% 2001-03-26
CVE-2001-0581 EXP Spytech Spynet Chat Server 6.5 allows a remote attacker to create a denial of service (crash) via a large number of connections to port 6387. Patch early 5.0 medium 7.1% 2001-08-22
CVE-2001-0616 EXP Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to create a denial of service via a URL request which includes a MS-… Patch early 5.0 medium 7.1% 2001-08-14
CVE-2001-1156 EXP TYPSoft FTP 0.95 allows remote attackers to cause a denial of service (CPU consumption) via a "../../*" argument to (1) STOR or (2) RETR. Patch early 5.0 medium 7.1% 2001-10-08
CVE-2017-0175 EXP The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sensitive information via a speci… Patch early 4.7 medium 7% 2017-05-12
CVE-2006-5190 EXP Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script… Patch early 4.3 medium 7% 2006-10-10
CVE-2004-0361 EXP The Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a new Array obje… Patch early 5.0 medium 7% 2004-11-23
← previous page 83 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt