peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,534 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

169,340 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-2330 EXP PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary… Patch early 6.4 medium 7.8% 2006-05-12
CVE-2007-1362 EXP Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to cause a denial of service via… Patch early 4.3 medium 7.8% 2007-06-01
CVE-2007-2425 EXP Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the album par… Patch early 5.0 medium 7.8% 2007-05-02
CVE-2007-2611 EXP Multiple PHP remote file inclusion vulnerabilities in CGX 20050314 allow remote attackers to execute arbitrary PHP code via a URL in the pathCGX param… Patch early 6.8 medium 7.8% 2007-05-11
CVE-2005-3293 EXP Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory contents via a… Patch early 5.0 medium 7.8% 2005-10-23
CVE-2008-1488 EXP Stack-based buffer overflow in apc.c in Alternative PHP Cache (APC) 3.0.11 through 3.0.16 allows remote attackers to execute arbitrary code via a long… Patch early 6.8 medium 7.8% 2008-03-24
CVE-2006-1784 EXP PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote attackers… Patch early 5.1 medium 7.8% 2006-04-13
CVE-2009-2478 EXP Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors, rel… Patch early 5.0 medium 7.8% 2009-07-16
CVE-2017-6805 EXP Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read arbitrary files via a .. (dot d… Patch early 5.3 medium 7.8% 2017-03-20
CVE-2009-1353 EXP Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause a denial of service (daemon cr… Patch early 5.0 medium 7.8% 2009-04-21
CVE-2005-2719 EXP Ventrilo 2.1.2 through 2.3.0 allows remote attackers to cause a denial of service (application crash) via a status packet that contains less data than… Patch early 5.0 medium 7.8% 2005-08-30
CVE-2008-6713 EXP World in Conflict (WIC) 1.008 and earlier allows remote attackers to cause a denial of service (access violation and crash) via a zero-byte data block… Patch early 5.0 medium 7.8% 2009-04-10
CVE-2000-0423 EXP Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd, and utag. Patch early 5.0 medium 7.8% 2000-05-05
CVE-2009-3242 EXP Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2.0 and 1.2.1 allows remote attackers to cause a denial of service (app… Patch early 5.0 medium 7.8% 2009-09-18
CVE-2018-12979 EXP An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions allow an authenticated user t… Patch early 6.5 medium 7.8% 2018-07-12
CVE-2000-0282 EXP TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webpl… Patch early 5.0 medium 7.8% 2000-04-12
CVE-2002-1432 EXP MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly r… Patch early 5.0 medium 7.8% 2003-04-11
CVE-2006-0714 EXP Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbitrary file… Patch early 5.0 medium 7.8% 2006-02-15
CVE-2009-5026 EXP The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave i… Patch early 6.8 medium 7.8% 2012-08-17
CVE-2003-1263 EXP ICAL.EXE in iCal 3.7 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, possibly due to an invalid method name… Patch early 5.0 medium 7.8% 2003-12-31
CVE-2005-1703 EXP Warrior Kings: Battles 1.23 and earlier allows remote attackers to cause a denial of service (server crash) via a partial join packet that triggers a… Patch early 5.0 medium 7.7% 2005-05-24
CVE-2008-4514 EXP The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a font tag with a long color value… Patch early 5.0 medium 7.7% 2008-10-09
CVE-2015-2169 EXP Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attackers to inject arbitrary web scri… Patch early 4.3 medium 7.7% 2015-06-24
CVE-2004-2507 EXP Absolute path traversal vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to read arbitrary files v… Patch early 5.0 medium 7.7% 2004-12-31
CVE-2011-4643 EXP Multiple directory traversal vulnerabilities in Splunk 4.x before 4.2.5 allow remote authenticated users to read arbitrary files via a .. (dot dot) in… Patch early 4.0 medium 7.7% 2012-01-03
CVE-2006-4850 EXP PHP remote file inclusion vulnerability in system/_b/contentFiles/gBIndex.php in BolinOS 4.5.5 and earlier allows remote attackers to execute arbitrar… Patch early 5.1 medium 7.7% 2006-09-19
CVE-2012-4889 EXP Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 7.7% 2012-09-10
CVE-2008-0767 EXP ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain "number of URLs" field is consistent with the… Patch early 5.0 medium 7.7% 2008-02-13
CVE-2008-3396 EXP Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via… Patch early 5.0 medium 7.7% 2008-07-31
CVE-2003-1386 EXP AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displ… Patch early 6.4 medium 7.7% 2003-12-31
← previous page 78 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt