peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,624 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

170,408 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-1162 EXP Directory traversal vulnerability in Nodez 4.6.1.1 and earlier allows remote attackers to read or include arbitrary PHP files via a .. (dot dot) in t… Patch early 5.1 medium 2.8% 2006-03-12
CVE-2006-4979 EXP Direct static code injection vulnerability in cfgphpquiz/install.php in Walter Beschmout PhpQuiz 1.2 and earlier allows remote attackers to inject arb… Patch early 5.0 medium 2.8% 2006-09-25
CVE-2005-0506 EXP The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows loc… Patch early 5.0 medium 2.8% 2005-03-14
CVE-2012-5243 EXP functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request. Patch early 5.0 medium 2.8% 2014-10-21
CVE-2008-5209 EXP Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 5.0 medium 2.8% 2008-11-24
CVE-2009-1602 EXP Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outage or CPU consumption) via mul… Patch early 5.0 medium 2.8% 2009-05-11
CVE-2007-3159 EXP http.c in MiniWeb Http Server 0.8.x allows remote attackers to cause a denial of service (application crash) via a negative value in the Content-Lengt… Patch early 5.0 medium 2.8% 2007-06-11
CVE-2014-8775 EXP MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote a… Patch early 5.0 medium 2.8% 2014-12-03
CVE-2015-5075 EXP Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of administrators fo… Patch early 6.8 medium 2.8% 2015-09-29
CVE-2007-2252 EXP Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive information v… Patch early 5.0 medium 2.8% 2007-04-25
CVE-2018-0895 EXP The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold… Patch early 4.7 medium 2.8% 2018-03-14
CVE-2006-2397 EXP Multiple cross-site scripting (XSS) vulnerabilities in GPhotos 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (… Patch early 5.8 medium 2.8% 2006-05-16
CVE-2008-7084 EXP Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary files via a .… Patch early 5.0 medium 2.8% 2009-08-26
CVE-2009-4809 EXP Directory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to read arbitrary files via a ..… Patch early 5.0 medium 2.8% 2010-04-23
CVE-2010-2848 EXP Directory traversal vulnerability in assets/captcha/includes/alikon/playcode.php in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for… Patch early 5.0 medium 2.8% 2010-07-25
CVE-2008-0703 EXP Multiple directory traversal vulnerabilities in sflog! 0.96 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) permalink or… Patch early 5.0 medium 2.8% 2008-02-12
CVE-2008-1415 EXP Directory traversal vulnerability in index.php in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to read arbitrary files via "../.… Patch early 5.0 medium 2.8% 2008-03-20
CVE-2008-4759 EXP Directory traversal vulnerability in download.php in BuzzyWall 1.3.1 allows remote attackers to read arbitrary local files via a .. (dot dot) in the i… Patch early 5.0 medium 2.8% 2008-10-28
CVE-2008-3676 EXP Unspecified vulnerability in the IMAP server in hMailServer 4.4.1 allows remote authenticated users to cause a denial of service (resource exhaustion… Patch early 4.3 medium 2.8% 2008-08-14
CVE-2013-5757 EXP Absolute path traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a full pathname in… Patch early 4.0 medium 2.8% 2014-08-03
CVE-2006-3602 EXP Directory traversal vulnerability in jscripts/tiny_mce/tiny_mce_gzip.php in FarsiNews 3.0 BETA 1 allows remote attackers to include arbitrary files vi… Patch early 5.0 medium 2.8% 2006-07-18
CVE-2004-2017 EXP Multiple cross-site scripting (XSS) vulnerabilities in Turbo Traffic Trader C (TTT-C) 1.0 allow remote attackers to inject arbitrary HTML or web scrip… Patch early 4.3 medium 2.8% 2004-12-31
CVE-2006-2491 EXP Cross-site scripting (XSS) vulnerability in (1) index.php and (2) bmc/admin.php in BoastMachine (bMachine) 3.1 and earlier allows remote attackers to… Patch early 6.8 medium 2.8% 2006-05-19
CVE-2017-7725 EXP concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation o… Patch early 6.1 medium 2.8% 2017-04-13
CVE-2007-0364 EXP Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com INDEXU 5.3 and earlier allow remote attackers to inject arbitrary web script or H… Patch early 4.3 medium 2.8% 2007-01-19
CVE-2005-2324 EXP Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the searchtype… Patch early 4.3 medium 2.8% 2005-07-19
CVE-2007-6502 EXP Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel… Patch early 5.5 medium 2.8% 2007-12-20
CVE-2001-0202 EXP Picserver web server allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTP GET request. Patch early 5.0 medium 2.8% 2001-05-03
CVE-2006-5767 EXP PHP remote file inclusion vulnerability in includes/xhtml.php in Drake CMS 0.2.2 alpha rev.846 and earlier allows remote attackers to execute arbitrar… Patch early 6.8 medium 2.7% 2006-11-06
CVE-2006-4671 EXP PHP remote file inclusion vulnerability in headlines.php in Fantastic News 2.1.4, and possibly earlier, allows remote attackers to execute arbitrary P… Patch early 6.8 medium 2.7% 2006-09-11
← previous page 197 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt