peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

206,641 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-3851 EXP Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute arbitrary local files via a .… Patch early 5.0 medium 7.9% 2008-08-27
CVE-1999-1005 EXP Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter… Patch early 5.0 medium 7.9% 1999-12-19
CVE-2006-2156 EXP Directory traversal vulnerability in help/index.php in X7 Chat 2.0 and earlier allows remote attackers to include arbitrary files via .. (dot dot) seq… Patch early 6.4 medium 7.9% 2006-05-03
CVE-2009-1415 EXP lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows remote attackers to cause a denia… Patch early 4.3 medium 7.9% 2009-04-30
CVE-2006-2142 EXP PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and earlier allows remote attackers to execute arbitrary PHP code… Patch early 6.4 medium 7.9% 2006-05-02
CVE-2007-3799 EXP The session_start function in ext/session in PHP 4.x up to 4.4.7 and 5.x up to 5.2.3 allows remote attackers to insert arbitrary attributes into the s… Patch early 4.3 medium 7.9% 2007-07-16
CVE-2013-5680 EXP Heap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when using LDAP authentication, might allow remote attackers to cause a denial of… Patch early 6.8 medium 7.9% 2014-04-06
CVE-2001-1528 EXP AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote att… Patch early 5.0 medium 7.9% 2001-12-31
CVE-2001-0123 EXP Directory traversal vulnerability in eXtropia bbs_forum.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the file… Patch early 5.0 medium 7.9% 2001-03-12
CVE-2018-18775 EXP Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the Log… Patch early 6.1 medium 7.9% 2018-11-01
CVE-2009-2851 EXP Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web scri… Patch early 4.3 medium 7.9% 2009-08-18
CVE-2001-0900 EXP Directory traversal vulnerability in modules.php in Gallery before 1.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the inc… Patch early 5.0 medium 7.9% 2001-11-18
CVE-2006-5773 EXP Directory traversal vulnerability in index.php in FreeWebshop 2.2.1 and earlier allows remote attackers to read arbitrary files and disclose the insta… Patch early 5.0 medium 7.9% 2006-11-06
CVE-2018-5755 EXP Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.x before 7.8.2-rev4, 7.8.3 bef… Patch early 5.5 medium 7.9% 2018-06-16
CVE-2023-0493 EXP Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5. Patch early 5.3 medium 7.9% 2023-01-26
CVE-2018-13042 EXP The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling… Patch early 5.9 medium 7.9% 2018-10-05
CVE-2004-1422 EXP WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php settings. Patch early 5.0 medium 7.9% 2004-12-31
CVE-2004-1720 EXP The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an inval… Patch early 5.0 medium 7.9% 2004-08-17
CVE-2023-39115 EXP install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document. Patch early 9.8 critical 7.9% 2023-08-16
CVE-2012-5100 EXP Directory traversal vulnerability in HServer 0.1.1 allows remote attackers to read arbitrary files via a (1) ..%5c (dot dot encoded backslash) or (2)… Patch early 5.0 medium 7.9% 2012-09-23
CVE-2000-1147 EXP Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the "LANGUAGE" argument in a s… Patch early 4.6 medium 7.9% 2001-01-09
CVE-2006-0047 EXP packets.c in Freeciv 2.0 before 2.0.8 allows remote attackers to cause a denial of service (server crash) via crafted packets with negative compressed… Patch early 5.0 medium 7.9% 2006-03-07
CVE-2016-6256 EXP SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcelle… Patch early 9.6 critical 7.9% 2017-05-26
CVE-2010-4350 EXP Directory traversal vulnerability in admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to include and execute arbitrary lo… Patch early 5.1 medium 7.9% 2011-01-03
CVE-2008-6948 EXP Unrestricted file upload vulnerability in Collabtive 0.4.8 allows remote authenticated users to execute arbitrary code by uploading a file with an exe… Patch early 6.5 medium 7.9% 2009-08-12
CVE-2019-8404 EXP An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted product image during the crea… Patch early 6.5 medium 7.9% 2019-05-14
CVE-2006-2568 EXP PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute… Patch early 5.1 medium 7.9% 2006-05-24
CVE-2003-1191 EXP chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML in the Name field, which preven… Patch early 5.0 medium 7.9% 2003-10-29
CVE-2000-0350 EXP A debugging feature in NetworkICE ICEcap 2.0.23 and earlier is enabled, which allows a remote attacker to bypass the weak authentication and post unen… Patch early 5.0 medium 7.9% 2000-05-17
CVE-2008-3447 EXP The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop) via a malformed ZIP archive, p… Patch early 5.0 medium 7.9% 2008-08-04
← previous page 126 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt