peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,553 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

207,229 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-2528 EXP Cross-site scripting (XSS) vulnerability in sresult.exe in Webcam Watchdog 4.0.1a allows remote attackers to inject arbitrary web script or HTML via t… Patch early 4.3 medium 3.9% 2004-12-31
CVE-2007-5064 EXP Buffer overflow in a certain ActiveX control in Xunlei Web Thunder 5.6.9.344, possibly the DapPlayer ActiveX control in DapPlayer_Now.dll, allows remo… Patch early 6.8 medium 3.9% 2007-09-24
CVE-2008-0479 EXP Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz NewsPad 1.02 allows remote attackers to list arbitrary directories, and .txt and… Patch early 5.0 medium 3.9% 2008-01-29
CVE-2008-0480 EXP Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary directories, and .txt and .zi… Patch early 5.0 medium 3.9% 2008-01-29
CVE-2008-0481 EXP Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .… Patch early 5.0 medium 3.9% 2008-01-29
CVE-2007-0707 EXP Stack-based buffer overflow in GOM Player 2.0.12.3375 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI… Patch early 6.8 medium 3.9% 2007-02-04
CVE-2017-13754 EXP Cross-site scripting (XSS) vulnerability in the "advanced settings - time server" module in Wibu-Systems CodeMeter before 6.50b allows remote attacker… Patch early 5.4 medium 3.9% 2017-09-07
CVE-2010-2543 EXP Cross-site scripting (XSS) vulnerability in include/top_graph_header.php in Cacti before 0.8.7g allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 3.9% 2010-08-23
CVE-2006-2254 EXP Buffer overflow in filecpnt.exe in FileCOPA 1.01 allows remote attackers to cause a denial of service (application crash) via a username with a large… Patch early 5.0 medium 3.9% 2006-05-09
CVE-2001-0821 EXP The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive d… Patch early 5.0 medium 3.9% 2001-12-06
CVE-2026-44262 EXP Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints are publicly accessible and vali… Patch early 9.4 critical 3.9% 2026-05-12
CVE-2002-1445 EXP Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent pa… Patch early 4.3 medium 3.9% 2002-08-12
CVE-2015-2517 EXP The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012… Patch early 6.9 medium 3.9% 2015-09-09
CVE-2007-4711 EXP Multiple cross-site scripting (XSS) vulnerabilities in Toms Gaestebuch 1.00 allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 4.3 medium 3.9% 2007-09-05
CVE-2011-5211 EXP Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 3.9% 2012-10-22
CVE-2006-2027 EXP Buffer overflow in Unicode processing in the logging functionality in Pablo Software Solutions Quick 'n Easy FTP Server Professional and Lite, probabl… Patch early 6.5 medium 3.9% 2006-04-26
CVE-2011-1939 EXP SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction P… Patch early 9.8 critical 3.9% 2019-11-26
CVE-2018-10068 EXP The jDownloads extension before 3.2.59 for Joomla! has XSS. Patch early 6.1 medium 3.9% 2018-04-12
CVE-2017-11548 EXP The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service (memory corruption) via a cr… Patch early 5.5 medium 3.9% 2017-07-31
CVE-2002-1042 EXP Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Win… Patch early 5.0 medium 3.9% 2002-10-04
CVE-2000-1036 EXP Directory traversal vulnerability in Extent RBS ISP web server allows remote attackers to read sensitive information via a .. (dot dot) attack on the… Patch early 5.0 medium 3.9% 2000-12-11
CVE-2013-3661 EXP The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2… Patch early 4.9 medium 3.9% 2013-05-24
CVE-2006-4294 EXP Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the f… Patch early 5.0 medium 3.8% 2006-09-09
CVE-2006-4062 EXP PHP remote file inclusion vulnerability in usr/extensions/get_tree.inc.php in Dmitry Sheiko SAPID Shop 1.2 and earlier allows remote attackers to exec… Patch early 5.1 medium 3.8% 2006-08-10
CVE-2023-32750 EXP Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The… Patch early 6.5 medium 3.8% 2023-06-08
CVE-2013-3575 EXP hpdiags/frontend2/help/pageview.php in HP Insight Diagnostics 9.4.0.4710 does not properly restrict PHP include or require statements, which allows re… Patch early 5.0 medium 3.8% 2013-06-14
CVE-2012-2939 EXP Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute arbitrary code by uploading a… Patch early 6.5 medium 3.8% 2012-05-27
CVE-2006-1214 EXP UnrealIRCd 3.2.3 allows remote attackers to cause an unspecified denial of service by causing a linked server to send malformed TKL Q:Line commands, a… Patch early 5.0 medium 3.8% 2006-03-14
CVE-2007-0113 EXP Buffer overflow in Packeteer PacketShaper PacketWise 8.x allows remote authenticated users to cause a denial of service (reset or reboot) via (1) a lo… Patch early 6.8 medium 3.8% 2007-01-09
CVE-2013-7233 EXP Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows r… Patch early 6.8 medium 3.8% 2013-12-30
← previous page 198 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt