peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,646 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

205,949 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-0943 EXP Directory traversal vulnerability in the JA Showcase (com_jashowcase) component for Joomla! allows remote attackers to read arbitrary files via a .. (… Patch early 5.0 medium 15.9% 2010-03-08
CVE-2020-23935 EXP Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)". Patch early 9.8 critical 15.9% 2020-08-20
CVE-2005-3299 EXP PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__r… Patch early 5.0 medium 15.9% 2005-10-23
CVE-2010-1314 EXP Directory traversal vulnerability in the Highslide JS (com_hsconfig) component 1.5 and 2.0.9 for Joomla! allows remote attackers to read arbitrary fil… Patch early 5.0 medium 15.9% 2010-04-08
CVE-2010-1354 EXP Directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .… Patch early 5.0 medium 15.9% 2010-04-12
CVE-2018-9842 EXP CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message. Patch early 5.3 medium 15.9% 2018-04-12
CVE-2009-3898 EXP Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows rem… Patch early 4.9 medium 15.9% 2009-11-24
CVE-2024-30269 EXP DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0.… Patch early 5.3 medium 15.9% 2024-04-08
CVE-2005-1524 EXP PHP file inclusion vulnerability in top_graph_header.php in Cacti 0.8.6d and possibly earlier versions allows remote attackers to execute arbitrary PH… Patch early 5.0 medium 15.9% 2005-06-22
CVE-2011-0518 EXP Directory traversal vulnerability in core/lib/router.php in LotusCMS Fraise 3.0, when magic_quotes_gpc is disabled, allows remote attackers to include… Patch early 5.1 medium 15.8% 2011-01-20
CVE-2007-3855 EXP Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to have… Patch early 6.5 medium 15.8% 2007-07-18
CVE-2020-10230 EXP CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parame… Patch early 9.8 critical 15.8% 2020-03-16
CVE-2016-7866 EXP Adobe Animate versions 15.2.1.95 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code… Patch early 9.8 critical 15.8% 2016-12-15
CVE-2017-3549 EXP Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Supported versions that are affec… Patch early 9.1 critical 15.8% 2017-04-24
CVE-2025-4094 EXP The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightfo… Patch early 9.8 critical 15.8% 2025-05-21
CVE-2009-0543 EXP ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte c… Patch early 6.8 medium 15.8% 2009-02-12
CVE-2006-6310 EXP Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash) via an invalid src attribute value ("?")… Patch early 5.0 medium 15.8% 2006-12-06
CVE-2021-46379 EXP DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site. Patch early 6.1 medium 15.8% 2022-03-04
CVE-2004-0173 EXP Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read… Patch early 5.0 medium 15.8% 2004-04-15
CVE-2002-0862 EXP The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products includi… Patch early 6.8 medium 15.8% 2002-10-04
CVE-2015-3623 EXP XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forgery (SSRF) a… Patch early 6.4 medium 15.8% 2015-09-16
CVE-2006-5048 EXP Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier for Joomla! allow remote attack… Patch early 6.8 medium 15.8% 2006-09-27
CVE-2022-2651 EXP Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5. Patch early 9.8 critical 15.8% 2022-08-04
CVE-2021-43136 EXP An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platfor… Patch early 9.8 critical 15.7% 2021-11-10
CVE-2004-1325 EXP The getItemInfoByAtom function in the ActiveX control for Microsoft Windows Media Player 9.0 returns a 0 if the file does not exist and the size of th… Patch early 5.0 medium 15.7% 2004-12-18
CVE-2008-4327 EXP gdiplus.dll in GDI+ in Microsoft Windows XP SP3 does not properly handle crafted .ico files, which allows remote attackers to cause a denial of servic… Patch early 4.3 medium 15.7% 2008-09-30
CVE-2000-0200 EXP Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art l… Patch early 5.1 medium 15.7% 2000-03-06
CVE-2019-14696 EXP Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter. Patch early 6.1 medium 15.7% 2019-08-06
CVE-2008-3443 EXP The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows re… Patch early 5.0 medium 15.7% 2008-08-14
CVE-2007-2356 EXP Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attackers to e… Patch early 6.8 medium 15.7% 2007-04-30
← previous page 84 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt