peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,620 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

149,917 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-4153 EXP The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request. Patch early 7.8 high 7.4% 2014-06-18
CVE-2006-4859 EXP Unrestricted file upload vulnerability in contact.html.php in the Contact (com_contact) component in Limbo (aka Lite Mambo) CMS 1.0.4.2L and earlier a… Patch early 7.5 high 7.4% 2006-09-19
CVE-2007-4805 EXP Directory traversal vulnerability in getgalldata.php in fuzzylime (cms) 3.0 and earlier allows remote attackers to include arbitrary local files via a… Patch early 7.5 high 7.4% 2007-09-11
CVE-2007-4957 EXP Multiple directory traversal vulnerabilities in download.php in Chupix CMS 0.2.3 allow remote attackers to read or overwrite arbitrary files via a ..… Patch early 7.5 high 7.4% 2007-09-18
CVE-2007-6554 EXP Multiple directory traversal vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to include and execute arbitrary local files vi… Patch early 7.5 high 7.4% 2007-12-28
CVE-2015-4075 EXP The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task. Patch early 8.1 high 7.4% 2017-09-20
CVE-2011-4220 EXP Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows remote attackers to cause a denia… Patch early 9.3 high 7.4% 2011-11-01
CVE-2015-7893 EXP SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript. Patch early 8.8 high 7.4% 2017-04-11
CVE-2005-1246 EXP Format string vulnerability in the snmppd_log function in snmppd_util.c for snmppd 0.4.5 and earlier may allow remote attackers to cause a denial of s… Patch early 10.0 high 7.4% 2005-04-24
CVE-2013-6040 EXP MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls before version 4.0 vulnerable to arbitrary code via a crafted HTML document. Latest versions (4.0… Patch early 8.1 high 7.4% 2014-01-21
CVE-2017-10688 EXP In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A crafted input will lead to a… Patch early 7.5 high 7.4% 2017-06-29
CVE-2017-5359 EXP EasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI. Patch early 7.5 high 7.4% 2017-03-15
CVE-2006-5495 EXP Multiple PHP remote file inclusion vulnerabilities in Trawler Web CMS 1.8.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 7.4% 2006-10-25
CVE-2006-2531 EXP Ipswitch WhatsUp Professional 2006 only verifies the user's identity via HTTP headers, which allows remote attackers to spoof being a trusted console… Patch early 7.5 high 7.4% 2006-05-22
CVE-2003-0510 EXP Format string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command. Patch early 7.5 high 7.4% 2003-08-07
CVE-2014-9619 EXP Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x befo… Patch early 7.2 high 7.4% 2017-09-19
CVE-2012-4357 EXP Array index error in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 might allow remote attackers to execute arbit… Patch early 9.3 high 7.4% 2012-08-19
CVE-2008-5904 EXP The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via inpu… Patch early 7.5 high 7.4% 2009-01-15
CVE-2021-43579 EXP A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linkin… Patch early 7.8 high 7.3% 2022-01-10
CVE-2004-1554 EXP PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by modifying the… Patch early 7.5 high 7.3% 2004-12-31
CVE-2000-0766 EXP Buffer overflow in vqSoft vqServer 1.4.49 allows remote attackers to cause a denial of service or possibly gain privileges via a long HTTP GET request… Patch early 7.5 high 7.3% 2000-10-20
CVE-2000-0400 EXP The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to do… Patch early 7.5 high 7.3% 2000-05-13
CVE-2011-4800 EXP Directory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and write arbitrary files, and list a… Patch early 9.0 high 7.3% 2011-12-14
CVE-2001-1195 EXP Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager, which allows remote attackers… Patch early 7.5 high 7.3% 2001-12-15
CVE-2013-1594 EXP An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wireless keys and 3rd party creden… Patch early 7.5 high 7.3% 2020-01-24
CVE-2009-1627 EXP Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbitrary code via a long .asf URL… Patch early 9.3 high 7.3% 2009-05-12
CVE-2004-1161 EXP rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access res… Patch early 7.5 high 7.3% 2005-01-10
CVE-2007-4105 EXP A certain ActiveX control in BaiduBar.dll in Baidu Soba Search Bar 5.4 allows remote attackers to execute arbitrary code via a request containing "a l… Patch early 9.3 high 7.3% 2007-07-31
CVE-2017-6104 EXP Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0. Patch early 7.5 high 7.3% 2017-03-02
CVE-2006-4422 EXP PHP remote file inclusion vulnerability in includes/phpdig/libs/search_function.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 7.3% 2006-08-29
← previous page 181 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt