peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,178 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

206,676 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2000-0254 EXP The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that… Patch early 5.0 medium 6% 2000-04-14
CVE-2001-0200 EXP HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path… Patch early 5.0 medium 6% 2001-05-03
CVE-2001-0788 EXP Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows remote attackers to obtain an absolute path for the server directory by… Patch early 5.0 medium 6% 2001-10-18
CVE-2007-4508 EXP Stack-based buffer overflow in Rebellion Asura engine, as used for the server in Rogue Trooper 1.0 and earlier and Prism 1.1.1.0 and earlier, allows r… Patch early 6.8 medium 6% 2007-08-23
CVE-2010-4777 EXP The Perl_reg_numbered_buff_fetch function in Perl 5.10.0, 5.12.0, 5.14.0, and other versions, when running with debugging enabled, allows context-depe… Patch early 4.3 medium 6% 2014-02-10
CVE-2018-19371 EXP The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system. Patch early 6.5 medium 6% 2019-01-02
CVE-2005-4600 EXP Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to read or include arbitrary file… Patch early 6.4 medium 6% 2005-12-31
CVE-2017-16716 EXP A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands. Patch early 9.8 critical 6% 2018-01-05
CVE-2006-0806 EXP Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbit… Patch early 4.3 medium 6% 2006-02-21
CVE-2012-2270 EXP Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web site… Patch early 5.8 medium 6% 2012-04-20
CVE-2010-2332 EXP Impact Financials, Inc. Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers to cause a denial of service… Patch early 5.0 medium 6% 2010-06-18
CVE-2011-4431 EXP Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary commands via a… Patch early 6.5 medium 6% 2011-11-10
CVE-2001-0283 EXP Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, i… Patch early 6.4 medium 6% 2001-05-03
CVE-2009-1668 EXP TYPSoft FTP Server 1.11 allows remote attackers to cause a denial of service (CPU consumption) by sending an ABOR (abort) command without an active fi… Patch early 4.0 medium 6% 2009-05-18
CVE-2023-2779 EXP The Social Share, Social Login and Social Comments WordPress plugin before 7.13.52 does not sanitise and escape a parameter before outputting it back… Patch early 6.1 medium 6% 2023-06-19
CVE-2005-2543 EXP Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) i… Patch early 5.0 medium 6% 2005-08-10
CVE-2017-3631 EXP Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11. Easi… Patch early 5.3 medium 6% 2017-06-22
CVE-2007-3233 EXP The TEC-IT TBarCode OCX ActiveX control (TBarCode7.ocx) 7.0.2.3524 allows remote attackers to overwrite arbitrary files via the SaveImage method. Patch early 5.0 medium 6% 2007-06-15
CVE-2006-3533 EXP Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allow remote attackers to inject… Patch early 5.8 medium 6% 2006-07-12
CVE-2011-5105 EXP Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in ZOHO ManageEngine ADSelfService Plus 4.5 Build 4521 allow remote attackers… Patch early 4.3 medium 6% 2012-08-23
CVE-2012-2602 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers… Patch early 6.8 medium 6% 2012-08-12
CVE-2006-5310 EXP PHP remote file inclusion vulnerability in common/visiteurs/include/menus.inc.php in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences… Patch early 6.8 medium 6% 2006-10-17
CVE-2009-0855 EXP Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 on z/OS allows re… Patch early 4.3 medium 6% 2009-03-09
CVE-2021-44653 EXP Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due… Patch early 9.8 critical 6% 2021-12-15
CVE-2021-44655 EXP Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. Admin panel authentication can… Patch early 9.8 critical 6% 2021-12-15
CVE-2006-6453 EXP PHP remote file inclusion vulnerability in JOWAMP_ShowPage.php in J-OWAMP Web Interface 2.1 allows remote authenticated users to execute arbitrary PHP… Patch early 6.5 medium 6% 2006-12-10
CVE-2014-3849 EXP The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users… Patch early 4.3 medium 6% 2014-05-23
CVE-1999-0264 EXP htmlscript CGI program allows remote read access to files. Patch early 5.0 medium 6% 1998-01-27
CVE-2013-0663 EXP Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE01… Patch early 6.8 medium 6% 2013-04-04
CVE-2002-0898 EXP Opera 6.0.1 and 6.0.2 allows a remote web site to upload arbitrary files from the client system, without prompting the client, via an input type=file… Patch early 5.0 medium 6% 2002-10-04
← previous page 155 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt