peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,045 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

206,615 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-0112 EXP Etype Eserv 2.97 allows remote attackers to view password protected files via /./ in the URL. Patch early 5.0 medium 8.1% 2002-03-25
CVE-2007-0197 EXP Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a lo… Patch early 6.8 medium 8.1% 2007-01-11
CVE-2000-0921 EXP Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot do… Patch early 5.0 medium 8.1% 2000-12-19
CVE-2001-0295 EXP Directory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly read files via a "dir *./../.." c… Patch early 5.0 medium 8.1% 2001-05-03
CVE-2001-0924 EXP Directory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary files via a .. (dot dot) in t… Patch early 5.0 medium 8.1% 2001-11-22
CVE-2006-1470 EXP OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an… Patch early 5.0 medium 8.1% 2006-06-27
CVE-2009-0497 EXP Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\ (dot dot back… Patch early 5.0 medium 8.1% 2009-02-10
CVE-2012-0389 EXP Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in MailEnable Professional, Enterprise, and Premium 4.26 and earlier, 5.x before 5.… Patch early 4.3 medium 8.1% 2012-01-24
CVE-2024-50477 EXP Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentica… Patch early 9.8 critical 8.1% 2024-10-28
CVE-2019-9623 EXP Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php. Patch early 9.8 critical 8.1% 2019-03-07
CVE-2004-1937 EXP Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbitrary files via .. sequences in… Patch early 5.0 medium 8.1% 2004-12-31
CVE-2004-2640 EXP Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequence… Patch early 5.0 medium 8.1% 2004-12-31
CVE-2017-3132 EXP A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the… Patch early 6.1 medium 8.1% 2017-09-12
CVE-2009-4050 EXP Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 allows remote attackers to read arbitrary files via directory traversal sequen… Patch early 5.0 medium 8.1% 2009-11-23
CVE-2002-2084 EXP Directory traversal vulnerability in index.php of Portix 0.4.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) l and (2… Patch early 5.0 medium 8.1% 2002-12-31
CVE-2005-4208 EXP Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id… Patch early 5.0 medium 8.1% 2005-12-13
CVE-2019-7671 EXP Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may a… Patch early 9.0 critical 8.1% 2019-06-05
CVE-2008-0625 EXP Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attackers to execute arbitrary code vi… Patch early 4.3 medium 8.1% 2008-02-06
CVE-2008-1119 EXP Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .… Patch early 5.0 medium 8.1% 2008-03-03
CVE-2003-0277 EXP Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot… Patch early 5.0 medium 8.1% 2003-06-16
CVE-2001-1408 EXP Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 5.0 medium 8.1% 2001-07-05
CVE-2004-1951 EXP xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) aud… Patch early 5.0 medium 8.1% 2004-12-31
CVE-2004-2184 EXP Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write arbitrary files via "../" or "..… Patch early 6.4 medium 8.1% 2004-12-31
CVE-2004-1699 EXP SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter… Patch early 5.0 medium 8.1% 2004-09-21
CVE-2026-1830 EXP The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insuffici… Patch early 9.8 critical 8.1% 2026-04-09
CVE-2004-0269 EXP SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive inf… Patch early 6.4 medium 8.1% 2004-11-23
CVE-2016-9018 EXP Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlaye… Patch early 5.5 medium 8.1% 2016-10-28
CVE-2006-4955 EXP Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via… Patch early 5.0 medium 8.1% 2006-09-23
CVE-2007-3006 EXP Buffer overflow in Acoustica MP3 CD Burner 4.32 allows user-assisted remote attackers to execute arbitrary code via a .asx playlist file with a REF el… Patch early 6.8 medium 8.1% 2007-06-04
CVE-2010-1128 EXP The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attack… Patch early 6.4 medium 8.1% 2010-03-26
← previous page 123 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt