peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,486 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

169,328 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2001-0295 EXP Directory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly read files via a "dir *./../.." c… Patch early 5.0 medium 8.1% 2001-05-03
CVE-2001-0924 EXP Directory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary files via a .. (dot dot) in t… Patch early 5.0 medium 8.1% 2001-11-22
CVE-2006-1470 EXP OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an… Patch early 5.0 medium 8.1% 2006-06-27
CVE-2009-0497 EXP Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\ (dot dot back… Patch early 5.0 medium 8.1% 2009-02-10
CVE-2012-0389 EXP Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in MailEnable Professional, Enterprise, and Premium 4.26 and earlier, 5.x before 5.… Patch early 4.3 medium 8.1% 2012-01-24
CVE-2004-1937 EXP Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbitrary files via .. sequences in… Patch early 5.0 medium 8.1% 2004-12-31
CVE-2004-2640 EXP Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequence… Patch early 5.0 medium 8.1% 2004-12-31
CVE-2017-3132 EXP A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the… Patch early 6.1 medium 8.1% 2017-09-12
CVE-2009-4050 EXP Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 allows remote attackers to read arbitrary files via directory traversal sequen… Patch early 5.0 medium 8.1% 2009-11-23
CVE-2002-2084 EXP Directory traversal vulnerability in index.php of Portix 0.4.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) l and (2… Patch early 5.0 medium 8.1% 2002-12-31
CVE-2005-4208 EXP Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id… Patch early 5.0 medium 8.1% 2005-12-13
CVE-2008-0625 EXP Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attackers to execute arbitrary code vi… Patch early 4.3 medium 8.1% 2008-02-06
CVE-2008-1119 EXP Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .… Patch early 5.0 medium 8.1% 2008-03-03
CVE-2003-0277 EXP Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot… Patch early 5.0 medium 8.1% 2003-06-16
CVE-2001-1408 EXP Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 5.0 medium 8.1% 2001-07-05
CVE-2004-1951 EXP xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) aud… Patch early 5.0 medium 8.1% 2004-12-31
CVE-2004-2184 EXP Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write arbitrary files via "../" or "..… Patch early 6.4 medium 8.1% 2004-12-31
CVE-2004-1699 EXP SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter… Patch early 5.0 medium 8.1% 2004-09-21
CVE-2004-0269 EXP SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive inf… Patch early 6.4 medium 8.1% 2004-11-23
CVE-2016-9018 EXP Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlaye… Patch early 5.5 medium 8.1% 2016-10-28
CVE-2006-4955 EXP Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via… Patch early 5.0 medium 8.1% 2006-09-23
CVE-2007-3006 EXP Buffer overflow in Acoustica MP3 CD Burner 4.32 allows user-assisted remote attackers to execute arbitrary code via a .asx playlist file with a REF el… Patch early 6.8 medium 8.1% 2007-06-04
CVE-2010-1128 EXP The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attack… Patch early 6.4 medium 8.1% 2010-03-26
CVE-2000-0242 EXP WindMail allows remote attackers to read arbitrary files or execute commands via shell metacharacters. Patch early 5.0 medium 8.1% 2000-03-25
CVE-2008-7248 EXP Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to… Patch early 6.8 medium 8.1% 2009-12-16
CVE-2018-10077 EXP XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to read arbitrary files via crafted… Patch early 4.9 medium 8.1% 2018-04-20
CVE-2009-5029 EXP Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possib… Patch early 6.8 medium 8.1% 2013-05-02
CVE-2007-3947 EXP request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as… Patch early 5.8 medium 8.1% 2007-07-24
CVE-2005-0698 EXP PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) G_PA… Patch early 4.6 medium 8.1% 2005-03-07
CVE-2014-8493 EXP ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to Forms/access_cwmp_1. Patch early 5.0 medium 8.1% 2014-11-20
← previous page 74 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt