peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,237 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

150,786 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-2073 EXP Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modif… Patch early 7.2 high 3.1% 2004-02-06
CVE-2007-1079 EXP Stack-based buffer overflow in Rhino Software, Inc. FTP Voyager 14.0.0.3 and earlier allows remote servers to cause a denial of service (crash) via a… Patch early 7.8 high 3.1% 2007-02-22
CVE-2015-7715 EXP Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the… Patch early 8.8 high 3.1% 2017-10-18
CVE-2002-0938 EXP Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as other web users via the actio… Patch early 7.5 high 3.1% 2002-10-04
CVE-2018-0880 EXP The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerabi… Patch early 7.0 high 3.1% 2018-03-14
CVE-2004-1592 EXP PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying… Patch early 7.5 high 3.1% 2004-12-31
CVE-2007-1075 EXP TurboFTP 5.30 Build 572 allows remote servers to cause a denial of service (CPU consumption) via a response with a large number of newline characters. Patch early 7.8 high 3.1% 2007-02-22
CVE-2023-1211 EXP SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2. Patch early 7.2 high 3.1% 2023-03-07
CVE-2008-1860 EXP Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Confi… Patch early 9.3 high 3% 2008-04-17
CVE-2010-0605 EXP SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute ar… Patch early 7.5 high 3% 2010-02-11
CVE-2010-1873 EXP SQL injection vulnerability in the Jvehicles (com_jvehicles) component 1.0, 2.0, and 2.1111 for Joomla! allows remote attackers to execute arbitrary S… Patch early 7.5 high 3% 2010-05-12
CVE-2009-4747 EXP PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to e… Patch early 7.5 high 3% 2010-03-26
CVE-2008-2282 EXP admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_admi… Patch early 7.5 high 3% 2008-05-18
CVE-2008-2081 EXP Directory traversal vulnerability in index.php in Siteman 2.0.x2 allows remote authenticated administrators to include and execute arbitrary local fil… Patch early 9.0 high 3% 2008-05-05
CVE-2015-7293 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x. Patch early 8.8 high 3% 2017-09-25
CVE-2019-6282 EXP ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlse… Patch early 8.8 high 3% 2019-03-21
CVE-2008-2822 EXP Multiple directory traversal vulnerabilities in the FTP client in 3D-FTP Client 8.01 (8.0 build 1) allow remote FTP servers to create or overwrite arb… Patch early 9.3 high 3% 2008-06-23
CVE-2015-2553 EXP The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2,… Patch early 7.2 high 3% 2015-10-14
CVE-2015-2055 EXP Zhone GPON 2520 with firmware R4.0.2.566b allows remote attackers to cause a denial of service via a long string in the oldpassword parameter. Patch early 7.8 high 3% 2015-02-23
CVE-2007-5174 EXP Directory traversal vulnerability in phpinc/news.php in actSite 1.56 allows remote attackers to include and execute arbitrary local files via a .. (do… Patch early 7.5 high 3% 2007-10-03
CVE-2017-14848 EXP WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter. Patch early 8.8 high 3% 2017-10-03
CVE-2009-2395 EXP SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 3% 2009-07-09
CVE-2008-1620 EXP Directory traversal vulnerability in 2X TFTP service (TFTPd.exe) 3.2.0.0 and earlier in 2X ThinClientServer 5.0_sp1-r3497 and earlier allows remote at… Patch early 7.5 high 3% 2008-04-02
CVE-2008-4749 EXP Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, all… Patch early 9.3 high 3% 2008-10-27
CVE-2007-5684 EXP Multiple directory traversal vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to include and execute arbitrary files via an abso… Patch early 7.5 high 3% 2007-10-26
CVE-2006-5102 EXP PHP remote file inclusion vulnerability in include/editfunc.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.42 and earlier allows remo… Patch early 7.5 high 3% 2006-10-03
CVE-2015-1862 EXP The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directo… Patch early 7.0 high 3% 2018-02-09
CVE-2016-9314 EXP Sensitive Information Disclosure in com.trend.iwss.gui.servlet.ConfigBackup in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.… Patch early 7.8 high 3% 2017-02-21
CVE-2008-5840 EXP PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1. Patch early 7.5 high 3% 2009-01-05
CVE-2009-3962 EXP The management interface on the 2wire Gateway 1700HG, 1701HG, 1800HW, 2071, 2700HG, and 2701HG-T with software before 5.29.52 allows remote attackers… Patch early 7.8 high 3% 2009-11-17
← previous page 261 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt