peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,891 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

208,016 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-5453 EXP SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arbitrary SQL… Patch early 6.5 medium 2.7% 2012-10-22
CVE-2006-1039 EXP SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive aut… Patch early 6.4 medium 2.7% 2006-03-07
CVE-2007-0056 EXP Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote attackers to inject arbitrary web… Patch early 6.8 medium 2.7% 2007-01-04
CVE-2008-7021 EXP Unrestricted file upload vulnerability in editlogo.php in AvailScript Jobs Portal Script allows remote authenticated users to execute arbitrary code b… Patch early 6.0 medium 2.7% 2009-08-21
CVE-2007-2560 EXP Directory traversal vulnerability in theme/acgv.php in ACGVannu 1.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in… Patch early 5.0 medium 2.7% 2007-05-09
CVE-2007-2566 EXP The SaveBarCode function in the Taltech Tal Bar Code ActiveX control allows remote attackers to cause a denial of service (disk consumption) by upload… Patch early 5.0 medium 2.7% 2007-05-09
CVE-2001-1075 EXP poprelayd script before 2.0 in Cobalt RaQ3 servers allows remote attackers to bypass authentication for relaying by causing a "POP login by user" stri… Patch early 5.0 medium 2.7% 2001-07-04
CVE-2010-1309 EXP Directory traversal vulnerability in Irmin CMS (formerly Pepsi CMS) 0.6 BETA2 allows remote attackers to read arbitrary files via a .. (dot dot) in th… Patch early 5.0 medium 2.7% 2010-04-08
CVE-2009-4192 EXP Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary files via a .… Patch early 5.0 medium 2.7% 2009-12-03
CVE-2019-14748 EXP An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries.… Patch early 5.4 medium 2.7% 2019-08-07
CVE-2014-8652 EXP Elipse E3 3.x and earlier allows remote attackers to cause a denial of service (application crash and plant outage) via a rapid series of HTTP request… Patch early 5.0 medium 2.7% 2014-11-10
CVE-2008-5431 EXP Teamtek Universal FTP Server 1.0.44 allows remote attackers to cause a denial of service via (1) a certain CWD command, (2) a long LIST command, or (3… Patch early 5.0 medium 2.7% 2008-12-11
CVE-2008-6674 EXP mailPage.asp in QuickerSite 1.8.5 allows remote attackers to flood e-mail accounts with messages via a large number of requests with a modified sEmail… Patch early 5.0 medium 2.7% 2009-04-08
CVE-2005-2769 EXP Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 2.7% 2005-09-02
CVE-2012-2275 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in TestLink 1.9.3 and earlier allow remote attackers to hijack the authentication of users… Patch early 6.8 medium 2.7% 2012-09-15
CVE-2015-2701 EXP Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that chang… Patch early 6.8 medium 2.7% 2015-03-25
CVE-2005-4485 EXP Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 2.7% 2005-12-22
CVE-2003-0736 EXP Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the… Patch early 6.8 medium 2.7% 2003-10-20
CVE-2007-4726 EXP Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. Patch early 5.0 medium 2.7% 2007-09-05
CVE-2008-6870 EXP Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) co… Patch early 5.0 medium 2.7% 2009-07-23
CVE-2011-1838 EXP Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to inject arbitrary web script or… Patch early 4.3 medium 2.7% 2011-05-20
CVE-2005-2327 EXP Cross-site scripting (XSS) vulnerability in e107 0.617 and earlier allows remote attackers to inject arbitrary web script or HTML via nested [url] BBC… Patch early 4.3 medium 2.7% 2005-07-20
CVE-2020-15468 EXP Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter. Patch early 9.8 critical 2.7% 2020-07-01
CVE-2007-4895 EXP Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the f parameter. Patch early 5.0 medium 2.7% 2007-09-14
CVE-2009-1519 EXP Directory traversal vulnerability in index.php in Pecio CMS 1.1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the language p… Patch early 5.0 medium 2.7% 2009-05-04
CVE-2009-3151 EXP Directory traversal vulnerability in actions/downloadFile.php in Ultrize TimeSheet 1.2.2 allows remote attackers to read arbitrary files via a .. (dot… Patch early 5.0 medium 2.7% 2009-09-10
CVE-2006-0731 EXP WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolu… Patch early 4.0 medium 2.7% 2006-02-16
CVE-2007-5739 EXP Directory traversal vulnerability in component/flashupload/download.jsp in the FlashUpload component in Korean GHBoard allows remote attackers to read… Patch early 5.0 medium 2.7% 2007-10-30
CVE-2009-4816 EXP Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files via a .. (do… Patch early 5.0 medium 2.7% 2010-04-27
CVE-2008-0489 EXP Directory traversal vulnerability in install.php in Clansphere 2007.4.4 allows remote attackers to include and execute arbitrary local files via a ..… Patch early 5.0 medium 2.7% 2008-01-30
← previous page 258 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt