peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,893 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

207,492 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-15966 EXP The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php. Patch early 9.8 critical 3.4% 2017-10-29
CVE-2006-4714 EXP PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier, when register_globa… Patch early 5.1 medium 3.4% 2006-09-12
CVE-2005-2239 EXP oftpd 0.3.7 allows remote attackers to cause a denial of service via a USER command with a large number of null (\0) characters. Patch early 5.0 medium 3.4% 2005-07-12
CVE-2008-4741 EXP Directory traversal vulnerability in index.php in FAR-PHP 1.00, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via… Patch early 5.0 medium 3.4% 2008-10-27
CVE-2009-2533 EXP rmserver in RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allows remote attackers to cause a denial of service (daemon exit) via mul… Patch early 5.0 medium 3.4% 2009-07-20
CVE-2008-6929 EXP Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file wi… Patch early 6.5 medium 3.4% 2009-08-11
CVE-2009-1446 EXP Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by upl… Patch early 6.5 medium 3.4% 2009-04-27
CVE-2021-45425 EXP Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScript codes. Patch early 6.1 medium 3.4% 2021-12-28
CVE-2006-1209 EXP PHP Advanced Transfer Manager 1.00 through 1.30 stores sensitive information, including password hashes, under the web root with insufficient access c… Patch early 5.0 medium 3.4% 2006-03-14
CVE-2004-1908 EXP McFreeScan.CoMcFreeScan.1 ActiveX object in Mcafee FreeScan allows remote attackers to obtain sensitive information via the GetSpecialFolderLocation f… Patch early 5.0 medium 3.4% 2004-12-31
CVE-2005-1329 EXP owOfflineCC.asp in OneWorldStore allows remote attackers to obtain sensitive information by modifying the idOrder parameter. Patch early 5.0 medium 3.4% 2005-05-02
CVE-2019-9650 EXP An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event. Patch early 6.1 medium 3.4% 2019-03-11
CVE-2012-6500 EXP Directory traversal vulnerability in download.lib.php in Pragyan CMS 3.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot… Patch early 5.0 medium 3.4% 2013-01-12
CVE-2007-1472 EXP Variable overwrite vulnerability in groupit/base/groupit.start.inc in Groupit 2.00b5 allows remote attackers to conduct remote file inclusion attacks… Patch early 6.8 medium 3.4% 2007-03-16
CVE-2008-6930 EXP Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary code by uploading a file with an… Patch early 6.5 medium 3.4% 2009-08-11
CVE-2008-6931 EXP Unrestricted file upload vulnerability in PHPStore Job Search (aka PHPCareers) allows remote authenticated users to execute arbitrary code by uploadin… Patch early 6.5 medium 3.4% 2009-08-11
CVE-2008-7076 EXP Unrestricted file upload vulnerability in user.modify.profile.php in Kalptaru Infotech Ltd. Star Articles 6.0 allows remote authenticated users to exe… Patch early 6.5 medium 3.4% 2009-08-25
CVE-2002-1566 EXP netris 0.5, and possibly other versions before 0.52, when running with the -w (wait) option, allows remote attackers to cause a denial of service (cra… Patch early 5.0 medium 3.4% 2003-08-27
CVE-2009-2917 EXP Stack-based buffer overflow in ImTOO MPEG Encoder 3.1.53 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary co… Patch early 4.3 medium 3.4% 2009-08-21
CVE-2008-3148 EXP Stack-based buffer overflow in (1) OllyDBG 1.10 and (2) ImpREC 1.7f allows user-assisted attackers to execute arbitrary code via a crafted DLL file th… Patch early 6.8 medium 3.4% 2008-07-11
CVE-2015-7564 EXP Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id paramete… Patch early 9.8 critical 3.4% 2017-04-12
CVE-2007-0843 EXP The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allow… Patch early 4.6 medium 3.4% 2007-02-23
CVE-2007-5625 EXP Cross-site scripting (XSS) vulnerability in filename.asp in ASP Site Search SearchSimon Lite 1.0 allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 3.4% 2007-10-23
CVE-2010-4930 EXP Cross-site scripting (XSS) vulnerability in index.php in @mail Webmail before 6.2.0 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 3.4% 2011-10-09
CVE-2005-2141 EXP TCP Chat 1.0 allows remote attackers to cause a denial of service (crash) via a long string to the chat service, possibly triggering a buffer overflow… Patch early 5.0 medium 3.4% 2005-07-05
CVE-2007-4375 EXP The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versions exposes a memory compariso… Patch early 5.8 medium 3.4% 2007-08-16
CVE-2006-2767 EXP PHP remote file inclusion vulnerability in Ottoman 1.1.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via… Patch early 5.1 medium 3.4% 2006-06-02
CVE-2002-1101 EXP Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name. Patch early 5.0 medium 3.4% 2002-10-04
CVE-2003-1342 EXP Trend Micro Virus Control System (TVCS) 1.8 running with IIS allows remote attackers to cause a denial of service (memory consumption) in IIS via mult… Patch early 5.0 medium 3.4% 2003-12-31
CVE-2008-2859 EXP Unspecified vulnerability in the IMAP service in NetWin SurgeMail before 3.9g2 allows remote attackers to cause a denial of service (daemon crash) via… Patch early 5.0 medium 3.4% 2008-06-25
← previous page 219 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt