peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,405 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

169,696 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-5673 EXP PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled, allows remote attackers to e… Patch early 6.8 medium 6.1% 2006-11-03
CVE-2019-12543 EXP An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter. Patch early 6.1 medium 6.1% 2019-06-05
CVE-2011-0405 EXP Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc is disabled, allows remote atta… Patch early 6.8 medium 6.1% 2011-01-11
CVE-2004-1564 EXP CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify ex… Patch early 5.0 medium 6.1% 2004-12-31
CVE-2000-0992 EXP Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack. Patch early 5.0 medium 6.1% 2000-12-19
CVE-2000-0056 EXP IMail IMONITOR status.cgi CGI script allows remote attackers to cause a denial of service with many calls to status.cgi. Patch early 5.0 medium 6% 2000-01-05
CVE-2004-1101 EXP mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash), leak sensitive p… Patch early 5.8 medium 6% 2005-01-10
CVE-2014-8606 EXP Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files… Patch early 4.0 medium 6% 2015-06-10
CVE-2007-6317 EXP Multiple directory traversal vulnerabilities in BarracudaDrive Web Server before 3.8 allow (1) remote attackers to read arbitrary files via certain ..… Patch early 5.5 medium 6% 2007-12-12
CVE-2002-2416 EXP Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request. Patch early 5.0 medium 6% 2002-12-31
CVE-2015-3632 EXP Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a c… Patch early 4.3 medium 6% 2015-05-01
CVE-2015-7707 EXP Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp. Patch early 6.5 medium 6% 2015-10-05
CVE-2019-12538 EXP An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field. Patch early 6.1 medium 6% 2019-06-05
CVE-2019-12541 EXP An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter. Patch early 6.1 medium 6% 2019-06-05
CVE-2019-12542 EXP An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter. Patch early 6.1 medium 6% 2019-06-05
CVE-2000-1075 EXP Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary fil… Patch early 5.0 medium 6% 2000-12-11
CVE-2008-5824 EXP Heap-based buffer overflow in msadpcm.c in libaudiofile in audiofile 0.2.6 allows context-dependent attackers to cause a denial of service (applicatio… Patch early 6.8 medium 6% 2009-01-02
CVE-2000-0254 EXP The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that… Patch early 5.0 medium 6% 2000-04-14
CVE-2001-0200 EXP HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path… Patch early 5.0 medium 6% 2001-05-03
CVE-2001-0788 EXP Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows remote attackers to obtain an absolute path for the server directory by… Patch early 5.0 medium 6% 2001-10-18
CVE-2007-4508 EXP Stack-based buffer overflow in Rebellion Asura engine, as used for the server in Rogue Trooper 1.0 and earlier and Prism 1.1.1.0 and earlier, allows r… Patch early 6.8 medium 6% 2007-08-23
CVE-2010-4777 EXP The Perl_reg_numbered_buff_fetch function in Perl 5.10.0, 5.12.0, 5.14.0, and other versions, when running with debugging enabled, allows context-depe… Patch early 4.3 medium 6% 2014-02-10
CVE-2018-19371 EXP The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system. Patch early 6.5 medium 6% 2019-01-02
CVE-2005-4600 EXP Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to read or include arbitrary file… Patch early 6.4 medium 6% 2005-12-31
CVE-2006-0806 EXP Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbit… Patch early 4.3 medium 6% 2006-02-21
CVE-2012-2270 EXP Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web site… Patch early 5.8 medium 6% 2012-04-20
CVE-2010-2332 EXP Impact Financials, Inc. Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers to cause a denial of service… Patch early 5.0 medium 6% 2010-06-18
CVE-2011-4431 EXP Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary commands via a… Patch early 6.5 medium 6% 2011-11-10
CVE-2001-0283 EXP Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, i… Patch early 6.4 medium 6% 2001-05-03
CVE-2009-1668 EXP TYPSoft FTP Server 1.11 allows remote attackers to cause a denial of service (CPU consumption) by sending an ABOR (abort) command without an active fi… Patch early 4.0 medium 6% 2009-05-18
← previous page 103 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt