peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-3183 EXP Multiple SQL injection vulnerabilities in Calendarix 0.7.20070307, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL… Patch early 6.8 medium 4.5% 2007-06-26
CVE-2007-6699 EXP Multiple buffer overflows in the AIM PicEditor 9.5.1.8 ActiveX control in YGPPicEdit.dll in AOL You've Got Pictures (YGP) Picture Editor allow remote… Patch early 4.3 medium 4.5% 2008-02-04
CVE-2007-4592 EXP Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, an… Patch early 4.3 medium 4.5% 2008-03-20
CVE-2005-4503 EXP httprint v202, and possibly other versions before v301, allows remote attackers to cause a denial of service (crash) via a long Server field in an HTT… Patch early 5.0 medium 4.5% 2005-12-22
CVE-2017-5631 EXP An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is transmitted in the l… Patch early 6.1 medium 4.5% 2017-05-01
CVE-2006-1356 EXP Stack-based buffer overflow in the count_vcards function in LibVC 3, as used in Rolo, allows user-assisted attackers to execute arbitrary code via a v… Patch early 5.1 medium 4.5% 2006-03-22
CVE-2012-6534 EXP Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllog… Patch early 4.3 medium 4.5% 2013-03-29
CVE-2010-3514 EXP Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 6.1 and 7.0 allows remo… Patch early 4.3 medium 4.5% 2010-10-14
CVE-2007-6500 EXP Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to delete "gateway information" via a re… Patch early 4.9 medium 4.5% 2007-12-20
CVE-2004-0192 EXP Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hija… Patch early 6.8 medium 4.5% 2004-03-15
CVE-2007-3014 EXP Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to inject arbitrary web script o… Patch early 4.3 medium 4.5% 2007-07-15
CVE-2018-19799 EXP Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS. Patch early 6.1 medium 4.5% 2018-12-26
CVE-2012-3524 EXP libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privilege… Patch early 6.9 medium 4.5% 2012-09-18
CVE-2008-7244 EXP Mozilla Firefox 3.0.1 and earlier allows remote attackers to cause a denial of service (browser hang) by calling the window.print function in a loop,… Patch early 5.0 medium 4.5% 2009-09-18
CVE-2007-2932 EXP Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web script or HTML via the blog para… Patch early 4.3 medium 4.5% 2007-05-31
CVE-2006-2922 EXP Multiple PHP remote file inclusion vulnerabilities in MiraksGalerie 2.62 allow remote attackers to execute arbitrary PHP code via a URL in the (1) g_p… Patch early 5.1 medium 4.5% 2006-06-09
CVE-2006-1145 EXP Format string vulnerability in the safe_cprintf function in acebot_cmds.c in Alien Arena 2006 Gold Edition 5.00 allows remote attackers (possibly auth… Patch early 6.5 medium 4.5% 2006-03-10
CVE-2011-1723 EXP Cross-site scripting (XSS) vulnerability in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows remote attackers to inject arbitrary we… Patch early 4.3 medium 4.5% 2011-04-19
CVE-2008-5918 EXP Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php in WebSVN 2.0 and earlier allows remote attackers to inj… Patch early 4.3 medium 4.5% 2009-01-21
CVE-2007-3130 EXP Multiple PHP remote file inclusion vulnerabilities in the OpenWiki (formerly JD-Wiki) component (com_jd-wiki) 1.0.2, and possibly earlier, for Joomla!… Patch early 6.8 medium 4.5% 2007-06-08
CVE-2012-1188 EXP Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 4.3 medium 4.5% 2012-09-26
CVE-2020-7934 EXP In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerab… Patch early 5.4 medium 4.5% 2020-01-28
CVE-2007-2191 EXP Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (… Patch early 6.8 medium 4.5% 2007-04-24
CVE-2003-1414 EXP Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attacke… Patch early 4.3 medium 4.5% 2003-12-31
CVE-2004-2518 EXP Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00") to a URL or (2) an invalid L… Patch early 5.0 medium 4.5% 2004-12-31
CVE-2012-3184 EXP Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6… Patch early 4.3 medium 4.5% 2012-10-17
CVE-2014-5464 EXP Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackers to injec… Patch early 4.3 medium 4.5% 2014-09-08
CVE-2015-2182 EXP Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script or HTML via the (1) schltr par… Patch early 4.3 medium 4.5% 2015-03-11
CVE-2018-13457 EXP qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-servi… Patch early 5.5 medium 4.5% 2018-07-12
CVE-2018-13458 EXP qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-servi… Patch early 5.5 medium 4.5% 2018-07-12
← previous page 122 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt