peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,108 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

321,115 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2000-0906 EXP Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to read arbitrary files via a .. (d… Patch early 5.0 medium 8.6% 2000-12-19
CVE-2002-0955 EXP Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execute arbitra… Patch early 7.5 high 8.6% 2002-10-04
CVE-2010-1132 EXP The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute… Patch early 9.3 high 8.5% 2010-03-27
CVE-2007-2536 EXP PicoZip allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous fil… Patch early 7.8 high 8.5% 2007-05-09
CVE-2015-1482 EXP Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connecti… Patch early 5.0 medium 8.5% 2015-02-04
CVE-2014-3437 EXP The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requ… Patch early 7.5 high 8.5% 2014-11-07
CVE-2002-2314 EXP Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which cause… Patch early 5.0 medium 8.5% 2002-12-31
CVE-2006-3970 EXP PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows remote attackers to execute arb… Patch early 7.5 high 8.5% 2006-08-01
CVE-2005-2455 EXP Greasemonkey before 0.3.5 allows remote web servers to (1) read arbitrary files via a GET request to a file:// URL in the GM_xmlhttpRequest API functi… Patch early 5.0 medium 8.5% 2005-08-04
CVE-2012-5329 EXP Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application crash) via a long string in an A… Patch early 4.0 medium 8.5% 2012-10-08
CVE-2001-0495 EXP Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack. Patch early 5.0 medium 8.5% 2001-06-27
CVE-2008-4409 EXP libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a de… Patch early 5.0 medium 8.5% 2008-10-03
CVE-2010-4617 EXP Directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers to read arbitrary files via dir… Patch early 6.8 medium 8.5% 2010-12-29
CVE-2000-0187 EXP EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metachar… Patch early 7.5 high 8.5% 2000-02-27
CVE-2008-0396 EXP Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Ente… Patch early 7.8 high 8.5% 2008-01-23
CVE-2009-4501 EXP The zbx_get_next_field function in libs/zbxcommon/str.c in Zabbix Server before 1.6.8 allows remote attackers to cause a denial of service (crash) via… Patch early 5.0 medium 8.5% 2009-12-31
CVE-2008-1262 EXP The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote… Patch early 10.0 high 8.5% 2008-03-10
CVE-2007-2364 EXP Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the ro… Patch early 7.5 high 8.5% 2007-04-30
CVE-2014-0242 EXP mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type h… Patch early 7.5 high 8.5% 2019-12-09
CVE-2006-1831 EXP Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows remote attackers to execute a… Patch early 7.5 high 8.5% 2006-04-19
CVE-2007-0684 EXP PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute arbitrary PHP code via a URL i… Patch early 7.5 high 8.5% 2007-02-03
CVE-2007-4976 EXP Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to in… Patch early 6.5 medium 8.5% 2007-09-19
CVE-2010-3203 EXP Directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot… Patch early 5.0 medium 8.5% 2010-09-03
CVE-2014-0329 EXP The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remote attacker… Patch early 9.3 high 8.5% 2014-02-04
CVE-2012-2441 EXP RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes i… Patch early 8.5 high 8.5% 2012-04-28
CVE-2008-0151 EXP Heap-based buffer overflow in Foxit WAC Server 2.1.0.910, 2.0 Build 3503, and earlier allows remote attackers to cause a denial of service (crash) and… Patch early 10.0 high 8.5% 2008-01-09
CVE-2018-1038 EXP The Windows kernel in Windows 7 SP1 and Windows Server 2008 R2 SP1 allows an elevation of privilege vulnerability due to the way it handles objects in… Patch early 7.8 high 8.5% 2018-04-02
CVE-2017-9746 EXP The disassemble_bytes function in objdump.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application… Patch early 7.8 high 8.5% 2017-06-19
CVE-2017-9749 EXP The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer overflow and application cras… Patch early 7.8 high 8.5% 2017-06-19
CVE-2010-3313 EXP phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly… Patch early 7.5 high 8.5% 2010-09-22
← previous page 235 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt