peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-1158 EXP Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows remote attackers to read arbitr… Patch early 5.0 medium 4.5% 2007-03-02
CVE-2008-3606 EXP Heap-based buffer overflow in the IMAP service in Qbik WinGate 6.2.2.1137 and earlier allows remote authenticated users to cause a denial of service (… Patch early 6.5 medium 4.5% 2008-08-12
CVE-2010-3770 EXP Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey be… Patch early 4.3 medium 4.5% 2010-12-10
CVE-2009-1233 EXP Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an XML document containing many… Patch early 4.3 medium 4.4% 2009-04-02
CVE-2012-2904 EXP player.swf in LongTail JW Player 5.9 allows remote attackers to conduct cross-site scripting (XSS) attacks to inject arbitrary web script or HTML via… Patch early 4.3 medium 4.4% 2012-05-21
CVE-2013-1804 EXP Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 4.4% 2014-04-29
CVE-2006-3324 EXP The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attackers to ov… Patch early 5.0 medium 4.4% 2006-06-30
CVE-2008-6927 EXP Multiple cross-site scripting (XSS) vulnerabilities in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allow remote a… Patch early 4.3 medium 4.4% 2009-08-10
CVE-2005-0670 EXP Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web script or HTML via (1) the ne… Patch early 4.3 medium 4.4% 2005-05-02
CVE-2004-1121 EXP Apple Safari 1.0 through 1.2.3 allows remote attackers to spoof the URL displayed in the status bar via TABLE tags. Patch early 5.0 medium 4.4% 2004-11-01
CVE-2018-19782 EXP Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML v… Patch early 6.1 medium 4.4% 2019-01-30
CVE-2008-6768 EXP Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute arbitrary PHP code by uploadi… Patch early 6.8 medium 4.4% 2009-04-29
CVE-2009-0470 EXP Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow remote attackers to inject arbitrary web script or… Patch early 4.3 medium 4.4% 2009-02-06
CVE-2020-10385 EXP A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress. Patch early 5.4 medium 4.4% 2020-03-24
CVE-2018-20009 EXP DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field. Patch early 4.8 medium 4.4% 2018-12-10
CVE-2018-20010 EXP DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field. Patch early 4.8 medium 4.4% 2018-12-10
CVE-2018-20011 EXP DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field. Patch early 4.8 medium 4.4% 2018-12-10
CVE-2000-0636 EXP HP JetDirect printers versions G.08.20 and H.08.20 and earlier allow remote attackers to cause a denial of service via a malformed FTP quote command. Patch early 5.0 medium 4.4% 2000-07-19
CVE-2009-4867 EXP Buffer overflow in Tuniac 090517c allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a lo… Patch early 4.3 medium 4.4% 2010-05-11
CVE-2019-9593 EXP A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or… Patch early 6.1 medium 4.4% 2019-03-06
CVE-2006-1194 EXP Integer signedness error in the enet_protocol_handle_incoming_commands function in protocol.c for ENet library CVS version Jul 2005 and earlier, as us… Patch early 5.0 medium 4.4% 2006-03-13
CVE-2007-5416 EXP Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parame… Patch early 6.8 medium 4.4% 2007-10-12
CVE-2015-8726 EXP wiretap/vwr.c in the VeriWave file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate certain signature and Modulation… Patch early 5.5 medium 4.4% 2016-01-04
CVE-2000-0737 EXP The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator… Patch early 4.6 medium 4.4% 2000-10-20
CVE-2007-2182 EXP Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP files via a t… Patch early 6.8 medium 4.4% 2007-04-24
CVE-2018-7747 EXP Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow remote attackers to inject arbit… Patch early 4.8 medium 4.4% 2018-04-20
CVE-2007-2437 EXP The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to caus… Patch early 5.5 medium 4.4% 2007-05-02
CVE-2015-1060 EXP Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect users to arbitrary web sites a… Patch early 5.8 medium 4.4% 2015-01-16
CVE-2005-3954 EXP Cross-site scripting (XSS) vulnerability in blogBuddies 0.3 allows remote attackers to inject arbitrary web script or HTML via the u parameter to inde… Patch early 4.3 medium 4.4% 2005-12-01
CVE-2015-8736 EXP The mp2t_find_next_pcr function in wiretap/mp2t.c in the MP2T file parser in Wireshark 2.0.x before 2.0.1 does not reserve memory for a trailer, which… Patch early 5.5 medium 4.4% 2016-01-04
← previous page 123 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt