peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,165 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

169,602 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2003-1137 EXP Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an as… Patch early 5.0 medium 6.8% 2003-10-27
CVE-2015-4040 EXP Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 through 3.1.1 allows remote aut… Patch early 4.0 medium 6.8% 2015-09-17
CVE-2007-6213 EXP Multiple directory traversal vulnerabilities in mod/chat/index.php in WebED 0.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in… Patch early 5.0 medium 6.8% 2007-12-04
CVE-2006-2437 EXP The viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to obtain the source code for… Patch early 5.0 medium 6.8% 2006-05-17
CVE-2006-2768 EXP PHP remote file inclusion vulnerability in METAjour 2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via t… Patch early 5.1 medium 6.7% 2006-06-02
CVE-2000-0016 EXP Buffer overflow in Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service or execute commands via a long username. Patch early 5.0 medium 6.7% 1999-10-01
CVE-2003-0413 EXP Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Su… Patch early 6.8 medium 6.7% 2003-06-30
CVE-2005-1125 EXP Race condition in libsafe 2.0.16 and earlier, when running in multi-threaded applications, allows attackers to bypass libsafe protection and exploit o… Patch early 5.1 medium 6.7% 2005-05-02
CVE-2017-7089 EXP An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected.… Patch early 6.1 medium 6.7% 2017-10-23
CVE-2022-36551 EXP A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authen… Patch early 6.5 medium 6.7% 2022-10-03
CVE-2007-6620 EXP Directory traversal vulnerability in include/images.inc.php in Joovili 2.x allows remote attackers to read arbitrary files via a .. (dot dot) in the p… Patch early 6.4 medium 6.7% 2008-01-04
CVE-2006-3814 EXP Buffer overflow in the Loader_XM::load_instrument_internal function in loader_xm.cpp for Cheese Tracker 0.9.9 and earlier allows user-assisted attacke… Patch early 5.1 medium 6.7% 2006-07-25
CVE-2006-6426 EXP PHP remote file inclusion vulnerability in design/thinkedit/render.php in ThinkEdit 1.9.2 and earlier, when register_globals is enabled, allows remote… Patch early 6.8 medium 6.7% 2006-12-10
CVE-2010-3468 EXP Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CMS 5 through 5.2, allows remote… Patch early 5.0 medium 6.7% 2010-09-29
CVE-2006-1336 EXP Cross-site scripting vulnerability in calendar.php in ExtCalendar 1.0 and possibly other versions before 2.0 allows remote attackers to inject arbitra… Patch early 5.0 medium 6.7% 2006-03-21
CVE-2006-3561 EXP BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication p… Patch early 5.0 medium 6.7% 2006-07-13
CVE-2008-7062 EXP Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows remote attackers to execute ar… Patch early 6.8 medium 6.7% 2009-08-25
CVE-2015-8309 EXP Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to… Patch early 4.3 medium 6.7% 2017-03-27
CVE-2007-6105 EXP Multiple PHP remote file inclusion vulnerabilities in TalkBack 2.2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) languag… Patch early 6.8 medium 6.7% 2007-11-23
CVE-2015-4668 EXP Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attack… Patch early 6.1 medium 6.7% 2017-09-25
CVE-2018-7706 EXP Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via a ..… Patch early 6.5 medium 6.7% 2018-03-15
CVE-2001-0206 EXP Directory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by inserting a .. (dot dot) or ... into… Patch early 5.0 medium 6.7% 2001-06-02
CVE-2015-6996 EXP IOAcceleratorFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code or cause a denia… Patch early 6.8 medium 6.7% 2015-10-23
CVE-2008-6843 EXP Directory traversal vulnerability in index.php in Fantastico, as used with cPanel 11.x, allows remote attackers to read arbitrary files via a .. (dot… Patch early 5.0 medium 6.7% 2009-07-02
CVE-2010-2006 EXP Directory traversal vulnerability in op/op.Login.php in LetoDMS (formerly MyDMS) 1.7.2 and earlier allows remote authenticated users to include and ex… Patch early 6.5 medium 6.7% 2010-05-20
CVE-2019-8663 EXP This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6. A remote attacker may be able to leak memory. Patch early 5.3 medium 6.7% 2019-12-18
CVE-2002-1986 EXP Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP request with a trailing dot ("."). Patch early 5.0 medium 6.7% 2002-12-31
CVE-2004-2385 EXP EMU Webmail 5.2.7 allows remote attackers to obtain sensitive path information (home directory) via an HTTP request for init.emu. Patch early 5.0 medium 6.7% 2004-12-31
CVE-2006-0700 EXP imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists f… Patch early 5.0 medium 6.7% 2006-02-15
CVE-2007-2005 EXP Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary P… Patch early 6.8 medium 6.7% 2007-04-12
← previous page 94 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt