peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,359 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

206,301 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-1220 EXP BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain tha… Patch early 5.0 medium 9.6% 2002-11-29
CVE-2005-2330 EXP Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers to read arbitrary files via (1) .. sequences or (2) a… Patch early 5.0 medium 9.6% 2005-07-20
CVE-2011-4906 EXP Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution. Patch early 9.8 critical 9.6% 2020-02-12
CVE-2020-8866 EXP This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authenticati… Patch early 6.5 medium 9.6% 2020-03-23
CVE-2001-0042 EXP PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash)… Patch early 5.0 medium 9.6% 2001-02-16
CVE-2022-32272 EXP OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access con… Patch early 9.8 critical 9.6% 2022-06-09
CVE-2015-4071 EXP The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticke… Patch early 5.3 medium 9.6% 2017-08-18
CVE-2006-2863 EXP PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 5.1 medium 9.6% 2006-06-06
CVE-2010-1130 EXP session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the sessio… Patch early 5.0 medium 9.5% 2010-03-26
CVE-2007-6341 EXP Net/DNS/RR/A.pm in Net::DNS 0.60 build 654, as used in packages such as SpamAssassin and OTRS, allows remote attackers to cause a denial of service (p… Patch early 5.0 medium 9.5% 2007-12-20
CVE-2008-1482 EXP Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary… Patch early 6.8 medium 9.5% 2008-03-24
CVE-2008-2795 EXP Directory traversal vulnerability in the FTP and SFTP clients in IDM Computer Solutions Inc UltraEdit 14.00b allows remote FTP servers to create or ov… Patch early 4.3 medium 9.5% 2008-06-20
CVE-2013-2576 EXP Buffer overflow in Artweaver before 3.1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a craft… Patch early 6.8 medium 9.5% 2013-08-09
CVE-2011-1470 EXP The Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via a ziparchive stream that… Patch early 4.3 medium 9.5% 2011-03-20
CVE-2018-18793 EXP School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos. Patch early 9.8 critical 9.5% 2018-11-16
CVE-2002-0484 EXP move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to uninten… Patch early 5.0 medium 9.5% 2002-08-12
CVE-2006-2134 EXP PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to exe… Patch early 5.1 medium 9.5% 2006-05-02
CVE-2006-0513 EXP Directory traversal vulnerability in pkmslogout in Tivoli Web Server Plug-in 5.1.0.10 in Tivoli Access Manager (TAM) 5.1 allows remote attackers to re… Patch early 5.0 medium 9.5% 2006-02-06
CVE-2007-4504 EXP Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allows remote attackers to read ar… Patch early 5.0 medium 9.5% 2007-08-23
CVE-2010-3847 EXP elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGI… Patch early 6.9 medium 9.5% 2011-01-07
CVE-2009-2109 EXP Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (… Patch early 5.0 medium 9.5% 2009-06-18
CVE-2014-9181 EXP Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in… Patch early 5.0 medium 9.5% 2014-12-02
CVE-2005-4557 EXP dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attacker… Patch early 5.0 medium 9.5% 2005-12-28
CVE-2020-5811 EXP An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary f… Patch early 6.5 medium 9.5% 2020-12-30
CVE-2015-2862 EXP Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1… Patch early 4.0 medium 9.5% 2015-07-20
CVE-2010-3676 EXP storage/innobase/dict/dict0crea.c in mysqld in Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (assertio… Patch early 4.0 medium 9.5% 2011-01-11
CVE-2010-1474 EXP Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote attackers to read arbitrary files… Patch early 6.8 medium 9.5% 2010-04-19
CVE-2010-1475 EXP Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows remote attackers to read arbitra… Patch early 6.8 medium 9.5% 2010-04-19
CVE-2010-1722 EXP Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to read arbitrary files and poss… Patch early 6.8 medium 9.5% 2010-05-04
CVE-2006-3879 EXP Integer overflow in the loadChunk function in loaders/load_gt2.c in libmikmod in Mikmod Sound System 3.2.2 allows remote attackers to cause a denial o… Patch early 5.0 medium 9.5% 2006-07-27
← previous page 109 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt