peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,556 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

170,398 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-3350 EXP SQL injection vulnerability in index.php in Webmatic 3.1.1 allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header. Patch early 6.8 medium 2.9% 2012-07-12
CVE-2005-1893 EXP FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in… Patch early 5.0 medium 2.9% 2005-06-09
CVE-2007-0329 EXP download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathname in the file parameter, as d… Patch early 5.0 medium 2.9% 2007-01-18
CVE-2006-5784 EXP Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to read… Patch early 4.6 medium 2.9% 2006-11-07
CVE-2018-1002002 EXP There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileg… Patch early 4.8 medium 2.9% 2018-12-03
CVE-2018-1002003 EXP There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileg… Patch early 4.8 medium 2.9% 2018-12-03
CVE-2018-1002004 EXP There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileg… Patch early 4.8 medium 2.9% 2018-12-03
CVE-2006-1205 EXP Multiple cross-site scripting (XSS) vulnerabilities in myWebland myBloggie 2.1.3 beta and earlier allow remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 2.9% 2006-03-14
CVE-2009-2397 EXP Directory traversal vulnerability in download.php in Audio Article Directory allows remote attackers to read arbitrary files via directory traversal s… Patch early 5.0 medium 2.9% 2009-07-09
CVE-2009-3425 EXP Directory traversal vulnerability in includes/inc.thcms_admin_dirtree.php in MaxCMS 3.11.20b allows remote attackers to read arbitrary files via direc… Patch early 5.0 medium 2.9% 2009-09-25
CVE-2009-4726 EXP Directory traversal vulnerability in download.php in Quickdev 4 PHP allows remote attackers to read arbitrary files via a .. (dot dot) in the file par… Patch early 5.0 medium 2.9% 2010-03-18
CVE-2009-4978 EXP Directory traversal vulnerability in down.php in MyBackup 1.4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename par… Patch early 5.0 medium 2.9% 2010-08-25
CVE-2015-4072 EXP Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web… Patch early 5.4 medium 2.9% 2017-09-20
CVE-2006-5510 EXP Directory traversal vulnerability in explorer_load_lang.php in PH Pexplorer 0.24 allows remote attackers to include arbitrary local files via ".." seq… Patch early 6.4 medium 2.9% 2006-10-25
CVE-2008-0435 EXP Directory traversal vulnerability in index.php in OZJournals 2.1.1 allows remote attackers to read portions of arbitrary files via a .. (dot dot) in t… Patch early 5.0 medium 2.9% 2008-01-23
CVE-2008-1400 EXP Directory traversal vulnerability in the Net Inspector HTTP Server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote… Patch early 5.0 medium 2.9% 2008-03-20
CVE-2008-1730 EXP Directory traversal vulnerability in download.html in ARWScripts Gallery Script Lite (aka gallery-script-lite or Free Photo Gallery Site Script), as o… Patch early 5.0 medium 2.9% 2008-04-11
CVE-2008-3675 EXP Directory traversal vulnerability in classes/imgsize.php in Gelato 0.95 allows remote attackers to read arbitrary files via (1) a .. (dot dot) and pos… Patch early 5.0 medium 2.9% 2008-08-14
CVE-2008-4151 EXP Directory traversal vulnerability in collect.php in CYASK 3.x allows remote attackers to read arbitrary files via a .. (dot dot) in the neturl paramet… Patch early 5.0 medium 2.9% 2008-09-24
CVE-2008-1541 EXP Directory traversal vulnerability in cgi-bin/his-webshop.pl in HIS Webshop 2.50 allows remote attackers to read arbitrary files via a .. (dot dot) in… Patch early 4.3 medium 2.9% 2008-03-28
CVE-2002-2404 EXP Buffer overflow in IISPop email server 1.161 and 1.181 allows remote attackers to cause a denial of service (crash) via a long request to the POP3 por… Patch early 5.0 medium 2.9% 2002-12-31
CVE-2006-5716 EXP Directory traversal vulnerability in aff_news.php in FreeNews 2.1 allows remote attackers to include local files via a .. (dot dot) sequence in the ch… Patch early 5.0 medium 2.9% 2006-11-04
CVE-2007-0429 EXP DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to cause a denial of service (Int… Patch early 5.0 medium 2.9% 2007-01-23
CVE-2021-33562 EXP A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.8 medium 2.9% 2021-05-24
CVE-2000-1114 EXP Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+"… Patch early 5.0 medium 2.9% 2001-01-09
CVE-2006-3846 EXP PHP remote file inclusion vulnerability in extadminmenus.class.php in the MultiBanners 1.0.1 for Mambo allows remote attackers to execute arbitrary PH… Patch early 6.8 medium 2.9% 2006-07-25
CVE-2008-6045 EXP Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTC… Patch early 6.8 medium 2.9% 2009-02-03
CVE-2007-1427 EXP Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 5.0 medium 2.9% 2007-03-13
CVE-2005-4510 EXP Directory traversal vulnerability in server.np in NetPublish Server 7 allows remote attackers to read arbitrary files via "../" sequences in the templ… Patch early 5.0 medium 2.9% 2005-12-23
CVE-2007-4101 EXP Multiple PHP remote file inclusion vulnerabilities in Madoa Poll 1.1 allow remote attackers to execute arbitrary PHP code via the Madoa parameter to (… Patch early 6.8 medium 2.9% 2007-07-31
← previous page 188 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt