peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,373 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

321,352 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-1607 EXP Directory traversal vulnerability in wmi.php in the Webmoney Web Merchant Interface (aka WMI or com_wmi) component 1.5.0 for Joomla! allows remote att… Patch early 6.8 medium 8.2% 2010-04-29
CVE-2010-1715 EXP Directory traversal vulnerability in the Online Examination (aka Online Exam or com_onlineexam) component 1.5.0 for Joomla! allows remote attackers to… Patch early 6.8 medium 8.2% 2010-05-04
CVE-2015-5696 EXP Dell Netvault Backup before 10.0.5 allows remote attackers to cause a denial of service (crash) via a crafted request. Patch early 5.0 medium 8.2% 2015-08-14
CVE-2007-3432 EXP Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jpg… Patch early 7.5 high 8.2% 2007-06-27
CVE-2003-0339 EXP Multiple heap-based buffer overflows in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allow remote attackers to execute arbitrary code via long HTTP reques… Patch early 7.5 high 8.2% 2003-05-22
CVE-2008-6604 EXP Directory traversal vulnerability in index.php in PicoFlat CMS 0.5.9 allows remote attackers to include and execute arbitrary local files via a .. (do… Patch early 10.0 high 8.2% 2009-04-04
CVE-2010-1147 EXP Stack-based buffer overflow in Open Direct Connect Hub (aka Open DC Hub or OpenDCHub) 0.8.1 allows remote authenticated users to execute arbitrary cod… Patch early 6.0 medium 8.2% 2010-04-06
CVE-2006-3475 EXP Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the qb_path pa… Patch early 7.5 high 8.2% 2006-07-10
CVE-2010-1469 EXP Directory traversal vulnerability in the Ternaria Informatica JProject Manager (com_jprojectmanager) component 1.0 for Joomla! allows remote attackers… Patch early 6.8 medium 8.2% 2010-04-19
CVE-2010-1473 EXP Directory traversal vulnerability in the Advertising (com_advertising) component 0.25 for Joomla! allows remote attackers to read arbitrary files and… Patch early 6.8 medium 8.2% 2010-04-19
CVE-2010-1478 EXP Directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allows remote attackers to read arb… Patch early 6.8 medium 8.2% 2010-04-19
CVE-2009-0348 EXP The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently to a failed login attempt depe… Patch early 5.0 medium 8.2% 2009-01-29
CVE-2007-2570 EXP PHP remote file inclusion vulnerability in handlers/page/show.php in Wikivi5 allows remote attackers to execute arbitrary PHP code via a URL in the so… Patch early 7.5 high 8.2% 2007-05-09
CVE-2008-4748 EXP Format string vulnerability in the URI handler in KVirc 3.4.0, when set as the default application for processing IRC URIs, allows remote attackers to… Patch early 7.6 high 8.2% 2008-10-27
CVE-2007-3621 EXP Multiple CRLF injection vulnerabilities in callboth.php in AsteriDex 3.0 and earlier allow remote attackers to inject arbitrary shell commands via the… Patch early 7.5 high 8.2% 2007-07-09
CVE-2017-5881 EXP GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafte… Patch early 7.8 high 8.2% 2017-02-21
CVE-2017-9614 EXP The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and ap… Patch early 8.8 high 8.2% 2017-07-27
CVE-2006-0922 EXP CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results… Patch early 5.0 medium 8.1% 2006-02-28
CVE-2019-11369 EXP An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensiti… Patch early 8.8 high 8.1% 2019-06-03
CVE-2006-4849 EXP PHP remote file inclusion vulnerability in header.php in MobilePublisherPHP 1.5 RC2 and earlier allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 8.1% 2006-09-19
CVE-2003-0118 EXP SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attacker… Patch early 7.5 high 8.1% 2003-05-12
CVE-2009-3704 EXP ZoIPer 2.22, and possibly other versions before 2.24 Library 5324, allows remote attackers to cause a denial of service (crash) via a SIP INVITE reque… Patch early 5.0 medium 8.1% 2009-10-16
CVE-2007-3956 EXP TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which allows remote attackers to cause… Patch early 7.8 high 8.1% 2007-07-24
CVE-2018-11415 EXP SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indica… Patch early 6.1 medium 8.1% 2018-05-24
CVE-2001-0705 EXP Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via… Patch early 5.0 medium 8.1% 2001-09-20
CVE-2004-1620 EXP CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML c… Patch early 5.0 medium 8.1% 2004-10-21
CVE-2002-0112 EXP Etype Eserv 2.97 allows remote attackers to view password protected files via /./ in the URL. Patch early 5.0 medium 8.1% 2002-03-25
CVE-2006-4204 EXP Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execute arbitrary PHP code via a UR… Patch early 7.5 high 8.1% 2006-08-17
CVE-2006-4477 EXP Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute arbitrary PHP code via an empt… Patch early 7.5 high 8.1% 2006-08-31
CVE-2014-0983 EXP Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py in Oracle Vi… Patch early 6.9 medium 8.1% 2014-03-31
← previous page 243 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt