peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,003 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

169,214 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2013-6890 EXP denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (inc… Patch early 5.0 medium 8.9% 2013-12-23
CVE-2008-0364 EXP Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; on Windows… Patch early 5.0 medium 8.9% 2008-01-18
CVE-2008-3293 EXP Directory traversal vulnerability in download.php in EZWebAlbum allows remote attackers to read arbitrary files via the dlfilename parameter. Patch early 5.0 medium 8.9% 2008-07-24
CVE-2014-4874 EXP BMC Track-It! 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment page. Patch early 4.0 medium 8.9% 2014-10-10
CVE-2014-3225 EXP Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files vi… Patch early 4.0 medium 8.9% 2014-05-14
CVE-2011-1715 EXP Directory traversal vulnerability in framework/source/resource/qx/test/part/delay.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2… Patch early 5.0 medium 8.9% 2011-04-18
CVE-2007-2872 EXP Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of servic… Patch early 6.8 medium 8.9% 2007-06-04
CVE-2011-0761 EXP Perl 5.10.x allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) by leveraging an ability… Patch early 5.0 medium 8.9% 2011-05-13
CVE-2006-4829 EXP Multiple cross-site scripting (XSS) vulnerabilities in David Czarnecki Blojsom 2.31 allow remote attackers to inject arbitrary web script or HTML via… Patch early 6.8 medium 8.9% 2006-09-15
CVE-2014-9000 EXP Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to… Patch early 6.5 medium 8.9% 2014-11-20
CVE-2019-19743 EXP On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal. Patch early 6.5 medium 8.9% 2019-12-16
CVE-2006-3104 EXP users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals the install… Patch early 5.0 medium 8.9% 2006-06-21
CVE-2007-5253 EXP c32web.exe in McMurtrey/Whitaker Cart32 before 6.4 allows remote attackers to read arbitrary files via the ImageName parameter in a GetImage action, b… Patch early 5.0 medium 8.9% 2007-10-06
CVE-2006-2175 EXP PHP remote file inclusion vulnerability in FtrainSoft Fast Click 2.3.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 6.4 medium 8.9% 2006-05-04
CVE-2013-0145 EXP Buffer overflow in the TFTPD service in Serva32 2.1.0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrar… Patch early 5.0 medium 8.9% 2013-05-20
CVE-2004-1444 EXP Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ com… Patch early 5.0 medium 8.9% 2004-12-31
CVE-2018-19287 EXP XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (… Patch early 6.1 medium 8.9% 2018-11-15
CVE-2002-2072 EXP java.security.AccessController in Sun Java Virtual Machine (JVM) in JRE 1.2.2 and 1.3.1 allows remote attackers to cause a denial of service (JVM cras… Patch early 5.0 medium 8.9% 2002-12-31
CVE-2007-3619 EXP Directory traversal vulnerability in login.php in Maia Mailguard 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 5.0 medium 8.9% 2007-07-09
CVE-2014-4937 EXP Directory traversal vulnerability in includes/bookx_export.php BookX plugin 1.7 for WordPress allows remote attackers to read arbitrary files via a ..… Patch early 5.0 medium 8.9% 2014-07-11
CVE-2001-1303 EXP The default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain sensitive configuration information for the prote… Patch early 5.0 medium 8.8% 2001-07-18
CVE-2008-5498 EXP Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the contents of arbitrary memory loc… Patch early 5.0 medium 8.8% 2008-12-26
CVE-2002-1224 EXP Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary files as the kpf user via a URL wi… Patch early 5.0 medium 8.8% 2002-10-28
CVE-2010-4349 EXP admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to obtain sensitive information via an invalid db_type parameter, which… Patch early 5.0 medium 8.8% 2011-01-03
CVE-2010-1677 EXP MHonArc 2.6.16 allows remote attackers to cause a denial of service (CPU consumption) via start tags that are placed within other start tags, as demon… Patch early 5.0 medium 8.8% 2011-01-03
CVE-2005-4385 EXP Cross-site scripting (XSS) vulnerability in search.htm in Cofax 2.0 RC3 and earlier allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 8.8% 2005-12-20
CVE-2004-0375 EXP SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall 5.01 and 5.1.1, and Client Sec… Patch early 5.0 medium 8.8% 2004-08-18
CVE-2020-8615 EXP A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing… Patch early 6.5 medium 8.8% 2020-02-04
CVE-2007-6323 EXP Multiple directory traversal vulnerabilities in MMS Gallery PHP 1.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parame… Patch early 5.0 medium 8.8% 2007-12-13
CVE-2009-1201 EXP Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances (ASA) device with sof… Patch early 4.3 medium 8.8% 2009-06-25
← previous page 66 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt