peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,116 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

206,665 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-7237 EXP The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directo… Patch early 9.8 critical 6.7% 2017-04-06
CVE-2010-3468 EXP Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CMS 5 through 5.2, allows remote… Patch early 5.0 medium 6.7% 2010-09-29
CVE-2010-1866 EXP The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of se… Patch early 9.8 critical 6.7% 2010-05-07
CVE-2006-1336 EXP Cross-site scripting vulnerability in calendar.php in ExtCalendar 1.0 and possibly other versions before 2.0 allows remote attackers to inject arbitra… Patch early 5.0 medium 6.7% 2006-03-21
CVE-2006-3561 EXP BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication p… Patch early 5.0 medium 6.7% 2006-07-13
CVE-2008-7062 EXP Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows remote attackers to execute ar… Patch early 6.8 medium 6.7% 2009-08-25
CVE-2015-8309 EXP Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to… Patch early 4.3 medium 6.7% 2017-03-27
CVE-2007-6105 EXP Multiple PHP remote file inclusion vulnerabilities in TalkBack 2.2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) languag… Patch early 6.8 medium 6.7% 2007-11-23
CVE-2015-4668 EXP Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attack… Patch early 6.1 medium 6.7% 2017-09-25
CVE-2022-23366 EXP HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php. Patch early 9.8 critical 6.7% 2022-01-21
CVE-2018-7706 EXP Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via a ..… Patch early 6.5 medium 6.7% 2018-03-15
CVE-2001-0206 EXP Directory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by inserting a .. (dot dot) or ... into… Patch early 5.0 medium 6.7% 2001-06-02
CVE-2015-6996 EXP IOAcceleratorFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code or cause a denia… Patch early 6.8 medium 6.7% 2015-10-23
CVE-2008-6843 EXP Directory traversal vulnerability in index.php in Fantastico, as used with cPanel 11.x, allows remote attackers to read arbitrary files via a .. (dot… Patch early 5.0 medium 6.7% 2009-07-02
CVE-2010-2006 EXP Directory traversal vulnerability in op/op.Login.php in LetoDMS (formerly MyDMS) 1.7.2 and earlier allows remote authenticated users to include and ex… Patch early 6.5 medium 6.7% 2010-05-20
CVE-2019-8663 EXP This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6. A remote attacker may be able to leak memory. Patch early 5.3 medium 6.7% 2019-12-18
CVE-2002-1986 EXP Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP request with a trailing dot ("."). Patch early 5.0 medium 6.7% 2002-12-31
CVE-2004-2385 EXP EMU Webmail 5.2.7 allows remote attackers to obtain sensitive path information (home directory) via an HTTP request for init.emu. Patch early 5.0 medium 6.7% 2004-12-31
CVE-2006-0700 EXP imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists f… Patch early 5.0 medium 6.7% 2006-02-15
CVE-2007-2005 EXP Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary P… Patch early 6.8 medium 6.7% 2007-04-12
CVE-2009-4535 EXP Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending a / (slash) character to the URI. Patch early 5.0 medium 6.7% 2009-12-31
CVE-2016-9951 EXP An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `RespawnCommand` or `ProcCmdline` fiel… Patch early 6.5 medium 6.7% 2016-12-17
CVE-2007-6561 EXP Multiple stack-based buffer overflows in PDFLib allow user-assisted remote attackers to execute arbitrary code via a long filename argument to the PDF… Patch early 5.7 medium 6.7% 2007-12-28
CVE-2011-3187 EXP The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in reque… Patch early 4.3 medium 6.7% 2011-08-29
CVE-2004-0164 EXP KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message t… Patch early 5.0 medium 6.7% 2004-03-03
CVE-2009-4665 EXP Directory traversal vulnerability in CuteSoft_Client/CuteEditor/Load.ashx in CuteSoft Components Cute Editor for ASP.NET allows remote attackers to re… Patch early 5.0 medium 6.7% 2010-03-05
CVE-2017-2364 EXP An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. The issue involves the "WebKit" co… Patch early 6.5 medium 6.7% 2017-02-20
CVE-2009-0744 EXP Apple Safari 4 Beta build 528.16 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a feeds: UR… Patch early 5.0 medium 6.7% 2009-02-27
CVE-2006-2284 EXP Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarol… Patch early 6.8 medium 6.7% 2006-05-10
CVE-2007-2486 EXP Directory traversal vulnerability in download.asp in Motobit 1.3 and 1.5 (aka PStruh-CZ) allows remote attackers to read arbitrary files via a .. (dot… Patch early 5.0 medium 6.6% 2007-05-03
← previous page 145 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt