peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,917 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

205,673 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-5631 EXP Multiple PHP remote file inclusion vulnerabilities in PeopleAggregator 1.2pre6, when register_globals is enabled, allow remote attackers to execute ar… Patch early 6.8 medium 39.4% 2007-10-23
CVE-2011-2757 EXP Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read arbitrary… Patch early 5.0 medium 39.4% 2011-07-17
CVE-2018-16133 EXP Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI. Patch early 5.3 medium 39.3% 2018-08-29
CVE-2017-14537 EXP trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.p… Patch early 6.5 medium 39.3% 2018-02-16
CVE-2014-2383 EXP dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitra… Patch early 6.8 medium 39.2% 2014-04-28
CVE-2017-12943 EXP D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path trav… Patch early 9.8 critical 39.2% 2017-08-18
CVE-2020-25494 EXP Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels paramete… Patch early 9.8 critical 39.2% 2020-12-18
CVE-2018-5262 EXP A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context… Patch early 9.8 critical 39.1% 2018-01-12
CVE-2006-4301 EXP Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attribute in multiple DirectX Media… Patch early 5.0 medium 39.1% 2006-08-23
CVE-2009-3641 EXP Snort before 2.8.5.1, when the -v option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted IPv6 packe… Patch early 4.3 medium 38.8% 2009-10-28
CVE-2018-8716 EXP WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers. Patch early 5.4 medium 38.7% 2018-04-25
CVE-2013-5093 EXP The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows… Patch early 6.8 medium 38.7% 2013-09-27
CVE-2015-7309 EXP The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitr… Patch early 6.5 medium 38.6% 2015-09-22
CVE-2007-5781 EXP PHP remote file inclusion vulnerability in inc/sige_init.php in Sige 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the SYS_PA… Patch early 6.8 medium 38.6% 2007-11-01
CVE-2007-5315 EXP PHP remote file inclusion vulnerability in common.php in LiveAlbum 0.9.0, when register_globals is enabled, allows remote attackers to execute arbitra… Patch early 6.8 medium 38.6% 2007-10-09
CVE-2007-5102 EXP PHP remote file inclusion vulnerability in config.inc.php in Wordsmith 1.0 RC1, when register_globals is enabled, allows remote attackers to execute a… Patch early 6.8 medium 38.6% 2007-09-26
CVE-2007-5015 EXP Multiple PHP remote file inclusion vulnerabilities in Streamline PHP Media Server 1.0-beta4 allow remote attackers to execute arbitrary PHP code via a… Patch early 6.8 medium 38.6% 2007-09-20
CVE-2018-17440 EXP An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has… Patch early 9.8 critical 38.5% 2018-10-08
CVE-2014-8598 EXP The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via the impor… Patch early 6.4 medium 38.5% 2014-11-18
CVE-2012-6636 EXP The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary met… Patch early 6.8 medium 38.5% 2014-03-03
CVE-2016-10034 EXP The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before… Patch early 9.8 critical 38.4% 2016-12-30
CVE-2021-3817 EXP wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command Patch early 9.8 critical 38.4% 2021-12-09
CVE-2001-1501 EXP The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption)… Patch early 5.0 medium 38.4% 2001-12-31
CVE-2007-4906 EXP PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is enabled, allows remote attacker… Patch early 6.8 medium 38.4% 2007-09-17
CVE-2007-5388 EXP Multiple PHP remote file inclusion vulnerabilities in WebDesktop 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) app par… Patch early 6.8 medium 38.4% 2007-10-12
CVE-2006-1518 EXP Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via craft… Patch early 6.5 medium 38.4% 2006-05-05
CVE-2002-0419 EXP Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks v… Patch early 5.0 medium 38.2% 2002-08-12
CVE-2018-14009 EXP Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689. Patch early 9.8 critical 38% 2018-07-12
CVE-2007-6514 EXP Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed c… Patch early 4.3 medium 38% 2007-12-21
CVE-2019-10945 EXP An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to ac… Patch early 9.8 critical 38% 2019-04-10
← previous page 55 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt