peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,413 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

321,367 results

CVESummaryPriorityCVSSEPSSPublished
CVE-1999-1508 EXP Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented UR… Patch early 10.0 high 8.1% 1999-11-16
CVE-2010-0303 EXP mystring.c in hybserv in IRCD-Hybrid (aka Hybrid2 IRC Services) 1.9.2 through 1.9.4 allows remote attackers to cause a denial of service (daemon crash… Patch early 5.0 medium 8.1% 2010-02-04
CVE-2015-1371 EXP Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code by uploading a file with an exe… Patch early 7.5 high 8.1% 2015-01-27
CVE-2000-1093 EXP Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command. Patch early 7.5 high 8.1% 2001-01-09
CVE-2011-1425 EXP xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to crea… Patch early 5.1 medium 8.1% 2011-04-04
CVE-1999-1521 EXP Computalynx CMail 2.4 and CMail 2.3 SP2 SMTP servers are vulnerable to a buffer overflow attack in the MAIL FROM command that may allow a remote attac… Patch early 10.0 high 8.1% 1999-09-12
CVE-1999-1069 EXP Directory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the ic… Patch early 5.0 medium 8.1% 1997-11-08
CVE-2001-0189 EXP Directory traversal vulnerability in LocalWEB2000 HTTP server allows remote attackers to read arbitrary commands via a .. (dot dot) attack in an HTTP… Patch early 5.0 medium 8.1% 2001-03-26
CVE-2002-1525 EXP Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (… Patch early 5.0 medium 8.1% 2003-04-02
CVE-2003-0748 EXP Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary fil… Patch early 5.0 medium 8.1% 2003-10-20
CVE-2008-0763 EXP Stack-based buffer overflow in NPSpcSVR.exe in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier allows remote attackers to execute arb… Patch early 10.0 high 8.1% 2008-02-13
CVE-2002-1656 EXP X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via sniffing or th… Patch early 7.5 high 8.1% 2002-12-31
CVE-2003-0621 EXP The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modifie… Patch early 5.0 medium 8% 2003-12-01
CVE-2017-14523 EXP WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that ex… Patch early 7.5 high 8% 2018-01-26
CVE-2007-4583 EXP Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in ACTi Network Video Recorder (… Patch early 5.0 medium 8% 2007-08-29
CVE-2017-6823 EXP Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action. Patch early 8.8 high 8% 2017-03-12
CVE-2007-0873 EXP nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) config_ed… Patch early 7.5 high 8% 2007-02-12
CVE-2002-1031 EXP KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00 (null) chara… Patch early 5.0 medium 8% 2002-10-04
CVE-2017-2491 EXP Use after free vulnerability in the String.replace method JavaScriptCore in Apple Safari in iOS before 10.3 allows remote attackers to execute arbitra… Patch early 8.8 high 8% 2017-06-27
CVE-2000-0919 EXP Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. Patch early 5.0 medium 8% 2000-12-19
CVE-2001-1209 EXP Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. Patch early 5.0 medium 8% 2001-12-31
CVE-2007-2371 EXP admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows re… Patch early 10.0 high 8% 2007-04-30
CVE-2013-1638 EXP Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document. Patch early 9.3 high 8% 2013-02-08
CVE-2006-3532 EXP PHP file inclusion vulnerability in includes/edit_new.php in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allows remote attackers to… Patch early 5.1 medium 8% 2006-07-12
CVE-2007-2317 EXP Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other products, allow… Patch early 7.5 high 8% 2007-04-26
CVE-2007-2891 EXP Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_da… Patch early 7.5 high 8% 2007-05-30
CVE-2004-2519 EXP Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specifiers in the LANGUAGE parameter… Patch early 5.0 medium 8% 2004-12-31
CVE-2002-0733 EXP Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, whi… Patch early 7.5 high 8% 2002-08-12
CVE-2006-0755 EXP Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute… Patch early 5.6 medium 8% 2006-02-18
CVE-2004-2132 EXP Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary files via a .. (dot dot) in the… Patch early 5.0 medium 8% 2004-01-29
← previous page 246 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt