peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-1204 EXP Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrary web script or HTML via the P… Patch early 4.3 medium 4.5% 2009-04-01
CVE-2015-0003 EXP win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wind… Patch early 6.9 medium 4.5% 2015-02-11
CVE-2011-5207 EXP Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1.1.6 before 2011-12-31 allows… Patch early 4.3 medium 4.5% 2012-10-04
CVE-2017-15223 EXP Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) v… Patch early 5.3 medium 4.5% 2017-10-24
CVE-2001-0791 EXP Trend Micro InterScan VirusWall for Windows NT allows remote attackers to make configuration changes by directly calling certain CGI programs, which d… Patch early 5.0 medium 4.5% 2001-10-18
CVE-2006-6770 EXP Multiple PHP remote file inclusion vulnerabilities in Jinzora Media Jukebox 2.7 and earlier, when register_globals is enabled, allow remote attackers… Patch early 6.8 medium 4.5% 2006-12-27
CVE-2017-3630 EXP Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11… Patch early 5.3 medium 4.5% 2017-06-22
CVE-2009-5065 EXP Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0 allows remote atta… Patch early 4.3 medium 4.5% 2011-04-11
CVE-2014-2045 EXP Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 300 allow remote attackers to in… Patch early 6.1 medium 4.5% 2017-01-20
CVE-2014-1906 EXP Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote att… Patch early 4.3 medium 4.5% 2014-03-06
CVE-2015-4084 EXP Cross-site scripting (XSS) vulnerability in the Free Counter plugin 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 4.5% 2015-05-28
CVE-2008-2333 EXP Cross-site scripting (XSS) vulnerability in ldap_test.cgi in Barracuda Spam Firewall (BSF) before 3.5.11.025 allows remote attackers to inject arbitra… Patch early 4.3 medium 4.5% 2008-05-23
CVE-2011-2938 EXP Multiple cross-site scripting (XSS) vulnerabilities in filter_api.php in MantisBT before 1.2.7 allow remote attackers to inject arbitrary web script o… Patch early 4.3 medium 4.5% 2011-09-21
CVE-2013-1409 EXP Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script o… Patch early 4.3 medium 4.5% 2014-03-03
CVE-2013-2643 EXP Multiple cross-site scripting (XSS) vulnerabilities in Sophos Web Appliance before 3.7.8.2 allow remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 4.5% 2014-03-18
CVE-2009-0275 EXP Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into… Patch early 6.5 medium 4.5% 2009-01-26
CVE-2011-0901 EXP Multiple stack-based buffer overflows in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150, and possibly other… Patch early 6.8 medium 4.5% 2011-02-07
CVE-2019-1125 EXP An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully e… Patch early 5.6 medium 4.5% 2019-09-03
CVE-2012-6550 EXP Cross-site scripting (XSS) vulnerability in ZeroClipboard before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via "the clipTex… Patch early 4.3 medium 4.5% 2013-04-02
CVE-1999-0752 EXP Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake. Patch early 5.0 medium 4.5% 1999-07-06
CVE-2006-3949 EXP PHP remote file inclusion vulnerability in artlinks.dispnew.php in the Artlinks component (com_artlinks) for Mambo allows remote attackers to execute… Patch early 6.8 medium 4.5% 2006-08-01
CVE-2014-3842 EXP Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow remote attackers to inject ar… Patch early 4.3 medium 4.5% 2014-05-22
CVE-2005-0992 EXP Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2-rc1 allows remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 4.5% 2005-05-02
CVE-2002-1473 EXP Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbi… Patch early 4.6 medium 4.5% 2003-04-22
CVE-2006-0703 EXP Unspecified vulnerability in index.php in imageVue 16.1 has unknown impact, probably a cross-site scripting (XSS) vulnerability involving the query st… Patch early 4.3 medium 4.5% 2006-02-15
CVE-2009-2937 EXP Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC att… Patch early 4.3 medium 4.5% 2009-09-18
CVE-2008-1385 EXP Cross-site scripting (XSS) vulnerability in the Top Referrers (aka referrer) plugin in Serendipity (S9Y) before 1.3.1 allows remote attackers to injec… Patch early 4.3 medium 4.5% 2008-04-23
CVE-2020-7680 EXP docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources… Patch early 6.1 medium 4.5% 2020-07-20
CVE-2005-1807 EXP The Data function in class.smtp.php in PHPMailer 1.7.2 and earlier allows remote attackers to cause a denial of service (infinite loop leading to memo… Patch early 5.0 medium 4.5% 2005-05-28
CVE-2010-3171 EXP The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random n… Patch early 5.8 medium 4.5% 2010-09-15
← previous page 121 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt