peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,045 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-3748 EXP PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and possibly other versions includi… Patch early 6.8 medium 5% 2006-07-21
CVE-2004-0591 EXP Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to… Patch early 6.8 medium 5% 2004-08-06
CVE-2010-2129 EXP Directory traversal vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.1 and 1.0.3 for Joomla! allows remote attacker… Patch early 6.8 medium 5% 2010-06-01
CVE-2007-1020 EXP Cross-site scripting (XSS) vulnerability in index.php in CedStat 1.31 allows remote attackers to inject arbitrary web script or HTML via the hier para… Patch early 6.8 medium 5% 2007-02-21
CVE-2005-1380 EXP Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server param… Patch early 6.8 medium 5% 2005-05-03
CVE-2008-6253 EXP Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allows remote attackers to include… Patch early 6.8 medium 5% 2009-02-24
CVE-2007-3060 EXP Multiple cross-site scripting (XSS) vulnerabilities in PHP Live! 3.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) sid p… Patch early 4.3 medium 5% 2007-06-06
CVE-2013-4868 EXP Karotz API 12.07.19.00: Session Token Information Disclosure Patch early 5.3 medium 5% 2019-12-27
CVE-2007-6103 EXP I Hear U (IHU) 0.5.6 and earlier allows remote attackers to cause (1) a denial of service (infinite loop) via a packet that contains zero in the size… Patch early 5.0 medium 5% 2007-11-23
CVE-2017-0300 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 5% 2017-06-15
CVE-2007-1702 EXP PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote attackers to execute arbitrary… Patch early 6.8 medium 5% 2007-03-27
CVE-2013-7387 EXP Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions via the PHPSESSID cookie. Patch early 6.8 medium 5% 2014-06-02
CVE-2010-2630 EXP The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate the data types of codec-specific tags that have an out-of-order position in… Patch early 4.3 medium 5% 2010-07-06
CVE-2017-4916 EXP VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issu… Patch early 6.5 medium 5% 2017-05-22
CVE-2009-1915 EXP Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial of service (persistent crash)… Patch early 4.3 medium 5% 2009-06-04
CVE-2006-0315 EXP index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote… Patch early 5.8 medium 4.9% 2006-01-19
CVE-2007-1474 EXP Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users… Patch early 6.8 medium 4.9% 2007-03-16
CVE-2008-3140 EXP The syslog dissector in Wireshark (formerly Ethereal) 1.0.0 allows remote attackers to cause a denial of service (application crash) via unknown vecto… Patch early 5.0 medium 4.9% 2008-07-10
CVE-2017-15014 EXP OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows authenticated… Patch early 4.3 medium 4.9% 2017-10-13
CVE-2004-1075 EXP Cross-site scripting (XSS) vulnerability in standard_error_message.dtml for Zwiki after 0.10.0rc1 to 0.36.2 allows remote attackers to inject arbitrar… Patch early 6.8 medium 4.9% 2005-01-10
CVE-2006-5763 EXP Multiple PHP remote file inclusion vulnerabilities in Free File Hosting 1.1, and possibly earlier, when register_globals is enabled, allow remote atta… Patch early 5.1 medium 4.9% 2006-11-06
CVE-2012-2698 EXP Cross-site scripting (XSS) vulnerability in the outputPage function in includes/SkinTemplate.php in MediaWiki before 1.17.5, 1.18.x before 1.18.4, and… Patch early 4.3 medium 4.9% 2012-06-29
CVE-2021-26929 EXP An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker… Patch early 6.1 medium 4.9% 2021-02-14
CVE-2002-0031 EXP Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsgr URI with long arguments to (… Patch early 4.6 medium 4.9% 2002-07-26
CVE-2003-1085 EXP The HTTP server in the Thomson TWC305, TWC315, and TCW690 cable modem ST42.03.0a allows remote attackers to cause a denial of service (unstable servic… Patch early 5.0 medium 4.9% 2003-12-31
CVE-2007-1540 EXP Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to run arbitr… Patch early 4.3 medium 4.9% 2007-03-20
CVE-2019-11370 EXP Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" field. Patch early 5.4 medium 4.9% 2019-06-03
CVE-2001-0484 EXP Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which all… Patch early 6.4 medium 4.9% 2001-06-27
CVE-2008-6769 EXP Unrestricted file upload vulnerability in upload.php in YourPlace 1.0.2 and earlier allows remote authenticated users to execute arbitrary code by upl… Patch early 6.0 medium 4.9% 2009-04-29
CVE-2008-0466 EXP Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authenticati… Patch early 5.0 medium 4.9% 2008-01-29
← previous page 113 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt