peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,317 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

170,063 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-1110 EXP Directory traversal vulnerability in data/showcode.php in ActiveCalendar 1.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in t… Patch early 5.0 medium 3.6% 2007-02-26
CVE-2001-0462 EXP Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. Patch early 5.0 medium 3.6% 2001-06-27
CVE-2002-1033 EXP Directory traversal vulnerability in none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via a "..:" sequence (dot-dot v… Patch early 5.0 medium 3.6% 2002-10-04
CVE-2003-1450 EXP BitchX 75p3 and 1.0c16 through 1.0c20cvs allows remote attackers to cause a denial of service (segmentation fault) via a malformed RPL_NAMREPLY numeri… Patch early 5.0 medium 3.6% 2003-12-31
CVE-2018-0968 EXP An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel… Patch early 5.5 medium 3.6% 2018-04-12
CVE-2008-4874 EXP The web component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 has a back door "service" account with "service" as it… Patch early 5.0 medium 3.5% 2008-11-01
CVE-2005-0369 EXP Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a… Patch early 5.3 medium 3.5% 2005-05-02
CVE-2012-0782 EXP Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow re… Patch early 4.3 medium 3.5% 2012-01-30
CVE-2009-4053 EXP Multiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) create arbitrary directories via di… Patch early 6.5 medium 3.5% 2009-11-23
CVE-2012-6276 EXP Directory traversal vulnerability in the web-based management interface on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n a… Patch early 4.3 medium 3.5% 2013-01-26
CVE-2007-6581 EXP Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrary local files via a .. (dot do… Patch early 6.4 medium 3.5% 2007-12-28
CVE-2002-1494 EXP Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script by inserting the script after… Patch early 4.3 medium 3.5% 2003-04-02
CVE-2002-1806 EXP Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. Patch early 4.3 medium 3.5% 2002-12-31
CVE-2002-1995 EXP Cross-site scripting (XSS) vulnerability in phptonuke.php for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the filnavn… Patch early 4.3 medium 3.5% 2002-12-31
CVE-2002-2193 EXP Cross-site scripting (XSS) vulnerability in mojo.cgi for Mojo Mail 2.7 allows remote attackers to inject arbitrary web script via the email parameter. Patch early 4.3 medium 3.5% 2002-12-31
CVE-2003-1243 EXP Cross-site scripting vulnerability (XSS) in Sage 1.0 b3 allows remote attackers to insert arbitrary HTML or web script via the mod parameter. Patch early 4.3 medium 3.5% 2003-12-31
CVE-2020-22841 EXP Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input fie… Patch early 4.8 medium 3.5% 2021-02-09
CVE-2009-1583 EXP Multiple cross-site scripting (XSS) vulnerabilities in TemaTres 1.0.3 and 1.031 allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 3.5% 2009-05-07
CVE-2010-0366 EXP Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta all… Patch early 6.8 medium 3.5% 2010-01-21
CVE-2009-3902 EXP Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read arbitrary files via a /\.. (sla… Patch early 5.0 medium 3.5% 2009-11-06
CVE-2002-1028 EXP Multiple buffer overflows in the CGI programs for Oddsock Song Requester WinAmp plugin 2.1 allow remote attackers to cause a denial of service (crash)… Patch early 5.0 medium 3.5% 2002-10-04
CVE-2000-1027 EXP Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requ… Patch early 5.0 medium 3.5% 2000-12-11
CVE-2007-0357 EXP Directory traversal vulnerability in the AVM IGD CTRL Service in Fritz!DSL 02.02.29 allows remote attackers to read arbitrary files via ..%5C (URL-enc… Patch early 5.0 medium 3.5% 2007-01-19
CVE-2005-3948 EXP Directory traversal vulnerability in main.php in PHPAlbum 0.2.3 and earlier allows remote attackers to read arbitrary files via the (1) cmd and (2) va… Patch early 5.0 medium 3.5% 2005-12-01
CVE-2009-2229 EXP Directory traversal vulnerability in engine.php in Kasseler CMS 1.3.5 lite allows remote attackers to read arbitrary files via a .. (dot dot) in the f… Patch early 5.0 medium 3.5% 2009-06-26
CVE-2011-3856 EXP Cross-site scripting (XSS) vulnerability in the Elegant Grunge theme before 1.0.4 for WordPress allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 3.5% 2011-09-28
CVE-2011-3858 EXP Cross-site scripting (XSS) vulnerability in the Pixiv Custom theme before 2.1.6 for WordPress allows remote attackers to inject arbitrary web script o… Patch early 4.3 medium 3.5% 2011-09-28
CVE-2011-3861 EXP Cross-site scripting (XSS) vulnerability in the Web Minimalist 200901 theme before 1.2 for WordPress allows remote attackers to inject arbitrary web s… Patch early 4.3 medium 3.5% 2011-09-28
CVE-2011-3865 EXP Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 3.5% 2011-09-28
CVE-2013-1604 EXP Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to read arbitrary files via a… Patch early 5.0 medium 3.5% 2014-03-25
← previous page 156 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt