peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,331 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

169,662 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-0645 EXP Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) l… Patch early 6.5 medium 6.3% 2009-02-18
CVE-2009-0858 EXP The response_addname function in response.c in Daniel J. Bernstein djbdns 1.05 and earlier does not constrain offsets in the required manner, which al… Patch early 5.8 medium 6.3% 2009-03-09
CVE-2005-3550 EXP Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the i… Patch early 5.0 medium 6.3% 2005-11-16
CVE-2006-0125 EXP Unspecified vulnerability in appserv/main.php in AppServ 2.4.5 allows remote attackers to include arbitrary files via the appserv_root parameter. NOT… Patch early 5.0 medium 6.3% 2006-01-09
CVE-2020-7656 EXP jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that… Patch early 6.1 medium 6.3% 2020-05-19
CVE-2007-0148 EXP Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary c… Patch early 6.8 medium 6.3% 2007-01-09
CVE-2008-6537 EXP LightNEasy/lightneasy.php in LightNEasy No database version 1.2 allows remote attackers to obtain the hash of the administrator password via the setup… Patch early 5.0 medium 6.3% 2009-03-30
CVE-2011-0745 EXP SugarCRM before 6.1.3 does not properly handle reloads and direct requests for a warning page produced by a certain duplicate check, which allows remo… Patch early 4.0 medium 6.3% 2011-03-16
CVE-2010-0496 EXP FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch, allows remote attackers to cause a denial of service (daemon crash) v… Patch early 5.0 medium 6.3% 2010-02-03
CVE-2008-7245 EXP Opera 9.52 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "… Patch early 5.0 medium 6.3% 2009-09-18
CVE-2015-1480 EXP ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getT… Patch early 4.0 medium 6.3% 2015-02-04
CVE-2014-5115 EXP Absolute path traversal vulnerability in DirPHP 1.0 allows remote attackers to read arbitrary files via a full pathname in the phpfile parameter to in… Patch early 5.0 medium 6.3% 2014-07-29
CVE-2009-2334 EXP wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin,… Patch early 4.9 medium 6.3% 2009-07-10
CVE-2004-1267 EXP Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code… Patch early 6.5 medium 6.3% 2005-01-10
CVE-2006-5714 EXP Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary files under the web root by app… Patch early 5.0 medium 6.3% 2006-11-04
CVE-2006-5715 EXP Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrary files under the web root by… Patch early 5.0 medium 6.3% 2006-11-04
CVE-2005-3894 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow… Patch early 4.3 medium 6.3% 2005-11-29
CVE-2006-3530 EXP PHP remote file inclusion vulnerability in com_pccookbook/pccookbook.php in the PccookBook Component for Mambo and Joomla 0.3 and possibly up to 1.3.1… Patch early 6.8 medium 6.2% 2006-07-12
CVE-2006-3980 EXP PHP remote file inclusion vulnerability in administrator/components/com_mgm/help.mgm.php in Mambo Gallery Manager (MGM) 0.95r2 and earlier for Mambo 4… Patch early 6.8 medium 6.2% 2006-08-05
CVE-2007-5063 EXP Adam Scheinberg Flip 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers t… Patch early 5.0 medium 6.2% 2007-09-24
CVE-2007-6395 EXP Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obta… Patch early 5.0 medium 6.2% 2007-12-17
CVE-2009-1171 EXP The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary… Patch early 4.3 medium 6.2% 2009-03-30
CVE-1999-0771 EXP The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack… Patch early 5.0 medium 6.2% 1999-05-26
CVE-2008-0852 EXP freeSSHd 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a SSH2_MSG_NEWKEYS packet to TCP port 22, which triggers a N… Patch early 5.0 medium 6.2% 2008-02-21
CVE-2008-2398 EXP Cross-site scripting (XSS) vulnerability in index.php in AppServ Open Project 2.5.10 and earlier allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 6.2% 2008-05-21
CVE-2012-2593 EXP Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web… Patch early 6.1 medium 6.2% 2020-02-06
CVE-2006-6624 EXP The FTP Server in Sambar Server 6.4 allows remote authenticated users to cause a denial of service (application crash) via a long series of "./" seque… Patch early 4.0 medium 6.2% 2006-12-18
CVE-2004-0312 EXP Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy strings via a qu… Patch early 6.4 medium 6.2% 2004-11-23
CVE-2012-2315 EXP admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authent… Patch early 4.0 medium 6.2% 2012-09-09
CVE-2007-5642 EXP Multiple directory traversal vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to include and execute arbitrary loca… Patch early 6.8 medium 6.2% 2007-10-23
← previous page 100 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt