peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,069 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

321,842 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-2060 EXP ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request… Patch early 5.0 medium 7.9% 2004-12-31
CVE-2007-3505 EXP Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot… Patch early 6.4 medium 7.9% 2007-07-02
CVE-2001-0037 EXP Directory traversal vulnerability in HomeSeer before 1.4.29 allows remote attackers to read arbitrary files via a URL containing .. (dot dot) specifie… Patch early 5.0 medium 7.9% 2001-02-16
CVE-2001-0805 EXP Directory traversal vulnerability in ttawebtop.cgi in Tarantella Enterprise 3.00 and 3.01 allows remote attackers to read arbitrary files via a .. (do… Patch early 5.0 medium 7.9% 2001-12-06
CVE-2008-3851 EXP Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute arbitrary local files via a .… Patch early 5.0 medium 7.9% 2008-08-27
CVE-2007-6515 EXP support/dispatch.cgi in SiteScape Forum allows remote attackers to execute arbitrary TCL code via code separator characters in the query string. Patch early 7.5 high 7.9% 2007-12-21
CVE-1999-1005 EXP Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter… Patch early 5.0 medium 7.9% 1999-12-19
CVE-2006-2156 EXP Directory traversal vulnerability in help/index.php in X7 Chat 2.0 and earlier allows remote attackers to include arbitrary files via .. (dot dot) seq… Patch early 6.4 medium 7.9% 2006-05-03
CVE-2009-1415 EXP lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows remote attackers to cause a denia… Patch early 4.3 medium 7.9% 2009-04-30
CVE-2018-6610 EXP Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request. Patch early 7.5 high 7.9% 2018-02-05
CVE-2018-7317 EXP Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/. Patch early 7.5 high 7.9% 2018-02-22
CVE-2006-2142 EXP PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and earlier allows remote attackers to execute arbitrary PHP code… Patch early 6.4 medium 7.9% 2006-05-02
CVE-2006-5773 EXP Directory traversal vulnerability in index.php in FreeWebshop 2.2.1 and earlier allows remote attackers to read arbitrary files and disclose the insta… Patch early 5.0 medium 7.9% 2006-11-06
CVE-2014-2927 EXP The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and 1… Patch early 9.3 high 7.9% 2014-10-15
CVE-2007-3799 EXP The session_start function in ext/session in PHP 4.x up to 4.4.7 and 5.x up to 5.2.3 allows remote attackers to insert arbitrary attributes into the s… Patch early 4.3 medium 7.9% 2007-07-16
CVE-2007-1581 EXP The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file funct… Patch early 9.3 high 7.9% 2007-03-21
CVE-2007-1867 EXP Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file. Patch early 10.0 high 7.9% 2007-04-04
CVE-2001-1528 EXP AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote att… Patch early 5.0 medium 7.9% 2001-12-31
CVE-2000-1116 EXP Buffer overflow in TransSoft Broker FTP Server before 4.3.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary comm… Patch early 7.5 high 7.9% 2001-01-09
CVE-2000-0446 EXP Buffer overflow in MDBMS database server allows remote attackers to execute arbitrary commands via a long string. Patch early 7.5 high 7.9% 2000-05-24
CVE-2003-1364 EXP Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) v… Patch early 8.5 high 7.9% 2003-12-31
CVE-2001-0123 EXP Directory traversal vulnerability in eXtropia bbs_forum.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the file… Patch early 5.0 medium 7.9% 2001-03-12
CVE-2007-2539 EXP The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadata) via uns… Patch early 7.8 high 7.9% 2007-05-09
CVE-2006-6692 EXP Multiple format string vulnerabilities in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute… Patch early 7.5 high 7.9% 2006-12-21
CVE-2017-14086 EXP Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the Office… Patch early 7.5 high 7.9% 2017-10-06
CVE-2018-18775 EXP Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the Log… Patch early 6.1 medium 7.9% 2018-11-01
CVE-2009-2851 EXP Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web scri… Patch early 4.3 medium 7.9% 2009-08-18
CVE-2016-9813 EXP The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference… Patch early 5.5 medium 7.9% 2017-01-13
CVE-2006-6488 EXP Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used by ICONICS… Patch early 7.5 high 7.9% 2006-12-31
CVE-2006-4254 EXP Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 allows local users to gain privileges via unspecified vectors. Patch early 7.5 high 7.9% 2006-08-21
← previous page 249 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt