peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,011 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

321,002 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-2059 EXP Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SearchFor par… Patch early 5.0 medium 8.8% 2004-12-31
CVE-2006-7136 EXP Multiple PHP remote file inclusion vulnerabilities in PHP Poll Creator (phpPC) 1.04 and earlier allow remote attackers to execute arbitrary PHP code v… Patch early 10.0 high 8.8% 2007-03-07
CVE-2002-0288 EXP Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP req… Patch early 5.0 medium 8.8% 2002-05-31
CVE-2005-3640 EXP Multiple buffer overflows in the IMAP Groupware Mail server of Floosietek FTGate (FTGate4) 4.1 allow remote attackers to execute arbitrary code via lo… Patch early 10.0 high 8.8% 2005-11-16
CVE-2017-11456 EXP Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configura… Patch early 7.5 high 8.8% 2017-07-19
CVE-2009-1092 EXP Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR systems allows remote attackers to… Patch early 9.3 high 8.8% 2009-03-25
CVE-2014-9094 EXP Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress… Patch early 4.3 medium 8.8% 2014-11-26
CVE-2026-3576 EXP The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions… Patch early 7.2 high 8.8% 2026-07-11
CVE-2006-6958 EXP Multiple PHP remote file inclusion vulnerabilities in phpBlueDragon 2.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the vsDrag… Patch early 7.5 high 8.8% 2007-01-29
CVE-2007-1044 EXP Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name a… Patch early 5.0 medium 8.8% 2007-02-21
CVE-2006-2739 EXP PHP remote file inclusion vulnerability in footers.php in Epicdesigns tinyBB 0.3, when register_globals is enabled, allows remote attackers to execute… Patch early 5.1 medium 8.8% 2006-06-01
CVE-2010-0718 EXP Buffer overflow in Microsoft Windows Media Player 9 and 11.0.5721.5145 allows remote attackers to cause a denial of service (divide-by-zero error and… Patch early 4.3 medium 8.8% 2010-02-26
CVE-2005-3262 EXP Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE… Patch early 7.5 high 8.8% 2005-10-20
CVE-2014-1222 EXP Directory traversal vulnerability in kcfinder/browse.php in Vtiger CRM before 6.0.0 Security patch 1 allows remote authenticated users to read arbitra… Patch early 4.0 medium 8.8% 2014-08-12
CVE-2017-10309 EXP Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u144 and 9. Ea… Patch early 7.1 high 8.8% 2017-10-19
CVE-2009-0389 EXP Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attackers to (1) create and overwri… Patch early 9.3 high 8.8% 2009-02-02
CVE-2019-12323 EXP The HC.Server service in Hosting Controller HC10 10.14 allows an Invalid Pointer Write DoS. Patch early 7.5 high 8.8% 2019-06-24
CVE-2004-1102 EXP MailPost 5.1.1sv, and possibly earlier versions, displays a different error message depending on whether the requested file exists or not, which allow… Patch early 5.0 medium 8.8% 2005-01-10
CVE-2019-20354 EXP The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user) to download arbitrary files f… Patch early 4.3 medium 8.8% 2020-01-06
CVE-2005-3927 EXP Multiple directory traversal vulnerabilities in GuppY 4.5.9 and earlier allow remote attackers to read and include arbitrary files via (1) the meskin… Patch early 6.4 medium 8.8% 2005-11-30
CVE-2006-1213 EXP JiRo's Banner System Experience and Professional 1.0 and earlier allows remote attackers to bypass access restrictions and gain privileges via a direc… Patch early 7.5 high 8.8% 2006-03-14
CVE-2021-31762 EXP Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse s… Patch early 8.8 high 8.8% 2021-04-25
CVE-2009-1828 EXP Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN ele… Patch early 5.0 medium 8.8% 2009-05-29
CVE-2008-1331 EXP cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other versions, allo… Patch early 10.0 high 8.8% 2008-04-02
CVE-2007-2946 EXP Buffer overflow in a certain ActiveX control in LeadTools Raster Dialog File_D Object (LTRDFD14e.DLL) 14.5.0.44 allows remote attackers to cause a den… Patch early 10.0 high 8.8% 2007-05-31
CVE-2007-1837 EXP Multiple PHP remote file inclusion vulnerabilities in MangoBery CMS 0.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the Site_P… Patch early 7.5 high 8.8% 2007-04-03
CVE-2004-0073 EXP PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrar… Patch early 7.5 high 8.8% 2004-02-17
CVE-2011-5107 EXP Cross-site scripting (XSS) vulnerability in post_alert.php in Alert Before Your Post plugin, possibly 0.1.1 and earlier, for WordPress allows remote a… Patch early 4.3 medium 8.8% 2012-08-23
CVE-2011-5179 EXP Cross-site scripting (XSS) vulnerability in skysa-official/skysa.php in Skysa App Bar Integration plugin, possibly before 1.04, for WordPress allows r… Patch early 4.3 medium 8.8% 2012-09-20
CVE-2005-2848 EXP Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary fi… Patch early 5.0 medium 8.8% 2005-09-08
← previous page 230 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt