peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,908 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

207,499 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-1466 EXP The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code of NtDecision script files with… Patch early 5.0 medium 3.3% 2012-03-19
CVE-2002-1945 EXP Buffer overflow in SmartMail Server 1.0 Beta 10 allows remote attackers to cause a denial of service (crash) via a long request to (1) TCP port 25 (SM… Patch early 5.0 medium 3.3% 2002-12-31
CVE-2003-1158 EXP Multiple buffer overflows in the FTP service in Plug and Play Web Server 1.0002c allow remote attackers to cause a denial of service (crash) via long… Patch early 5.0 medium 3.3% 2003-12-31
CVE-2017-6443 EXP Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web script or HTML via the W_AD1 pa… Patch early 6.1 medium 3.3% 2017-03-15
CVE-2006-6203 EXP Directory traversal vulnerability in startdown.php in the Flyspray ME 1.0.1 (com_flyspray) component for Mambo allows remote attackers to read arbitra… Patch early 5.0 medium 3.3% 2006-12-01
CVE-2012-1258 EXP cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow… Patch early 6.5 medium 3.3% 2020-01-09
CVE-2008-3208 EXP Simple DNS Plus 4.1, 5.0, and possibly other versions before 5.1.101 allows remote attackers to cause a denial of service via multiple DNS reply packe… Patch early 5.0 medium 3.3% 2008-07-18
CVE-2013-3514 EXP Multiple directory traversal vulnerabilities in OpenX before 2.8.10 revision 82710 allow remote administrators to read arbitrary files via a .. (dot d… Patch early 4.3 medium 3.3% 2014-05-14
CVE-2008-2648 EXP Unrestricted file upload vulnerability in upload/uploader.html in meBiblio 0.4.7 allows remote attackers to execute arbitrary code by uploading a .php… Patch early 6.8 medium 3.3% 2008-06-10
CVE-2008-6617 EXP Unrestricted file upload vulnerability in adm/visual/upload.php in SiteXS CMS 0.1.1 allows remote attackers to execute arbitrary code by uploading a f… Patch early 6.8 medium 3.3% 2009-04-06
CVE-2008-6814 EXP Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earlier for Mambo allows remote at… Patch early 6.8 medium 3.3% 2009-05-28
CVE-2008-7157 EXP Unrestricted file upload vulnerability in EkinBoard 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading an avatar file wi… Patch early 6.8 medium 3.3% 2009-09-02
CVE-2007-0143 EXP Multiple PHP remote file inclusion vulnerabilities in NUNE News Script 2.0pre2 allow remote attackers to execute arbitrary PHP code via a URL in the c… Patch early 6.8 medium 3.3% 2007-01-09
CVE-2022-41358 EXP A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a cra… Patch early 5.4 medium 3.3% 2022-10-20
CVE-2004-1923 EXP Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (2… Patch early 5.0 medium 3.3% 2004-04-11
CVE-2001-0038 EXP Offline Explorer 1.4 before Service Release 2 allows remote attackers to read arbitrary files by specifying the drive letter (e.g. C:) in the requeste… Patch early 5.0 medium 3.3% 2001-02-16
CVE-2001-0452 EXP BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls com… Patch early 5.0 medium 3.3% 2001-06-27
CVE-2007-5386 EXP Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allo… Patch early 4.3 medium 3.3% 2007-10-12
CVE-2007-5589 EXP Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.11.1.2 allow remote attackers to inject arbitrary web script or HTML via ce… Patch early 4.3 medium 3.3% 2007-10-19
CVE-2007-1968 EXP PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP co… Patch early 6.8 medium 3.3% 2007-04-11
CVE-2014-7177 EXP XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a crafted xml docume… Patch early 4.0 medium 3.3% 2014-10-31
CVE-2008-0464 EXP Directory traversal vulnerability in archiv.cgi in absofort aconon Mail 2007 Enterprise SQL 11.7.0 and Mail 2004 Enterprise SQL 11.5.1 allows remote a… Patch early 5.0 medium 3.3% 2008-01-25
CVE-2008-0790 EXP Directory traversal vulnerability in ipdsserver.exe in Intermate WinIPDS 3.3 G52-33-021 allows remote attackers to read arbitrary files via a .. (dot… Patch early 5.0 medium 3.3% 2008-02-15
CVE-2006-1114 EXP Multiple directory traversal vulnerabilities in Loudblog before 0.42 allow remote attackers to read or include arbitrary files via a .. (dot dot) and… Patch early 6.4 medium 3.3% 2006-03-09
CVE-2012-3551 EXP Cross-site scripting (XSS) vulnerability in crowbar_framework/app/views/support/index.html.haml in the Crowbar barclamp in Crowbar, possibly 1.4 and e… Patch early 4.3 medium 3.3% 2012-09-05
CVE-2003-1371 EXP Nuked-Klan 1.3b, and possibly earlier versions, allows remote attackers to obtain sensitive server information via an op parameter set to phpinfo for… Patch early 4.3 medium 3.3% 2003-12-31
CVE-2007-0335 EXP Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .… Patch early 6.8 medium 3.3% 2007-01-18
CVE-2002-0209 EXP Nortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled, allows remote attackers to de… Patch early 5.0 medium 3.3% 2002-05-16
CVE-2008-0760 EXP Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.0.4.0 and earlier, allows remo… Patch early 5.0 medium 3.3% 2008-02-13
CVE-2000-0897 EXP Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL that references a directory tha… Patch early 5.0 medium 3.3% 2001-01-09
← previous page 222 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt