peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,157 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

169,597 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-8283 EXP Directory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00. Patch early 6.5 medium 6.8% 2017-04-13
CVE-2005-2075 EXP PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows… Patch early 5.0 medium 6.8% 2005-06-29
CVE-2006-2180 EXP Buffer overflow in Golden FTP Server Pro 2.70 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via… Patch early 6.4 medium 6.8% 2006-05-04
CVE-2014-2612 EXP Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux… Patch early 4.0 medium 6.8% 2014-06-28
CVE-2004-1947 EXP The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as s… Patch early 5.0 medium 6.8% 2004-04-19
CVE-2010-0982 EXP Directory traversal vulnerability in the CARTwebERP (com_cartweberp) component 1.56.75 for Joomla! allows remote attackers to read arbitrary files via… Patch early 4.3 medium 6.8% 2010-03-16
CVE-2003-0726 EXP RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation with a URL that references a scri… Patch early 5.1 medium 6.8% 2003-10-20
CVE-2007-2659 EXP Directory traversal vulnerability in index.php in PHP Advanced Transfer Manager (phpATM) 1.30 allows remote attackers to read arbitrary files and obta… Patch early 5.0 medium 6.8% 2007-05-14
CVE-2006-3636 EXP Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspe… Patch early 6.8 medium 6.8% 2006-09-06
CVE-2015-1389 EXP Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote attackers to inject arbitrary we… Patch early 4.3 medium 6.8% 2015-05-28
CVE-2020-8865 EXP This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authenticat… Patch early 6.3 medium 6.8% 2020-03-23
CVE-2007-3957 EXP Buffer overflow in Nipun Jain xserver 0.1 alpha allows remote attackers to cause a denial of service via a POST request with a long URI. Patch early 5.0 medium 6.8% 2007-07-24
CVE-2006-2310 EXP BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to cause a denial of service (hang) via a request for a .cfm file whose… Patch early 5.0 medium 6.8% 2006-06-26
CVE-2008-1052 EXP The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large… Patch early 6.4 medium 6.8% 2008-02-27
CVE-2008-6423 EXP Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and earlier allows remote attackers to read arbitrary local files via a .. (d… Patch early 5.0 medium 6.8% 2009-03-06
CVE-2006-2745 EXP Multiple PHP remote file inclusion vulnerabilities in F@cile Interactive Web 0.8.5 and earlier, when register_globals is enabled, allow remote attacke… Patch early 5.1 medium 6.8% 2006-06-01
CVE-2014-1908 EXP The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugi… Patch early 5.0 medium 6.8% 2014-12-29
CVE-2002-1818 EXP ezhttpbench.php in eZ httpbench 1.1 allows remote attackers to read arbitrary files via a full pathname in the AnalyseSite parameter. Patch early 5.0 medium 6.8% 2002-12-31
CVE-2003-1242 EXP Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path in an error… Patch early 5.0 medium 6.8% 2003-12-31
CVE-2013-6835 EXP TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remote… Patch early 5.0 medium 6.8% 2014-03-14
CVE-1999-0934 EXP classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters. Patch early 5.0 medium 6.8% 1999-12-15
CVE-2009-2557 EXP Directory traversal vulnerability in system/download.php in Admin News Tools 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in… Patch early 5.0 medium 6.8% 2009-07-21
CVE-2017-15639 EXP tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature. Patch early 6.5 medium 6.8% 2017-10-19
CVE-2003-0488 EXP Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) the add_na… Patch early 5.1 medium 6.8% 2003-08-07
CVE-2015-3001 EXP SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which allows remote authenticated user… Patch early 5.0 medium 6.8% 2015-06-08
CVE-2006-4875 EXP Unrestricted file upload vulnerability in modules/galleryuploadfunction.php in Jupiter CMS allows remote attackers to upload picture files, and possib… Patch early 5.0 medium 6.8% 2006-09-19
CVE-2006-6288 EXP Multiple buffer overflows in Niek Albers CoolPlayer 216 and earlier allow remote attackers to execute arbitrary code via (1) a playlist file with long… Patch early 4.6 medium 6.8% 2006-12-04
CVE-2020-2229 EXP Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS)… Patch early 5.4 medium 6.8% 2020-08-12
CVE-2015-8740 EXP The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x before 2.0.1 does not validate the… Patch early 5.3 medium 6.8% 2016-01-04
CVE-2014-8657 EXP The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to cause a den… Patch early 5.0 medium 6.8% 2014-11-06
← previous page 93 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt