peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,585 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

170,402 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-1645 EXP Keyvan1 ImageGallery stores the image.mdb database under the web document root with insufficient access control, which allows remote attackers to obta… Patch early 5.0 medium 2.9% 2005-05-18
CVE-2000-0739 EXP Directory traversal vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to read arbitrary file… Patch early 5.0 medium 2.9% 2000-10-20
CVE-2005-2956 EXP ATutor 1.5.1, and possibly earlier versions, stores temporary chat logs under the web document root with insufficient access control and predictable f… Patch early 5.0 medium 2.9% 2005-09-16
CVE-2005-3432 EXP MiniGal 2 (MG2) 0.5.1 allows remote attackers to list password protected images via a request to index.php with the list parameter set to * (wildcard)… Patch early 5.0 medium 2.9% 2005-11-02
CVE-2005-3728 EXP Idetix Software Systems Revize CMS stores conf/revize.xml under the web document root with insufficient access control, which allows remote attackers… Patch early 5.0 medium 2.9% 2005-11-21
CVE-2005-4423 EXP Unrestricted file upload vulnerability in PHPFM before 0.2.3 allows remote authenticated users to execute arbitrary code by uploading a file with an e… Patch early 6.5 medium 2.9% 2005-12-20
CVE-2006-2763 EXP SQL injection vulnerability in Pre News Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) index.ph… Patch early 6.4 medium 2.9% 2006-06-02
CVE-2012-2237 EXP Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web… Patch early 6.1 medium 2.9% 2019-12-17
CVE-2007-1152 EXP Multiple directory traversal vulnerabilities in Pyrophobia 2.1.3.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) act or… Patch early 5.0 medium 2.9% 2007-03-02
CVE-2018-0745 EXP The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an information disclosure vulnerabilit… Patch early 4.7 medium 2.9% 2018-01-04
CVE-2007-0697 EXP index2.php in ACGVannu 1.3 and earlier allows remote attackers to change the password or profile of a user via a modified id parameter, related to tem… Patch early 6.4 medium 2.9% 2007-02-03
CVE-2005-2467 EXP Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML v… Patch early 5.8 medium 2.9% 2005-12-31
CVE-2006-6158 EXP Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpde… Patch early 6.8 medium 2.9% 2006-11-28
CVE-2000-1224 EXP Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters… Patch early 5.0 medium 2.9% 2000-11-23
CVE-2012-5905 EXP Buffer overflow in KnFTPd 1.0.0 allows remote authenticated users to cause a denial of service (crash) via a long string in a FEAT command. Patch early 4.0 medium 2.9% 2012-11-17
CVE-2006-6044 EXP PHP remote file inclusion vulnerability in gallery_top.inc.php in PHPQuickGallery 1.9 and earlier allows remote attackers to execute arbitrary PHP cod… Patch early 6.8 medium 2.9% 2006-11-22
CVE-2006-2252 EXP Cross-site scripting vulnerability in submit.php in OpenFAQ 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter. Patch early 6.4 medium 2.9% 2006-05-09
CVE-2012-2741 EXP Cross-site scripting (XSS) vulnerability in public_html/lists/admin/ in phpList before 2.10.18 allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 2.9% 2012-09-06
CVE-2010-2676 EXP Multiple directory traversal vulnerabilities in index.php in Open Web Analytics (OWA) 1.2.3 might allow remote attackers to read arbitrary files via d… Patch early 5.0 medium 2.9% 2010-07-08
CVE-2006-6643 EXP Fightersoft Multimedia Star FTP server 1.10 allows remote attackers to cause a denial of service (crash) via multiple RETR commands with long argument… Patch early 5.0 medium 2.9% 2006-12-20
CVE-2015-2838 EXP Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authen… Patch early 6.8 medium 2.9% 2015-04-03
CVE-2005-1674 EXP Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG… Patch early 6.5 medium 2.9% 2005-05-19
CVE-2014-4030 EXP Cross-site request forgery (CSRF) vulnerability in the JW Player plugin before 2.1.4 for WordPress allows remote attackers to hijack the authenticatio… Patch early 6.8 medium 2.9% 2014-06-25
CVE-2020-14073 EXP XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can create a map, and then use the… Patch early 5.4 medium 2.9% 2020-06-23
CVE-2006-0691 EXP edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbi… Patch early 5.0 medium 2.9% 2006-02-15
CVE-2007-6603 EXP Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator… Patch early 5.0 medium 2.9% 2007-12-31
CVE-2010-1652 EXP Directory traversal vulnerability in the HelpCenter module in Help Center Live (HCL) 2.0.6 and 2.1.7 allows remote attackers to read arbitrary files a… Patch early 5.0 medium 2.9% 2010-05-03
CVE-2007-0983 EXP PHP remote file inclusion vulnerability in _admin/nav.php in AT Contenator 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a… Patch early 6.8 medium 2.9% 2007-02-16
CVE-2007-3404 EXP Directory traversal vulnerability in ShowImage.php in SiteDepth CMS 3.44 allows remote attackers to read arbitrary files via a .. (dot dot) in the nam… Patch early 5.0 medium 2.9% 2007-06-26
CVE-2009-1663 EXP Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to execute arbitrary code b… Patch early 6.8 medium 2.9% 2009-05-18
← previous page 191 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt