peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,173 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

321,181 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-3407 EXP Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) via a URL with a trailing encode… Patch early 5.0 medium 8.4% 2007-06-26
CVE-2007-2369 EXP Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to read arbit… Patch early 5.0 medium 8.4% 2007-04-30
CVE-2000-0109 EXP The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily g… Patch early 10.0 high 8.4% 2000-01-31
CVE-2023-4112 EXP A vulnerability was found in PHP Jabbers Shuttle Booking Software 1.0. It has been classified as problematic. This affects an unknown part of the file… Patch early 4.3 medium 8.4% 2023-08-03
CVE-2023-4113 EXP A vulnerability was found in PHP Jabbers Service Booking Script 1.0. It has been declared as problematic. This vulnerability affects unknown code of t… Patch early 4.3 medium 8.4% 2023-08-03
CVE-2023-4115 EXP A vulnerability classified as problematic has been found in PHP Jabbers Cleaning Business 1.0. Affected is an unknown function of the file /index.php.… Patch early 4.3 medium 8.4% 2023-08-03
CVE-2023-4116 EXP A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0. Affected by this vulnerability is an unknown functionality of the… Patch early 4.3 medium 8.4% 2023-08-03
CVE-2007-3934 EXP PHP remote file inclusion vulnerability in postscript/postscript.php in BBS E-Market allows remote attackers to execute arbitrary PHP code via a URL i… Patch early 7.5 high 8.4% 2007-07-21
CVE-2011-1249 EXP The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server… Patch early 7.2 high 8.4% 2011-06-16
CVE-2009-1236 EXP Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers… Patch early 10.0 high 8.4% 2009-04-02
CVE-2009-0680 EXP cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (device crash) via a crafted quer… Patch early 7.8 high 8.4% 2009-02-22
CVE-2005-4720 EXP Mozilla Firefox 1.0.7 and earlier on Linux allows remote attackers to cause a denial of service (client crash) via an IFRAME element with a large valu… Patch early 5.0 medium 8.4% 2005-12-31
CVE-2002-1792 EXP Buffer overflow in Fake Identd 0.9 through 1.4 allows remote attackers to execute arbitrary code as root via a long request that is split into multipl… Patch early 10.0 high 8.4% 2002-12-31
CVE-2010-1723 EXP Directory traversal vulnerability in the iNetLanka Contact Us Draw Root Map (com_drawroot) component 1.1 for Joomla! allows remote attackers to read a… Patch early 6.8 medium 8.4% 2010-05-04
CVE-2011-4531 EXP Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allows remote attackers to cause a denial of service (NULL pointer dereference and d… Patch early 5.0 medium 8.4% 2012-01-08
CVE-2007-6268 EXP Directory traversal vulnerability in pages/default.aspx in Absolute News Manager.NET 5.1 allows remote attackers to read arbitrary files via a .. (dot… Patch early 5.0 medium 8.4% 2007-12-07
CVE-2015-2184 EXP ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls the phpinfo function. Patch early 5.0 medium 8.4% 2015-03-10
CVE-2001-0385 EXP GoAhead webserver 2.1 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory. Patch early 5.0 medium 8.4% 2001-07-02
CVE-2004-2254 EXP SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface… Patch early 7.5 high 8.4% 2004-12-31
CVE-2009-1313 EXP The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of s… Patch early 9.3 high 8.4% 2009-04-30
CVE-2000-1054 EXP Buffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execu… Patch early 10.0 high 8.4% 2000-12-11
CVE-2009-1959 EXP Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (cr… Patch early 5.0 medium 8.4% 2009-06-08
CVE-2008-1321 EXP The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote attackers to cause a denial of s… Patch early 5.0 medium 8.4% 2008-03-13
CVE-2007-3191 EXP Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to obtain configuration information via a direct request to admin/adm/te… Patch early 9.4 high 8.4% 2007-06-12
CVE-2006-4890 EXP Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the d… Patch early 7.5 high 8.4% 2006-09-19
CVE-2007-3572 EXP Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro allows remote attackers to execu… Patch early 9.3 high 8.4% 2007-07-05
CVE-2010-3213 EXP Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the au… Patch early 6.8 medium 8.4% 2010-09-07
CVE-2004-1859 EXP Directory traversal vulnerability in Trend Micro Interscan Web Viruswall in InterScan VirusWall 3.5x allows remote attackers to read arbitrary files v… Patch early 5.0 medium 8.4% 2004-03-24
CVE-2004-2516 EXP Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a large number of… Patch early 5.0 medium 8.4% 2004-12-31
CVE-2004-1475 EXP Multiple stack-based buffer overflows in xine-lib 1-rc2 through 1-rc5 allow attackers to execute arbitrary code via (1) long VideoCD vcd:// MRLs or (2… Patch early 5.1 medium 8.4% 2004-12-31
← previous page 238 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt