peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,999 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

207,510 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-4382 EXP CounterPath X-Lite 3.0 34025, and possibly eyeBeam, allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message witho… Patch early 5.0 medium 3.1% 2007-08-17
CVE-2004-1215 EXP Kreed 1.05 and earlier allows remote attackers to cause a denial of service (server disconnect) via a long UDP packet, which causes a "message too lon… Patch early 5.0 medium 3.1% 2005-01-10
CVE-2004-1216 EXP The scripts that handle players in Kreed 1.05 and earlier allow remote attackers to cause a denial of service (server freeze) via a long (1) nickname… Patch early 5.0 medium 3.1% 2005-01-10
CVE-2005-0382 EXP Breed patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via an empty UDP packet, which triggers a null dere… Patch early 5.0 medium 3.1% 2005-05-02
CVE-2000-0570 EXP FirstClass Internet Services server 5.770, and other versions before 6.1, allows remote attackers to cause a denial of service by sending an email wit… Patch early 5.0 medium 3.1% 2000-06-27
CVE-2008-5956 EXP Wbstreet (aka PHPSTREET Webboard) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers… Patch early 5.0 medium 3.1% 2009-01-23
CVE-2008-4875 EXP Directory traversal vulnerability in the web server in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote authen… Patch early 6.8 medium 3.1% 2008-11-01
CVE-2006-2099 EXP Directory traversal vulnerability in UltraISO 8.0.0.1392 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO i… Patch early 5.0 medium 3.1% 2006-04-29
CVE-2006-2101 EXP Directory traversal vulnerability in WinISO 5.3 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image. Patch early 5.0 medium 3.1% 2006-04-29
CVE-2015-2803 EXP SQL injection vulnerability in mod1/index.php in the Akronymmanager (sb_akronymmanager) extension before 7.0.0 for TYPO3 allows remote authenticated u… Patch early 6.0 medium 3.1% 2015-06-17
CVE-2006-0244 EXP Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote attackers to include arbitrary files via a .. (dot dot) and tra… Patch early 5.0 medium 3.1% 2006-01-18
CVE-2006-0355 EXP Helmsman Research (aka CoolUtils) HomeFtp 1.1 allows remote attackers to cause an unspecified denial of service via a long USER command combined with… Patch early 5.0 medium 3.1% 2006-01-22
CVE-2006-0357 EXP Grant Averett Cerberus FTP Server 2.32, and possibly earlier versions, allows remote attackers to cause an unspecified denial of service via a long st… Patch early 5.0 medium 3.1% 2006-01-22
CVE-2004-1919 EXP The hash_strcmp function in hasch.c in Crackalaka 1.0.8 allows remote attackers to cause a denial of service (crash) via large malformed strings. Patch early 5.0 medium 3.1% 2004-04-09
CVE-2005-0779 EXP PlatinumFTP 1.0.18, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via multiple connection attempt… Patch early 5.0 medium 3.1% 2005-05-02
CVE-2005-1603 EXP NiteEnterprises Remote File Manager 1.0 allows remote attackers to cause a denial of service (crash) via a crafted string to TCP port 7080. Patch early 5.0 medium 3.1% 2005-05-16
CVE-2002-1911 EXP ZoneAlarm Pro 3.0 and 3.1, when configured to block all traffic, allows remote attackers to cause a denial of service (CPU and memory consumption) via… Patch early 5.0 medium 3.1% 2002-12-31
CVE-2004-0282 EXP Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disconnecting from the server. Patch early 5.0 medium 3.1% 2004-11-23
CVE-2004-0295 EXP TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection. Patch early 5.0 medium 3.1% 2004-11-23
CVE-1999-0715 EXP Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook en… Patch early 4.6 medium 3.1% 1999-05-20
CVE-2007-5637 EXP The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and oth… Patch early 4.3 medium 3.1% 2007-10-23
CVE-2006-0784 EXP D-Link DWL-G700AP with firmware 2.00 and 2.01 allows remote attackers to cause a denial of service (CAMEO HTTP service crash) via a request composed o… Patch early 5.0 medium 3.1% 2006-02-19
CVE-2001-0304 EXP Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL request. Patch early 5.0 medium 3.1% 2001-05-03
CVE-2007-4327 EXP Multiple PHP remote file inclusion vulnerabilities in File Uploader 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[r… Patch early 6.8 medium 3.1% 2007-08-14
CVE-2002-1966 EXP Directory traversal vulnerability in magiccard.cgi in My Postcards Platinum 5.0 and 6.0 allows remote attackers to read arbitrary files via a .. (dot… Patch early 5.0 medium 3.1% 2002-12-31
CVE-2006-6872 EXP Directory traversal vulnerability in mod.php in eNdonesia 8.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter. Patch early 5.0 medium 3.1% 2006-12-31
CVE-2005-0479 EXP Directory traversal vulnerability in ComGetLogFile.php3 for TrackerCam 5.12 and earlier allows remote attackers to read arbitrary files via ".." seque… Patch early 5.0 medium 3.1% 2005-03-30
CVE-2008-4754 EXP SQL injection vulnerability in forum.php in Scripts for Sites (SFS) Ez Forum allows remote attackers to execute arbitrary SQL commands via the forum p… Patch early 5.8 medium 3.1% 2008-10-27
CVE-2006-1147 EXP The Com_sprintf function in q_shared.c in Alien Arena 2006 Gold Edition 5.00 does not properly NULL terminate certain long strings, which allows remot… Patch early 4.0 medium 3.1% 2006-03-10
CVE-2008-6785 EXP Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by uploading a file with an executable… Patch early 6.8 medium 3.1% 2009-05-01
← previous page 233 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt