peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,624 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

170,408 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-5776 EXP Directory traversal vulnerability in igallery.asp in Blue-Collar Productions i-Gallery 3.4 allows remote attackers to read arbitrary files via encoded… Patch early 5.0 medium 2.7% 2007-11-01
CVE-2009-2184 EXP Absolute path traversal vulnerability in forcedownload.php in Gravy Media Photo Host 1.0.8 allows remote attackers to read arbitrary files via an enco… Patch early 5.0 medium 2.7% 2009-06-23
CVE-2012-2442 EXP Buffer overflow in the Video Manager in Nokia PC Suite 7.1.180.64 and earlier allows remote attackers to cause a denial of service via a crafted mp4 f… Patch early 4.3 medium 2.7% 2012-07-25
CVE-2012-4680 EXP Directory traversal vulnerability in the XML Server in IOServer before 1.0.19.0, when the Root Directory pathname lacks a trailing \ (backslash) chara… Patch early 4.3 medium 2.7% 2012-08-27
CVE-2013-2714 EXP Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web script or html via the 'playerI… Patch early 6.1 medium 2.7% 2020-01-28
CVE-2007-3332 EXP Directory traversal vulnerability in Satellite.php in Satel Lite for PhpNuke allows remote attackers to read arbitrary files via a .. (dot dot) sequen… Patch early 5.0 medium 2.7% 2007-06-21
CVE-2009-3123 EXP Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitrary files via a .. (dot dot) i… Patch early 5.0 medium 2.7% 2009-09-09
CVE-2009-3912 EXP Directory traversal vulnerability in index.php in TFTgallery 0.13 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash)… Patch early 5.0 medium 2.7% 2009-11-09
CVE-2009-4434 EXP Directory traversal vulnerability in index.php in IDevSpot iSupport 1.8 and earlier allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 5.0 medium 2.7% 2009-12-28
CVE-2018-10118 EXP Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI, related to plugins/box/pages… Patch early 4.8 medium 2.7% 2018-04-16
CVE-2007-1459 EXP Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute arbitrary PHP code via a URL… Patch early 6.8 medium 2.7% 2007-03-14
CVE-2008-3295 EXP Cross-site scripting (XSS) vulnerability in modules/system/admin.php in XOOPS 2.0.18.1 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 2.7% 2008-07-25
CVE-2009-5019 EXP Web Wiz NewsPad stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database… Patch early 5.0 medium 2.7% 2010-12-01
CVE-2005-1398 EXP phpcart.php in PHPCart 3.2 allows remote attackers to change product price information by modifying the (1) price or (2) postage parameters. NOTE: it… Patch early 5.0 medium 2.7% 2005-05-03
CVE-2013-6787 EXP SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the non-encrypte… Patch early 6.0 medium 2.7% 2013-12-05
CVE-2007-6404 EXP Directory traversal vulnerability in Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to read arbitrary files v… Patch early 5.0 medium 2.7% 2007-12-17
CVE-2006-6035 EXP Cross-site scripting (XSS) vulnerability in list.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via… Patch early 6.8 medium 2.7% 2006-11-22
CVE-2012-5453 EXP SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arbitrary SQL… Patch early 6.5 medium 2.7% 2012-10-22
CVE-2006-1039 EXP SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive aut… Patch early 6.4 medium 2.7% 2006-03-07
CVE-2007-0056 EXP Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote attackers to inject arbitrary web… Patch early 6.8 medium 2.7% 2007-01-04
CVE-2008-7021 EXP Unrestricted file upload vulnerability in editlogo.php in AvailScript Jobs Portal Script allows remote authenticated users to execute arbitrary code b… Patch early 6.0 medium 2.7% 2009-08-21
CVE-2007-2560 EXP Directory traversal vulnerability in theme/acgv.php in ACGVannu 1.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in… Patch early 5.0 medium 2.7% 2007-05-09
CVE-2007-2566 EXP The SaveBarCode function in the Taltech Tal Bar Code ActiveX control allows remote attackers to cause a denial of service (disk consumption) by upload… Patch early 5.0 medium 2.7% 2007-05-09
CVE-2001-1075 EXP poprelayd script before 2.0 in Cobalt RaQ3 servers allows remote attackers to bypass authentication for relaying by causing a "POP login by user" stri… Patch early 5.0 medium 2.7% 2001-07-04
CVE-2009-4192 EXP Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary files via a .… Patch early 5.0 medium 2.7% 2009-12-03
CVE-2010-1309 EXP Directory traversal vulnerability in Irmin CMS (formerly Pepsi CMS) 0.6 BETA2 allows remote attackers to read arbitrary files via a .. (dot dot) in th… Patch early 5.0 medium 2.7% 2010-04-08
CVE-2019-14748 EXP An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries.… Patch early 5.4 medium 2.7% 2019-08-07
CVE-2014-8652 EXP Elipse E3 3.x and earlier allows remote attackers to cause a denial of service (application crash and plant outage) via a rapid series of HTTP request… Patch early 5.0 medium 2.7% 2014-11-10
CVE-2008-5431 EXP Teamtek Universal FTP Server 1.0.44 allows remote attackers to cause a denial of service via (1) a certain CWD command, (2) a long LIST command, or (3… Patch early 5.0 medium 2.7% 2008-12-11
CVE-2008-6674 EXP mailPage.asp in QuickerSite 1.8.5 allows remote attackers to flood e-mail accounts with messages via a large number of requests with a modified sEmail… Patch early 5.0 medium 2.7% 2009-04-08
← previous page 198 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt