peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,932 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

321,751 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-2132 EXP Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary files via a .. (dot dot) in the… Patch early 5.0 medium 8% 2004-01-29
CVE-2005-1073 EXP Directory traversal vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to read arbitrary files via the read parameter. Patch early 5.0 medium 8% 2005-05-02
CVE-2007-2429 EXP ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for t… Patch early 10.0 high 8% 2007-05-02
CVE-2017-7056 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 8.8 high 8% 2017-07-20
CVE-2017-13262 EXP In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. This could lead to remote inform… Patch early 6.5 medium 8% 2018-04-04
CVE-2008-3317 EXP admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrar… Patch early 7.5 high 8% 2008-07-25
CVE-2007-5198 EXP Buffer overflow in the redir function in check_http.c in Nagios Plugins before 1.4.10, when running with the -f (follow) option, allows remote web ser… Patch early 6.8 medium 8% 2007-10-04
CVE-2000-0142 EXP The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417. Patch early 5.0 medium 8% 2000-02-11
CVE-2008-1888 EXP Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 8% 2008-04-18
CVE-2006-4897 EXP CMtextS 1.0 and earlier stores users_logins/admin.txt under the web document root with insufficient access control, which allows remote attackers to o… Patch early 5.0 medium 8% 2006-09-19
CVE-2008-2888 EXP Multiple PHP remote file inclusion vulnerabilities in MiGCMS 2.0.5, when register_globals is enabled, allow remote attackers to execute arbitrary PHP… Patch early 10.0 high 8% 2008-06-27
CVE-2000-0671 EXP Roxen web server earlier than 2.0.69 allows allows remote attackers to bypass access restrictions, list directory contents, and read source code by in… Patch early 5.0 medium 8% 2000-07-21
CVE-2018-8002 EXP In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack… Patch early 8.8 high 8% 2018-03-09
CVE-2006-2020 EXP Asterisk Recording Interface (ARI) in Asterisk@Home before 2.8 stores recordings/includes/main.conf under the web document root with insufficient acce… Patch early 7.8 high 8% 2006-04-25
CVE-2005-3519 EXP Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and include arbitrary local files… Patch early 7.5 high 8% 2005-11-06
CVE-2012-0277 EXP Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitra… Patch early 6.8 medium 8% 2012-07-17
CVE-2000-0133 EXP Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD, XRMD, APPE, SIZE, and RNFR co… Patch early 10.0 high 8% 2000-02-01
CVE-2008-5856 EXP Directory traversal vulnerability in scripts/export.php in ClaSS before 0.8.61 allows remote attackers to read arbitrary files via directory traversal… Patch early 5.0 medium 8% 2009-01-06
CVE-2007-5156 EXP Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS,… Patch early 7.5 high 8% 2007-10-01
CVE-2017-1000367 EXP Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting i… Patch early 6.4 medium 8% 2017-06-05
CVE-2017-16902 EXP On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or loginUsername field to goform/logi… Patch early 7.5 high 8% 2017-11-20
CVE-2015-6972 EXP Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 8% 2015-09-16
CVE-2014-5287 EXP A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI)… Patch early 8.8 high 8% 2020-01-08
CVE-2018-18865 EXP The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13) allow Credentials Disclosure… Patch early 8.1 high 8% 2018-11-20
CVE-2004-2286 EXP Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary… Patch early 7.5 high 8% 2004-12-31
CVE-2006-4329 EXP Multiple PHP remote file inclusion vulnerabilities in Shadows Rising RPG (Pre-Alpha) 0.0.5b and earlier allow remote attackers to execute arbitrary PH… Patch early 7.5 high 8% 2006-08-24
CVE-2017-5798 EXP A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (f… Patch early 6.1 medium 8% 2018-02-15
CVE-2006-6047 EXP Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to include and execute arbitrary… Patch early 5.8 medium 8% 2006-11-22
CVE-2006-1784 EXP PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote attackers… Patch early 5.1 medium 8% 2006-04-13
CVE-2011-3493 EXP Multiple stack-based buffer overflows in the DH_OneSecondTick function in Cogent DataHub 7.1.1.63 and earlier allow remote attackers to cause a denial… Patch early 10.0 high 8% 2011-09-16
← previous page 247 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt