peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,707 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

187,600 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-4991 EXP Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated users to (1) read, (2) delete, or… Patch early 8.5 high 4.6% 2012-12-13
CVE-2006-2646 EXP Buffer overflow in Alt-N MDaemon, possibly 9.0.1 and earlier, allows remote attackers to execute arbitrary code via a long A0001 argument that begins… Patch early 7.5 high 4.6% 2006-05-30
CVE-2019-19032 EXP XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an XML File is validated. The com… Patch early 8.1 high 4.5% 2019-12-30
CVE-2007-2775 EXP AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote at… Patch early 10.0 high 4.5% 2007-05-21
CVE-2009-0602 EXP Unrestricted file upload vulnerability in upload.php in WikkiTikkiTavi 1.11 allows remote attackers to execute arbitrary code by uploading a file with… Patch early 7.5 high 4.5% 2009-02-16
CVE-2009-1152 EXP Siemens Gigaset SE461 WiMAX router 1.5-BL024.9.6401, and possibly other versions, allows remote attackers to cause a denial of service (device restart… Patch early 7.3 high 4.5% 2009-03-26
CVE-2005-0280 EXP Format string vulnerability in Soldner Secret Wars 30830 and earlier allows remote attackers to cause a denial of service (server crash) and possibly… Patch early 7.5 high 4.5% 2005-01-04
CVE-2023-24217 EXP AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability. Patch early 8.8 high 4.5% 2023-03-06
CVE-2005-4714 EXP Format string vulnerability in the vmps_log function in OpenVMPS (VLAN Management Policy Server) 1.3 allows remote attackers to execute arbitrary code… Patch early 7.5 high 4.5% 2005-12-31
CVE-2006-0171 EXP PHP remote file include vulnerability in index.php in OrjinWeb E-commerce allows remote attackers to execute arbitrary code via a URL in the page para… Patch early 7.5 high 4.5% 2006-01-11
CVE-2006-0710 EXP Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP request, as… Patch early 7.5 high 4.5% 2006-02-15
CVE-2002-0311 EXP Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharact… Patch early 10.0 high 4.5% 2002-05-31
CVE-2001-0527 EXP DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the… Patch early 10.0 high 4.5% 2001-08-14
CVE-2007-5815 EXP Absolute path traversal vulnerability in the WebCacheCleaner ActiveX control 1.3.0.3 in SonicWall SSL-VPN 200 before 2.1, and SSL-VPN 2000/4000 before… Patch early 10.0 high 4.5% 2007-11-05
CVE-2008-4673 EXP PHP remote file inclusion vulnerability in panel/common/theme/default/header_setup.php in WebBiscuits Software Events Calendar 1.1 allows remote attac… Patch early 10.0 high 4.5% 2008-10-22
CVE-2008-5063 EXP PHP remote file inclusion vulnerability in Admin/ADM_Pagina.php in OTManager 2.4 allows remote attackers to execute arbitrary PHP code via a URL in th… Patch early 10.0 high 4.5% 2008-11-13
CVE-2006-4666 EXP Multiple PHP remote file inclusion vulnerabilities in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attackers to execute arbitrary PHP c… Patch early 7.5 high 4.5% 2006-09-09
CVE-2019-10874 EXP Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by upload… Patch early 8.8 high 4.5% 2019-04-05
CVE-2000-0577 EXP Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack. Patch early 10.0 high 4.5% 2000-06-21
CVE-2005-4462 EXP PHP remote file include vulnerability in usermods.php in Tolva PHP website system 0.1.0 allows remote attackers to execute arbitrary code via a URL in… Patch early 7.5 high 4.5% 2005-12-21
CVE-2009-2158 EXP account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes it easier for remote attacker… Patch early 7.5 high 4.5% 2009-06-22
CVE-2008-5674 EXP Multiple array index errors in the HTTP server in Darkwet Network webcamXP 3.72.440.0 and earlier and beta 4.05.280 and earlier allow remote attackers… Patch early 9.4 high 4.5% 2008-12-19
CVE-2002-0913 EXP Format string vulnerability in log_doit function of Slurp NNTP client 1.1.0 allows a malicious news server to execute arbitrary code on the client via… Patch early 7.5 high 4.5% 2002-10-04
CVE-2004-2692 EXP The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and execute arbitrary… Patch early 9.3 high 4.5% 2004-12-31
CVE-2013-6027 EXP Stack-based buffer overflow in the RuntimeDiagnosticPing function in /bin/webs on D-Link DIR-100 routers might allow remote authenticated administrato… Patch early 8.5 high 4.5% 2013-10-19
CVE-2011-3488 EXP Use-after-free vulnerability in Equis MetaStock 11 and earlier allows remote attackers to execute arbitrary code via a malformed (1) mwc chart, (2) mw… Patch early 10.0 high 4.5% 2011-09-16
CVE-2009-2169 EXP Insecure method vulnerability in the PDFVIEWER.PDFViewerCtrl.1 ActiveX control (pdfviewer.ocx) in Edraw PDF Viewer Component before 3.2.0.126 allows r… Patch early 9.3 high 4.5% 2009-06-22
CVE-2008-6555 EXP cgi-bin/webutil.pl in The Puppet Master WebUtil allows remote attackers to execute arbitrary commands via shell metacharacters in the dig command. Patch early 10.0 high 4.5% 2009-03-30
CVE-2002-0773 EXP imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp_rootdir.a… Patch early 10.0 high 4.5% 2002-08-12
CVE-2009-3708 EXP Stack-based buffer overflow in the Meta Content Optimizer in Konae Technologies Alleycode HTML Editor 2.21 allows user-assisted remote attackers to ex… Patch early 9.3 high 4.5% 2009-10-16
← previous page 276 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt