peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,984 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

170,623 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-3681 EXP The IOCTL 9031 (BIOCGSTATS) handler in the NPF.SYS device driver in WinPcap before 4.0.1 allows local users to overwrite memory and execute arbitrary… Patch early 6.6 medium 2.4% 2007-07-11
CVE-2006-5625 EXP PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Management System (WCMS) 4.1 and earli… Patch early 5.1 medium 2.4% 2006-10-31
CVE-2005-1597 EXP Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers… Patch early 4.3 medium 2.4% 2005-05-16
CVE-2012-5350 EXP SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with certain permissions to execut… Patch early 6.0 medium 2.4% 2012-10-09
CVE-2003-0376 EXP Buffer overflow in Eudora 5.2.1 allows remote attackers to cause a denial of service (crash and failed restart) and possibly execute arbitrary code vi… Patch early 5.0 medium 2.4% 2003-06-16
CVE-2006-6756 EXP The code function in install.fct.php in Ixprim 1.2 produces a guessable value of the confidential IXP_CODE in mainfile.php, which might allow remote a… Patch early 5.1 medium 2.4% 2006-12-27
CVE-2003-1535 EXP Justice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the path in an er… Patch early 5.0 medium 2.4% 2003-12-31
CVE-2007-1475 EXP Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-… Patch early 5.4 medium 2.4% 2007-03-16
CVE-2008-0840 EXP Directory traversal vulnerability in view_member.php in Public Warehouse LightBlog 9.6 allows remote attackers to include and execute arbitrary local… Patch early 4.4 medium 2.4% 2008-02-20
CVE-2005-0477 EXP Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script v… Patch early 4.3 medium 2.4% 2005-03-30
CVE-2007-1515 EXP Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP H3 4.1.3, and possibly earlier, allow remote attackers to inject arbitrary web script… Patch early 4.3 medium 2.4% 2007-03-20
CVE-2010-3480 EXP Directory traversal vulnerability in index.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include and… Patch early 6.8 medium 2.4% 2010-09-22
CVE-2011-4519 EXP Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a craft… Patch early 4.3 medium 2.4% 2013-05-23
CVE-2011-4520 EXP Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafte… Patch early 4.3 medium 2.4% 2013-05-23
CVE-2002-2399 EXP Directory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file… Patch early 6.4 medium 2.4% 2002-12-31
CVE-2007-6475 EXP Multiple directory traversal vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot)… Patch early 6.4 medium 2.4% 2007-12-20
CVE-2007-6621 EXP Directory traversal vulnerability in joovili.images.php in Joovili 3.0.0 through 3.0.6 allows remote attackers to read arbitrary files via a .. (dot d… Patch early 6.4 medium 2.4% 2008-01-04
CVE-2007-1104 EXP PHP remote file inclusion vulnerability in top.php in PHP Module Implementation (PHP-MIP) 0.1 allows remote attackers to execute arbitrary PHP code vi… Patch early 4.3 medium 2.4% 2007-02-26
CVE-2007-5140 EXP PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in IntegraMOD Nederland 1.4.2 allows remote attackers to execute arbitra… Patch early 6.8 medium 2.4% 2007-09-28
CVE-2007-5157 EXP PHP remote file inclusion vulnerability in phfito-post.php in Alex Kocharin PHP Fidonet Tosser (PhFiTo) 1.3.0 in phpFidoNode allows remote attackers t… Patch early 6.8 medium 2.4% 2007-10-01
CVE-2007-5780 EXP PHP remote file inclusion vulnerability in pub/pub08_comments.php in teatro 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 6.8 medium 2.4% 2007-11-01
CVE-2009-0853 EXP login.php in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allows remote attackers to bypass authentication and obtain administrative access via s… Patch early 6.8 medium 2.4% 2009-03-09
CVE-2007-4647 EXP newswire/uploadmedia.cgi in 2coolcode Our Space (Ourspace) 2.0.9 allows remote attackers to upload certain files via unspecified vectors, probably inv… Patch early 5.0 medium 2.4% 2007-08-31
CVE-2008-4740 EXP Directory traversal vulnerability in templater.php in the ZZ_Templater module in TinyCMS 1.1.2, when register_globals is enabled and magic_quotes_gpc… Patch early 5.1 medium 2.4% 2008-10-27
CVE-2018-9173 EXP Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitr… Patch early 6.1 medium 2.4% 2018-04-02
CVE-2007-6582 EXP Directory traversal vulnerability in index.php in mBlog 1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter i… Patch early 6.4 medium 2.4% 2007-12-28
CVE-2006-5065 EXP PHP remote file inclusion vulnerability in libs/dbmax/mysql.php in ZoomStats 1.0.2 and earlier, when register_globals is enabled, allows remote attack… Patch early 5.1 medium 2.4% 2006-09-28
CVE-2018-0901 EXP The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold… Patch early 4.7 medium 2.4% 2018-03-14
CVE-2011-0773 EXP Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attackers to inject arbitrary web scr… Patch early 4.3 medium 2.4% 2011-02-04
CVE-1999-0683 EXP Denial of service in Gauntlet Firewall via a malformed ICMP packet. Patch early 5.0 medium 2.4% 1999-07-30
← previous page 220 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt