peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,599 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

170,406 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-0882 EXP Directory traversal vulnerability in include.php in Noah's Classifieds 1.3 allows remote attackers to include arbitrary local files via the otherTempl… Patch early 5.0 medium 2.8% 2006-02-24
CVE-2006-4989 EXP Patrick Michaelis Wili-CMS allows remote attackers to obtain sensitive information via a direct request for (1) thumbnail.php, (2) functions/admin/all… Patch early 5.0 medium 2.8% 2006-09-26
CVE-2007-3398 EXP LiteWEB 2.7 allows remote attackers to cause a denial of service (hang) via a large number of requests for nonexistent pages. Patch early 5.0 medium 2.8% 2007-06-26
CVE-2006-0174 EXP Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intrane… Patch early 4.0 medium 2.8% 2006-01-11
CVE-2013-4015 EXP Microsoft Internet Explorer 6 through 10 allows local users to bypass the elevation policy check in the (1) Protected Mode or (2) Enhanced Protected M… Patch early 6.9 medium 2.8% 2013-07-26
CVE-2012-1009 EXP NetSarang Xlpd 4 Build 0100 and NetSarang Xmanager Enterprise 4 Build 0186 allow remote attackers to cause a denial of service (daemon crash) via a ma… Patch early 5.0 medium 2.8% 2012-02-14
CVE-2008-6815 EXP mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a database backup by making a di… Patch early 5.0 medium 2.8% 2009-05-28
CVE-2013-7209 EXP Cross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote attackers to hijack the authenticati… Patch early 6.8 medium 2.8% 2013-12-30
CVE-2012-6272 EXP Multiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage Server Administrator 6.5.0.1, 7.0.0.1, and 7.1.0.1 allow remote attackers to in… Patch early 4.3 medium 2.8% 2013-01-25
CVE-2009-3789 EXP Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the last_mes… Patch early 4.3 medium 2.8% 2009-10-26
CVE-2009-2398 EXP Directory traversal vulnerability in test/index.php in PHP-Sugar 0.80 allows remote attackers to read arbitrary files via a ..// (dot dot slash slash)… Patch early 5.0 medium 2.8% 2009-07-09
CVE-2008-0452 EXP Directory traversal vulnerability in articles.php in Siteman 1.1.9 allows remote attackers to read arbitrary files via directory traversal sequences i… Patch early 5.0 medium 2.8% 2008-01-25
CVE-2008-0338 EXP Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary… Patch early 5.0 medium 2.8% 2008-01-17
CVE-2001-1137 EXP D-Link DI-704 Internet Gateway firmware earlier than V2.56b6 allows remote attackers to cause a denial of service (reboot) via malformed IP datagram f… Patch early 5.0 medium 2.8% 2001-09-06
CVE-2007-4964 EXP WinImage 8.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via an invalid BPB_BytsPerSec field in the header of a… Patch early 5.0 medium 2.8% 2007-09-18
CVE-2007-0300 EXP PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 6.8 medium 2.8% 2007-01-18
CVE-2007-0580 EXP PHP remote file inclusion vulnerability in menu.php in Foro Domus 2.10 allows remote attackers to execute arbitrary PHP code via a URL in the sesion_i… Patch early 6.8 medium 2.8% 2007-01-30
CVE-2007-1108 EXP PHP remote file inclusion vulnerability in index.php in Christian Schneider CS-Gallery 2.0 and earlier allows remote attackers to execute arbitrary PH… Patch early 6.8 medium 2.8% 2007-02-26
CVE-2006-3685 EXP PHP remote file inclusion vulnerability in CzarNews 1.12 through 1.14 allows remote attackers to execute arbitrary PHP code via a URL in the tpath par… Patch early 5.1 medium 2.8% 2006-07-21
CVE-2003-1427 EXP Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as th… Patch early 6.4 medium 2.8% 2003-12-31
CVE-2009-5093 EXP Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in t… Patch early 5.0 medium 2.8% 2011-09-12
CVE-2008-4181 EXP Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Registe… Patch early 6.8 medium 2.8% 2008-09-23
CVE-2006-4068 EXP The pswd.js script relies on the client to calculate whether a username and password match hard-coded hashed values for a server, and uses a hashing s… Patch early 5.0 medium 2.8% 2006-08-10
CVE-2006-0687 EXP process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote attackers to include arb… Patch early 5.0 medium 2.8% 2006-02-15
CVE-2012-1664 EXP Multiple cross-site scripting (XSS) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to inject arbitrary web script or… Patch early 4.3 medium 2.8% 2015-05-20
CVE-2014-4717 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote attackers to… Patch early 6.8 medium 2.8% 2014-07-03
CVE-2009-1514 EXP Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a throw statement w… Patch early 5.0 medium 2.8% 2009-05-04
CVE-2010-5240 EXP Multiple untrusted search path vulnerabilities in Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 allow local users to gain privileges via a Trojan hors… Patch early 6.9 medium 2.8% 2012-09-07
CVE-2007-2900 EXP Multiple PHP remote file inclusion vulnerabilities in Scallywag 2005-04-25 allow remote attackers to execute arbitrary PHP code via a URL in the path… Patch early 6.8 medium 2.8% 2007-05-30
CVE-2007-6585 EXP PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to execute arbitrary PHP code via… Patch early 6.8 medium 2.8% 2007-12-28
← previous page 194 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt