peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-1219 EXP CA 2E Web Option r8.1.2 accepts a predictable substring of a W2E_SSNID session token in place of the entire token, which allows remote attackers to hi… Patch early 5.1 medium 4.6% 2014-02-14
CVE-2003-0154 EXP Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, r… Patch early 6.8 medium 4.6% 2003-04-02
CVE-2008-0985 EXP Heap-based buffer overflow in the GIF library in the WebKit framework for Google Android SDK m3-rc37a and earlier allows remote attackers to execute a… Patch early 6.8 medium 4.6% 2008-03-06
CVE-2000-0480 EXP Dragon telnet server allows remote attackers to cause a denial of service via a long username. Patch early 5.0 medium 4.6% 2000-06-16
CVE-2004-2512 EXP CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting attacks to spo… Patch early 4.3 medium 4.6% 2004-12-31
CVE-2005-4449 EXP verify.php in FlatNuke 2.5.6 allows remote authenticated administrators to modify arbitrary PHP files by setting the file parameter to an arbitrary fi… Patch early 4.0 medium 4.6% 2005-12-21
CVE-2012-3996 EXP TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php,… Patch early 5.0 medium 4.6% 2012-07-12
CVE-2006-2928 EXP Multiple PHP remote file inclusion vulnerabilities in CMS-Bandits 2.5 and earlier, when register_globals is enabled, allow remote attackers to execute… Patch early 5.1 medium 4.6% 2006-06-09
CVE-2005-2472 EXP Multiple buffer overflows in BusinessMail 4.60.00 allow remote attackers to cause a denial of service (application crash) via a long string to SMTP (1… Patch early 5.0 medium 4.6% 2005-08-05
CVE-2007-5447 EXP ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_functions restrictions, which allow… Patch early 4.3 medium 4.6% 2007-10-14
CVE-2022-4407 EXP Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9. Patch early 6.1 medium 4.6% 2022-12-11
CVE-2013-7319 EXP Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web scr… Patch early 4.3 medium 4.6% 2014-02-06
CVE-2006-1709 EXP Cross-site scripting (XSS) vulnerability in shop_main.cgi in interaktiv.shop 5 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 6.8 medium 4.6% 2006-04-11
CVE-2013-3529 EXP Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote attackers… Patch early 4.3 medium 4.6% 2013-05-10
CVE-2007-6608 EXP Multiple cross-site scripting (XSS) vulnerabilities in OpenBiblio 0.5.2-pre4 and earlier allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 4.6% 2007-12-31
CVE-2007-3649 EXP Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Digital Imaging allows remote att… Patch early 6.8 medium 4.6% 2007-07-10
CVE-2015-8732 EXP The dissect_zcl_pwr_prof_pwrprofstatersp function in epan/dissectors/packet-zbee-zcl-general.c in the ZigBee ZCL dissector in Wireshark 1.12.x before… Patch early 5.5 medium 4.6% 2016-01-04
CVE-2013-5006 EXP main_internet.php on the Western Digital My Net N600 and N750 with firmware 1.03.12 and 1.04.16, and the N900 and N900C with firmware 1.05.12, 1.06.18… Patch early 4.3 medium 4.6% 2013-07-31
CVE-2014-7289 EXP SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security:… Patch early 6.5 medium 4.6% 2015-01-21
CVE-2014-6050 EXP phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request. Patch early 5.3 medium 4.6% 2018-08-28
CVE-2006-6242 EXP Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include arbitrary local files via a ..… Patch early 6.8 medium 4.6% 2006-12-03
CVE-2024-28397 EXP An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call. Patch early 5.3 medium 4.5% 2024-06-20
CVE-2006-2971 EXP Integer overflow in the recv_packet function in 0verkill 0.16 allows remote attackers to cause a denial of service (daemon crash) via a UDP packet wit… Patch early 5.0 medium 4.5% 2006-06-12
CVE-2006-2351 EXP Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers… Patch early 4.3 medium 4.5% 2006-05-15
CVE-2005-4584 EXP BZFlag server 2.0.4 and earlier allows remote attackers to cause a denial of service (application crash) via a callsign that is not followed by a NULL… Patch early 5.0 medium 4.5% 2005-12-29
CVE-2010-2273 EXP Multiple cross-site scripting (XSS) vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x… Patch early 4.3 medium 4.5% 2010-06-15
CVE-2007-2524 EXP Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket Request System (OTRS) 2.0.x allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 4.5% 2007-05-08
CVE-2003-0375 EXP Cross-site scripting (XSS) vulnerability in member.php of XMBforum XMB 1.8.x (aka Partagium) allows remote attackers to insert arbitrary HTML and web… Patch early 4.3 medium 4.5% 2003-06-16
CVE-2019-8649 EXP A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is fixed in iOS 1… Patch early 6.1 medium 4.5% 2019-12-18
CVE-2019-8690 EXP A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, mac… Patch early 6.1 medium 4.5% 2019-12-18
← previous page 120 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt