peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,237 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

208,197 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2026-2624 EXP Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows… Patch early 9.8 critical 2.4% 2026-02-25
CVE-2007-1475 EXP Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-… Patch early 5.4 medium 2.4% 2007-03-16
CVE-2008-0840 EXP Directory traversal vulnerability in view_member.php in Public Warehouse LightBlog 9.6 allows remote attackers to include and execute arbitrary local… Patch early 4.4 medium 2.4% 2008-02-20
CVE-2005-0477 EXP Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script v… Patch early 4.3 medium 2.4% 2005-03-30
CVE-2024-38944 EXP An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?for… Patch early 9.8 critical 2.4% 2024-07-22
CVE-2007-1515 EXP Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP H3 4.1.3, and possibly earlier, allow remote attackers to inject arbitrary web script… Patch early 4.3 medium 2.4% 2007-03-20
CVE-2010-3480 EXP Directory traversal vulnerability in index.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include and… Patch early 6.8 medium 2.4% 2010-09-22
CVE-2011-4519 EXP Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a craft… Patch early 4.3 medium 2.4% 2013-05-23
CVE-2011-4520 EXP Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafte… Patch early 4.3 medium 2.4% 2013-05-23
CVE-2002-2399 EXP Directory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file… Patch early 6.4 medium 2.4% 2002-12-31
CVE-2007-6475 EXP Multiple directory traversal vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot)… Patch early 6.4 medium 2.4% 2007-12-20
CVE-2007-6621 EXP Directory traversal vulnerability in joovili.images.php in Joovili 3.0.0 through 3.0.6 allows remote attackers to read arbitrary files via a .. (dot d… Patch early 6.4 medium 2.4% 2008-01-04
CVE-2007-1104 EXP PHP remote file inclusion vulnerability in top.php in PHP Module Implementation (PHP-MIP) 0.1 allows remote attackers to execute arbitrary PHP code vi… Patch early 4.3 medium 2.4% 2007-02-26
CVE-2007-5140 EXP PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in IntegraMOD Nederland 1.4.2 allows remote attackers to execute arbitra… Patch early 6.8 medium 2.4% 2007-09-28
CVE-2007-5157 EXP PHP remote file inclusion vulnerability in phfito-post.php in Alex Kocharin PHP Fidonet Tosser (PhFiTo) 1.3.0 in phpFidoNode allows remote attackers t… Patch early 6.8 medium 2.4% 2007-10-01
CVE-2007-5780 EXP PHP remote file inclusion vulnerability in pub/pub08_comments.php in teatro 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 6.8 medium 2.4% 2007-11-01
CVE-2024-53537 EXP An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager. Patch early 9.1 critical 2.4% 2025-01-31
CVE-2009-0853 EXP login.php in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allows remote attackers to bypass authentication and obtain administrative access via s… Patch early 6.8 medium 2.4% 2009-03-09
CVE-2007-4647 EXP newswire/uploadmedia.cgi in 2coolcode Our Space (Ourspace) 2.0.9 allows remote attackers to upload certain files via unspecified vectors, probably inv… Patch early 5.0 medium 2.4% 2007-08-31
CVE-2008-4740 EXP Directory traversal vulnerability in templater.php in the ZZ_Templater module in TinyCMS 1.1.2, when register_globals is enabled and magic_quotes_gpc… Patch early 5.1 medium 2.4% 2008-10-27
CVE-2026-61459 EXP MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) th… Patch early 9.8 critical 2.4% 2026-07-10
CVE-2018-9173 EXP Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitr… Patch early 6.1 medium 2.4% 2018-04-02
CVE-2007-6582 EXP Directory traversal vulnerability in index.php in mBlog 1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter i… Patch early 6.4 medium 2.4% 2007-12-28
CVE-2006-5065 EXP PHP remote file inclusion vulnerability in libs/dbmax/mysql.php in ZoomStats 1.0.2 and earlier, when register_globals is enabled, allows remote attack… Patch early 5.1 medium 2.4% 2006-09-28
CVE-2018-0901 EXP The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold… Patch early 4.7 medium 2.4% 2018-03-14
CVE-2011-0773 EXP Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attackers to inject arbitrary web scr… Patch early 4.3 medium 2.4% 2011-02-04
CVE-1999-0683 EXP Denial of service in Gauntlet Firewall via a malformed ICMP packet. Patch early 5.0 medium 2.4% 1999-07-30
CVE-2009-0080 EXP The ThreadPool class in Windows Vista Gold and SP1, and Server 2008, does not properly implement isolation among a set of distinct processes that (1)… Patch early 6.9 medium 2.4% 2009-04-15
CVE-2008-3127 EXP PHP remote file inclusion vulnerability in hioxBannerRotate.php in HIOX Banner Rotator (HBR) 1.3, when register_globals is enabled, allows remote atta… Patch early 6.8 medium 2.4% 2008-07-10
CVE-2021-24664 EXP The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them… Patch early 4.8 medium 2.4% 2021-11-08
← previous page 282 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt