peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

206,641 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-3131 EXP A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or comma… Patch early 5.4 medium 7.7% 2017-09-12
CVE-2017-15990 EXP Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/. Patch early 9.8 critical 7.7% 2017-10-31
CVE-2016-6505 EXP epan/dissectors/packet-packetbb.c in the PacketBB dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a… Patch early 5.9 medium 7.7% 2016-08-06
CVE-2005-3294 EXP Typsoft FTP Server 1.11, with "Sub Directory Include" enabled, allows remote attackers to cause a denial of service (crash) by sending multiple RETR c… Patch early 5.0 medium 7.7% 2005-10-23
CVE-2006-2149 EXP PHP remote file inclusion vulnerability in sources/lostpw.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows rem… Patch early 6.4 medium 7.7% 2006-05-03
CVE-2006-2392 EXP PHP remote file inclusion vulnerability in public_includes/pub_popup/popup_finduser.php in PHP Blue Dragon Platinum 2.8.0 allows remote attackers to e… Patch early 6.4 medium 7.7% 2006-05-16
CVE-2004-0437 EXP Titan FTP Server version 3.01 build 163, and possibly other versions before build 169, allows remote authenticated users to cause a denial of service… Patch early 5.0 medium 7.7% 2004-07-07
CVE-2000-0521 EXP Savant web server allows remote attackers to read source code of CGI scripts via a GET request that does not include the HTTP version number. Patch early 5.0 medium 7.7% 2000-06-05
CVE-2012-1670 EXP admin/index.php in PHP Grade Book before 1.9.5 BETA allows remote attackers to read the database via a SaveSQL action. Patch early 5.0 medium 7.7% 2012-03-31
CVE-2006-4788 EXP PHP remote file inclusion vulnerability in includes/log.inc.php in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled… Patch early 5.1 medium 7.7% 2006-09-14
CVE-2010-0642 EXP Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded characters in the filename extension… Patch early 5.0 medium 7.7% 2010-02-17
CVE-2017-16935 EXP Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to bypass intended access restri… Patch early 9.8 critical 7.7% 2017-11-24
CVE-2008-2106 EXP Call of Duty 4 (CoD4) 1.5 and earlier allows remote authenticated users to cause a denial of service (crash) via a type 7 stats packet, which triggers… Patch early 6.8 medium 7.7% 2008-05-07
CVE-2012-6313 EXP simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information via a reque… Patch early 5.0 medium 7.7% 2012-12-11
CVE-2007-2519 EXP Directory traversal vulnerability in the installer in PEAR 1.0 through 1.5.3 allows user-assisted remote attackers to overwrite arbitrary files via a… Patch early 6.8 medium 7.7% 2007-05-22
CVE-2006-1610 EXP PHP remote file inclusion vulnerability in lib/armygame.php in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allows… Patch early 5.1 medium 7.7% 2006-04-04
CVE-1999-0800 EXP The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm. Patch early 5.0 medium 7.7% 2001-03-12
CVE-2000-0240 EXP vqSoft vqServer program allows remote attackers to read arbitrary files via a /........../ in the URL, a variation of a .. (dot dot) attack. Patch early 5.0 medium 7.7% 2000-03-21
CVE-2000-0782 EXP netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. Patch early 5.0 medium 7.7% 2000-10-20
CVE-2000-0930 EXP Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch. Patch early 5.0 medium 7.7% 2000-12-19
CVE-2011-4336 EXP Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php. Patch early 6.1 medium 7.7% 2020-01-15
CVE-2005-0229 EXP CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card informati… Patch early 5.0 medium 7.7% 2005-04-27
CVE-2012-5907 EXP Directory traversal vulnerability in json.php in TomatoCart 1.2.0 Alpha 2 and possibly earlier allows remote attackers to read arbitrary files via a .… Patch early 5.0 medium 7.7% 2012-11-17
CVE-2014-10010 EXP Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id… Patch early 5.0 medium 7.7% 2015-01-13
CVE-2013-2619 EXP Directory traversal vulnerability in Aspen before 0.22 allows remote attackers to read arbitrary files via a .. (dot dot) to the default URI. Patch early 5.0 medium 7.7% 2014-03-18
CVE-2014-3806 EXP Directory traversal vulnerability in cgi-bin/help/doIt.cgi in VMTurbo Operations Manager before 4.6 allows remote attackers to read arbitrary files vi… Patch early 5.0 medium 7.7% 2014-05-21
CVE-2015-0514 EXP EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by l… Patch early 5.0 medium 7.6% 2015-01-21
CVE-2019-10273 EXP Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active u… Patch early 4.3 medium 7.6% 2019-04-04
CVE-2003-1181 EXP Advanced Poll 2.0.2 allows remote attackers to obtain sensitive information via an HTTP request to info.php, which invokes the phpinfo() function. Patch early 5.0 medium 7.6% 2003-10-25
CVE-2009-3749 EXP The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allows remo… Patch early 5.0 medium 7.6% 2009-10-22
← previous page 129 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt