peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,964 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

170,210 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-4426 EXP PHP remote file inclusion vulnerability in AES/modules/auth/phpsecurityadmin/include/logout.php in AlberT-EasySite (AES) 1.0a5 and earlier allows remo… Patch early 5.1 medium 3.1% 2006-08-29
CVE-2009-2600 EXP Multiple directory traversal vulnerabilities in view.php in Webboard 2.90 beta and earlier allow remote attackers to read arbitrary files via a .. (do… Patch early 5.0 medium 3.1% 2009-07-27
CVE-2011-4716 EXP Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read arbitrary files via the file p… Patch early 5.0 medium 3.1% 2011-12-08
CVE-2006-5400 EXP PHP remote file inclusion vulnerability in forum/track.php in CyberBrau 0.9.4, when register_globals is enabled, allows remote attackers to execute ar… Patch early 5.1 medium 3.1% 2006-10-18
CVE-2006-6065 EXP PHP remote file inclusion vulnerability in includes/mx_common.php in the CalSnails Module for MxBB Portal 1.06 allows remote attackers to execute arbi… Patch early 5.1 medium 3.1% 2006-11-22
CVE-2004-1751 EXP Ground Control II: Operation Exodus 1.0.0.7 and earlier allows remote servers to cause a denial of service (client or server crash) via a large packet… Patch early 5.0 medium 3.1% 2004-08-26
CVE-2012-2905 EXP Artiphp CMS 5.5.0 Neo (r422) stores database backups with predictable names under the web root with insufficient access control, which allows remote a… Patch early 5.0 medium 3.1% 2012-05-21
CVE-2012-1469 EXP Multiple cross-site scripting (XSS) vulnerabilities in Open Journal Systems before 2.3.7 allow remote attackers and remote authenticated users to inje… Patch early 4.3 medium 3.1% 2012-09-06
CVE-2007-4385 EXP OWASP Stinger before 2.5 allows remote attackers to bypass input validation routines by using multipart encoded requests instead of form-urlencoded re… Patch early 6.8 medium 3.1% 2007-08-17
CVE-2020-13228 EXP An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter. Patch early 6.1 medium 3.1% 2020-06-02
CVE-2008-0155 EXP Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 3.1% 2008-01-09
CVE-2023-0916 EXP A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. Affected by this vulnerability is an unknown fun… Patch early 6.3 medium 3.1% 2023-02-19
CVE-2010-3486 EXP Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbitrary files via a (1) ../ (dot… Patch early 5.0 medium 3.1% 2010-09-22
CVE-2008-3181 EXP Unrestricted file upload vulnerability in upload.php in ContentNow CMS 1.4.1 allows remote authenticated users to execute arbitrary code by uploading… Patch early 6.5 medium 3.1% 2008-07-15
CVE-2006-0877 EXP Cross-site scripting vulnerability in Easy Forum 2.5 allows remote attackers to inject arbitrary web script or HTML via the image variable. Patch early 5.0 medium 3.1% 2006-02-24
CVE-1999-1518 EXP Operating systems with shared memory implementations based on BSD 4.4 code allow a user to conduct a denial of service and bypass memory limits (e.g.,… Patch early 5.0 medium 3.1% 1999-07-15
CVE-2005-1061 EXP The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure fi… Patch early 5.0 medium 3.1% 2005-05-02
CVE-2017-12951 EXP The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (stack-based bu… Patch early 6.5 medium 3.1% 2017-08-28
CVE-2018-9172 EXP The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes. Patch early 5.4 medium 3.1% 2018-04-01
CVE-2005-0283 EXP Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of… Patch early 5.0 medium 3.1% 2005-01-04
CVE-2005-1998 EXP Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang paramet… Patch early 5.0 medium 3.1% 2005-06-15
CVE-2000-0601 EXP LeafChat 1.7 IRC client allows a remote IRC server to cause a denial of service by rapidly sending a large amount of error messages. Patch early 5.0 medium 3.1% 2000-06-25
CVE-2005-2357 EXP Directory traversal vulnerability in EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. Patch early 5.0 medium 3.1% 2005-08-16
CVE-2005-4160 EXP Directory traversal vulnerability in getdox.php in Torrential 1.2 allows remote attackers to read arbitrary files via "../" sequences in the query str… Patch early 5.0 medium 3.1% 2005-12-11
CVE-2005-4250 EXP Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via the language parameter. Patch early 5.0 medium 3.1% 2005-12-14
CVE-2009-4688 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Shopping Cart Selling Website Script allow remote attackers to inject arbitrar… Patch early 4.3 medium 3.1% 2010-03-10
CVE-2013-4898 EXP Unrestricted file upload vulnerability in the user profile page feature in the Timeline Plugin 4.2.5p9 for SocialEngine allows remote authenticated us… Patch early 6.5 medium 3.1% 2014-01-29
CVE-2023-34927 EXP Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows… Patch early 6.5 medium 3.1% 2023-06-22
CVE-2020-35437 EXP Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI. Patch early 6.1 medium 3.1% 2020-12-26
CVE-2019-1344 EXP An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memory, aka 'Windows Code Integrit… Patch early 5.5 medium 3.1% 2019-10-10
← previous page 180 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt