peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,058 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-4881 EXP Multiple cross-site scripting (XSS) vulnerabilities in David Bennett PHP-Post (PHPp) 1.0 and earlier allow remote attackers to inject arbitrary web sc… Patch early 4.3 medium 4.8% 2006-09-19
CVE-2009-2736 EXP Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators to inject arbitrary PHP code in… Patch early 6.5 medium 4.8% 2009-08-11
CVE-2006-5653 EXP Cross-site scripting (XSS) vulnerability in the errorHTML function in the index script in Sun Java System Messenger Express 6 allows remote attackers… Patch early 4.3 medium 4.8% 2006-11-03
CVE-2017-15646 EXP Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote URL' option t… Patch early 6.1 medium 4.8% 2017-10-19
CVE-2017-15374 EXP Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management system backend modules. Remot… Patch early 6.1 medium 4.8% 2017-10-16
CVE-2008-2751 EXP Multiple cross-site scripting (XSS) vulnerabilities in the Glassfish webadmin interface in Sun Java System Application Server 9.1_01 allow remote atta… Patch early 4.3 medium 4.8% 2008-06-18
CVE-2009-0643 EXP Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary PHP code into news.txt via th… Patch early 5.1 medium 4.8% 2009-02-20
CVE-2008-6956 EXP Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code int… Patch early 6.5 medium 4.8% 2009-08-12
CVE-2004-2748 EXP viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid pr… Patch early 4.3 medium 4.8% 2004-12-31
CVE-2009-2852 EXP WP-Syntax plugin 0.9.1 and earlier for Wordpress, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via the test_fi… Patch early 6.8 medium 4.8% 2009-08-18
CVE-2010-2349 EXP H264WebCam 3.7 allows remote attackers to cause a denial of service (crash) via a long URI in a GET request, which triggers a NULL pointer dereference… Patch early 5.0 medium 4.8% 2010-06-21
CVE-2018-9163 EXP A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users… Patch early 5.4 medium 4.8% 2018-04-02
CVE-2008-6995 EXP Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a denial of service (browser crash)… Patch early 4.3 medium 4.8% 2009-08-19
CVE-2019-9622 EXP eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as demonstrated by reading the use… Patch early 4.3 medium 4.8% 2019-03-07
CVE-2017-0299 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 4.8% 2017-06-15
CVE-1999-0751 EXP Buffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch. Patch early 5.0 medium 4.8% 1999-09-13
CVE-2012-0834 EXP Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web scri… Patch early 4.3 medium 4.8% 2012-02-11
CVE-2008-0661 EXP Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file with a long URI. NOTE: this mig… Patch early 6.8 medium 4.8% 2008-02-08
CVE-2010-3003 EXP Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote attackers to inject arbitrary… Patch early 4.3 medium 4.8% 2010-09-10
CVE-2011-3579 EXP server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly send HTTP req… Patch early 6.4 medium 4.8% 2011-09-30
CVE-2020-28413 EXP In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP. Patch early 5.3 medium 4.8% 2020-12-30
CVE-2017-13855 EXP An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchO… Patch early 5.5 medium 4.8% 2017-12-25
CVE-2008-0138 EXP PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows… Patch early 6.8 medium 4.8% 2008-01-08
CVE-2004-2334 EXP Multiple cross-site scripting (XSS) vulnerabilities in EMU Webmail 5.2.7 allow remote attackers to inject arbitrary web script or HTML via (1) a hex-e… Patch early 4.3 medium 4.8% 2004-12-31
CVE-2005-3959 EXP Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0 rev37 allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 4.3 medium 4.8% 2005-12-01
CVE-2006-3883 EXP Multiple cross-site scripting (XSS) vulnerabilities in Gonafish LinksCaffe 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) t… Patch early 4.3 medium 4.8% 2006-07-27
CVE-2007-5692 EXP Multiple cross-site scripting (XSS) vulnerabilities in SiteBar 3.3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the lang pa… Patch early 4.3 medium 4.8% 2007-10-29
CVE-2011-4273 EXP Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary web script or HTML via (1) th… Patch early 4.3 medium 4.8% 2011-11-03
CVE-2007-4257 EXP Multiple buffer overflows in Live for Speed (LFS) S1 and S2 allow user-assisted remote attackers to execute arbitrary code via (1) a .spr file (single… Patch early 6.8 medium 4.8% 2007-08-08
CVE-2019-7439 EXP cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter. Patch early 6.5 medium 4.8% 2019-03-21
← previous page 116 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt