peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,593 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

170,403 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-0345 EXP viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protected forums v… Patch early 5.0 medium 2.8% 2005-05-02
CVE-2009-3149 EXP Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a… Patch early 4.3 medium 2.8% 2009-09-10
CVE-2007-2202 EXP PHP remote file inclusion vulnerability in inc_ACVS/SOAP/Transport.php in Accueil et Conseil en Visites et Sejours Web Services (ACVSWS) PHP5 (ACVSWS_… Patch early 6.8 medium 2.8% 2007-04-24
CVE-2019-1148 EXP An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who suc… Patch early 5.5 medium 2.8% 2019-08-14
CVE-2019-1153 EXP An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who suc… Patch early 5.5 medium 2.8% 2019-08-14
CVE-2008-2969 EXP Directory traversal vulnerability in download.php in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allows remote attackers to read… Patch early 5.0 medium 2.8% 2008-07-02
CVE-2008-4758 EXP Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local files via a .. (dot dot) in the fi… Patch early 5.0 medium 2.8% 2008-10-28
CVE-2007-2009 EXP PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 6.8 medium 2.8% 2007-04-12
CVE-2007-3608 EXP Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certain files via unspecified vector… Patch early 5.0 medium 2.8% 2007-07-06
CVE-2007-6400 EXP Directory traversal vulnerability in download_file.php in PolDoc CMS (aka PDDMS) 0.96 allows remote attackers to read arbitrary files via a .. (dot do… Patch early 5.0 medium 2.8% 2007-12-17
CVE-2012-1112 EXP Directory traversal vulnerability in Open-Realty CMS 2.5.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (… Patch early 6.8 medium 2.8% 2012-09-06
CVE-2013-4240 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to hijack… Patch early 6.8 medium 2.8% 2014-04-02
CVE-2009-1808 EXP Microsoft Windows XP SP3 allows local users to cause a denial of service (system crash) by making an SPI_SETDESKWALLPAPER SystemParametersInfo call wi… Patch early 4.9 medium 2.8% 2009-05-28
CVE-2006-6604 EXP Directory traversal vulnerability in downloaddetails.php in TorrentFlux 2.2 allows remote authenticated users to read arbitrary files via .. (dot dot)… Patch early 6.5 medium 2.8% 2006-12-15
CVE-2016-4315 EXP Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requ… Patch early 5.7 medium 2.8% 2017-02-17
CVE-2003-1499 EXP Directory traversal vulnerability in index.php in Bytehoard 0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the infolder par… Patch early 5.0 medium 2.8% 2003-12-31
CVE-2008-0361 EXP Directory traversal vulnerability in agregar_info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local file… Patch early 4.3 medium 2.8% 2008-01-18
CVE-2019-10893 EXP CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to Stored/Persistent XSS for Adm… Patch early 4.8 medium 2.8% 2019-04-18
CVE-2013-2945 EXP SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to execute arbitrary SQL command… Patch early 6.5 medium 2.8% 2014-04-02
CVE-2004-0374 EXP Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensitive SQL information via an HT… Patch early 6.4 medium 2.8% 2004-05-04
CVE-2007-1577 EXP Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) i… Patch early 5.0 medium 2.8% 2007-03-21
CVE-2008-7008 EXP HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a direct request to admin/backup/… Patch early 5.0 medium 2.8% 2009-08-19
CVE-2013-1743 EXP Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x before 4.2.7 and 4.3.x and 4.4.x before 4.4.1 allow remo… Patch early 4.3 medium 2.8% 2013-10-24
CVE-2012-0865 EXP Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phis… Patch early 5.8 medium 2.8% 2012-02-21
CVE-2013-1645 EXP Directory traversal vulnerability in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allows remote authenticated… Patch early 4.0 medium 2.8% 2013-09-05
CVE-2012-3838 EXP Gekko before 1.2.0 allows remote attackers to obtain the installation path via a direct request to (1) admin/templates/babygekko/index.php or (2) temp… Patch early 5.0 medium 2.8% 2012-07-03
CVE-2007-5782 EXP Directory traversal vulnerability in dl.php in FireConfig 0.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter… Patch early 5.0 medium 2.8% 2007-11-01
CVE-2007-5813 EXP Multiple directory traversal vulnerabilities in download.php in ISPworker 1.21 allow remote attackers to read arbitrary files via a .. (dot dot) in th… Patch early 5.0 medium 2.8% 2007-11-05
CVE-2007-6215 EXP Multiple directory traversal vulnerabilities in play.php in Web-MeetMe 3.0.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the… Patch early 5.0 medium 2.8% 2007-12-04
CVE-2007-6368 EXP Directory traversal vulnerability in index.php in ezContents 1.4.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the link para… Patch early 5.0 medium 2.8% 2007-12-15
← previous page 193 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt