peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,166 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

321,937 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2001-0616 EXP Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to create a denial of service via a URL request which includes a MS-… Patch early 5.0 medium 7.1% 2001-08-14
CVE-2001-1156 EXP TYPSoft FTP 0.95 allows remote attackers to cause a denial of service (CPU consumption) via a "../../*" argument to (1) STOR or (2) RETR. Patch early 5.0 medium 7.1% 2001-10-08
CVE-2019-14267 EXP PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled. Patch early 7.8 high 7.1% 2019-07-29
CVE-2022-47876 EXP The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code via Groovy-scripts. Patch early 8.8 high 7% 2023-05-02
CVE-2017-0175 EXP The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sensitive information via a speci… Patch early 4.7 medium 7% 2017-05-12
CVE-2006-5190 EXP Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script… Patch early 4.3 medium 7% 2006-10-10
CVE-2008-6583 EXP Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a lon… Patch early 9.3 high 7% 2009-04-03
CVE-2004-0361 EXP The Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a new Array obje… Patch early 5.0 medium 7% 2004-11-23
CVE-2007-5070 EXP Heap-based buffer overflow in the EasyMailMessagePrinter ActiveX control in emprint.DLL 6.0.1.0 in the Quiksoft EasyMail MessagePrinter Object allows… Patch early 10.0 high 7% 2007-09-24
CVE-2017-2365 EXP An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. Th… Patch early 6.5 medium 7% 2017-02-20
CVE-2014-100029 EXP Multiple directory traversal vulnerabilities in class/session.php in Ganesha Digital Library (GDL) 4.2 allow remote attackers to read arbitrary files… Patch early 5.0 medium 7% 2015-01-13
CVE-2008-7054 EXP Multiple directory traversal vulnerabilities in ezContents 2.0.3 allow remote attackers to include and execute arbitrary local files via the (1) gsLan… Patch early 5.1 medium 7% 2009-08-24
CVE-2009-3691 EXP Multiple integer overflows in setnet32.exe 3.50.0.13752 in IBM Informix Client SDK 3.0 and 3.50 and Informix Connect Runtime 3.x allow remote attacker… Patch early 9.3 high 7% 2009-10-13
CVE-2007-2588 EXP Multiple buffer overflows in the Office Viewer OCX ActiveX control (oa.ocx) 3.2 allow remote attackers to cause a denial of service (crash) or possibl… Patch early 9.3 high 7% 2007-05-10
CVE-2006-0163 EXP SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attackers to execute arbitrary SQL com… Patch early 7.5 high 7% 2006-01-11
CVE-2009-0291 EXP Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the MA… Patch early 7.5 high 7% 2009-01-27
CVE-2007-6198 EXP portal/server.pt in the Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows wildcards in advanced searches for us… Patch early 5.0 medium 7% 2007-12-01
CVE-2023-33177 EXP Xibo is a content management system (CMS). A path traversal vulnerability exists in the Xibo CMS whereby a specially crafted zip file can be uploaded… Patch early 8.8 high 7% 2023-05-30
CVE-2000-0590 EXP Poll It 2.0 CGI script allows remote attackers to read arbitrary files by specifying the file name in the data_dir parameter. Patch early 7.5 high 7% 2000-07-04
CVE-2007-1790 EXP Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to execute arbitrary PHP code via a U… Patch early 6.8 medium 7% 2007-03-31
CVE-2007-2185 EXP Multiple PHP remote file inclusion vulnerabilities in Supasite 1.23b allow remote attackers to execute arbitrary PHP code via a URL in the supa[db_pat… Patch early 6.8 medium 7% 2007-04-24
CVE-2015-2315 EXP Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 7% 2015-03-17
CVE-2019-16679 EXP Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion. Patch early 4.9 medium 7% 2019-09-21
CVE-2007-4329 EXP Multiple PHP remote file inclusion vulnerabilities in Web News 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_o… Patch early 6.8 medium 7% 2007-08-14
CVE-1999-0068 EXP CGI PHP mylog script allows an attacker to read any file on the target server. Patch early 7.5 high 7% 1997-10-19
CVE-2008-4428 EXP Unrestricted file upload vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier allows remote attackers to exe… Patch early 10.0 high 7% 2008-10-03
CVE-2018-9107 EXP CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla!… Patch early 8.8 high 7% 2018-03-28
CVE-2009-0967 EXP The FTP server in Serv-U 7.0.0.1 through 7.4.0.1 allows remote authenticated users to cause a denial of service (service hang) via a large number of S… Patch early 4.0 medium 7% 2009-03-19
CVE-2014-1947 EXP Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial o… Patch early 7.8 high 7% 2020-02-17
CVE-2002-0413 EXP Cross-site scripting vulnerability in ReBB allows remote attackers to execute arbitrary Javascript and steal cookies via an IMG tag whose URL includes… Patch early 7.5 high 7% 2002-08-12
← previous page 275 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt