peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,584 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

169,343 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-1244 EXP Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions… Patch early 6.8 medium 7.5% 2007-03-03
CVE-2008-0149 EXP TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls the phpinfo function. Patch early 5.0 medium 7.5% 2008-01-09
CVE-2004-1533 EXP Buffer overflow in pop3svr.exe for DMS POP3 1.5.3.27 and earlier allows remote attackers to cause a denial of service (service crash) via a long (1) u… Patch early 5.0 medium 7.5% 2004-12-31
CVE-2002-1905 EXP Buffer overflow in the web server of Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (crash) via a long HTTP GET req… Patch early 5.0 medium 7.5% 2002-12-31
CVE-2006-2483 EXP PHP remote file inclusion vulnerability in cart_content.php in Squirrelcart 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code vi… Patch early 6.4 medium 7.5% 2006-05-19
CVE-2011-4881 EXP The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly check return values from functions, which allows remote attackers… Patch early 5.0 medium 7.5% 2012-04-13
CVE-2006-5031 EXP Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read… Patch early 5.0 medium 7.5% 2006-09-27
CVE-1999-0467 EXP The Webcom CGI Guestbook programs wguest.exe and rguest.exe allow a remote attacker to read arbitrary files using the "template" parameter. Patch early 5.0 medium 7.5% 1999-04-01
CVE-2007-6369 EXP Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow remote attackers to read arbit… Patch early 5.0 medium 7.5% 2007-12-15
CVE-2010-0462 EXP Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impa… Patch early 6.5 medium 7.5% 2010-01-28
CVE-2023-3219 EXP The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allo… Patch early 5.3 medium 7.5% 2023-07-10
CVE-2005-0430 EXP The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash… Patch early 5.0 medium 7.5% 2005-02-12
CVE-2014-8949 EXP The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metacha… Patch early 6.0 medium 7.5% 2014-11-16
CVE-2007-3702 EXP Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier allows remote attackers to re… Patch early 5.0 medium 7.5% 2007-07-11
CVE-2011-0538 EXP Wireshark 1.2.0 through 1.2.14, 1.4.0 through 1.4.3, and 1.5.0 frees an uninitialized pointer during processing of a .pcap file in the pcap-ng format,… Patch early 6.8 medium 7.5% 2011-02-08
CVE-2007-0609 EXP Directory traversal vulnerability in Advanced Guestbook 2.4.2 allows remote attackers to bypass .htaccess settings, and execute arbitrary PHP local fi… Patch early 5.1 medium 7.5% 2007-05-09
CVE-2004-1643 EXP WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid path with a ".… Patch early 5.0 medium 7.5% 2004-08-29
CVE-2005-3929 EXP Directory traversal vulnerability in the create function in xarMLSXML2PHPBackend.php in Xaraya 1.0 allows remote attackers to create directories and o… Patch early 5.0 medium 7.5% 2005-11-30
CVE-2000-0411 EXP Matt Wright's FormMail CGI script allows remote attackers to obtain environmental variables via the env_report parameter. Patch early 5.0 medium 7.5% 2000-05-10
CVE-2007-6322 EXP Directory traversal vulnerability in filedownload.php in xml2owl 0.1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file… Patch early 5.0 medium 7.5% 2007-12-13
CVE-2006-4845 EXP PHP remote file inclusion vulnerability in includes/footer.html.inc.php in TeamCal Pro 2.8.001 and earlier allows remote attackers to execute arbitrar… Patch early 5.1 medium 7.5% 2006-09-19
CVE-2008-2326 EXP mDNSResponder in the Bonjour Namespace Provider in Apple Bonjour for Windows before 1.0.5 allows attackers to cause a denial of service (NULL pointer… Patch early 5.0 medium 7.5% 2008-09-11
CVE-2000-0588 EXP SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whose contents… Patch early 5.0 medium 7.5% 2000-06-26
CVE-2000-0872 EXP explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack. Patch early 5.0 medium 7.5% 2000-11-14
CVE-2000-1002 EXP POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid passwords, which allows remote at… Patch early 5.0 medium 7.5% 2000-12-11
CVE-2000-1092 EXP loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in… Patch early 5.0 medium 7.5% 2001-01-09
CVE-2001-0255 EXP FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including the drive letter name (e.g. C:… Patch early 5.0 medium 7.5% 2001-06-02
CVE-2017-9936 EXP In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service atta… Patch early 6.5 medium 7.5% 2017-06-26
CVE-2007-4718 EXP Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary local… Patch early 5.1 medium 7.5% 2007-09-05
CVE-2000-0183 EXP Buffer overflow in ircII 4.4 IRC client allows remote attackers to execute commands via the DCC chat capability. Patch early 5.1 medium 7.5% 2000-03-10
← previous page 82 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt