peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,047 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-1374 EXP Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to… Patch early 6.8 medium 4.9% 2005-05-03
CVE-2009-1469 EXP CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and WebMail Server before 9.4.2 makes… Patch early 4.3 medium 4.9% 2009-05-05
CVE-2006-1413 EXP Multiple cross-site scripting (XSS) vulnerabilities in EZHomepagePro 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 4.9% 2006-03-28
CVE-2015-8703 EXP ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authenticated users to bypass inten… Patch early 6.5 medium 4.9% 2015-12-30
CVE-2012-0869 EXP Cross-site scripting (XSS) vulnerability in fup in Frams' Fast File EXchange (F*EX, aka fex) before 20120215 allows remote attackers to inject arbitra… Patch early 4.3 medium 4.9% 2012-09-25
CVE-2014-1841 EXP Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to copy an arbitrary user's… Patch early 5.0 medium 4.9% 2014-04-29
CVE-2007-1563 EXP The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to connect to other servers, perfor… Patch early 6.8 medium 4.8% 2007-03-21
CVE-2005-4417 EXP The default configuration of Widcomm Bluetooth for Windows (BTW) 4.0.1.1500 and earlier, as installed on Belkin Bluetooth Software 1.4.2 Build 10 and… Patch early 6.4 medium 4.8% 2005-12-20
CVE-2008-3261 EXP Open redirect vulnerability in claroline/redirector.php in Claroline before 1.8.10 allows remote attackers to redirect users to arbitrary web sites an… Patch early 4.3 medium 4.8% 2008-07-22
CVE-2010-2680 EXP Directory traversal vulnerability in the JExtensions JE Section/Property Finder (jesectionfinder) component for Joomla! allows remote attackers to inc… Patch early 6.8 medium 4.8% 2010-07-12
CVE-2010-2857 EXP Directory traversal vulnerability in the Music Manager component for Joomla! allows remote attackers to read arbitrary files and possibly have unspeci… Patch early 6.8 medium 4.8% 2010-07-25
CVE-2013-3242 EXP plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializin… Patch early 5.5 medium 4.8% 2013-05-03
CVE-2011-5214 EXP Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 4.8% 2012-10-25
CVE-2014-2879 EXP Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to in… Patch early 4.3 medium 4.8% 2014-04-17
CVE-2016-10258 EXP Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administra… Patch early 6.8 medium 4.8% 2018-04-11
CVE-2017-18256 EXP Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert() argument in JavaScript code… Patch early 6.5 medium 4.8% 2018-04-04
CVE-2012-0904 EXP VLC media player 1.1.11 allows remote attackers to cause a denial of service (crash) via a long string in an amr file. Patch early 4.3 medium 4.8% 2012-01-20
CVE-2005-0443 EXP index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks v… Patch early 4.3 medium 4.8% 2005-05-02
CVE-2007-4528 EXP The Foreign Function Interface (ffi) extension in PHP 5.0.5 does not follow safe_mode restrictions, which allows context-dependent attackers to execut… Patch early 4.3 medium 4.8% 2007-08-25
CVE-2011-5148 EXP Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote attack… Patch early 6.8 medium 4.8% 2012-08-31
CVE-2017-11333 EXP The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted… Patch early 5.5 medium 4.8% 2017-07-31
CVE-2006-0971 EXP Directory traversal vulnerability in Lionel Reyero DirectContact 0.3b allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. Patch early 5.0 medium 4.8% 2006-03-03
CVE-2007-2144 EXP PHP remote file inclusion vulnerability in includes/CAltInstaller.php in the JoomlaPack (com_jpack) 1.0.4a2 RE component for Joomla! allows remote att… Patch early 6.8 medium 4.8% 2007-04-19
CVE-2010-3449 EXP Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1… Patch early 6.8 medium 4.8% 2010-12-06
CVE-2009-0442 EXP Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute arbitrary local files via a .… Patch early 6.8 medium 4.8% 2009-02-10
CVE-2003-1256 EXP aff_liste_langue.php in E-theni allows remote attackers to execute arbitrary PHP code by modifying the rep_include parameter to reference a URL on a r… Patch early 6.8 medium 4.8% 2003-12-31
CVE-2004-0322 EXP Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1)… Patch early 4.3 medium 4.8% 2004-02-23
CVE-2009-3535 EXP Directory traversal vulnerability in image.php in Clear Content 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the url para… Patch early 4.3 medium 4.8% 2009-10-02
CVE-2009-3701 EXP Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in Horde Application Framework before 3.3.6, Horde Groupware befor… Patch early 4.3 medium 4.8% 2009-12-21
CVE-2018-20326 EXP ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage=html/index.html var:subpage p… Patch early 6.1 medium 4.8% 2019-01-02
← previous page 115 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt