peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,069 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-4771 EXP Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 4.4% 2012-10-22
CVE-2007-3569 EXP Multiple cross-site scripting (XSS) vulnerabilities in Oliver Library Management System allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 4.4% 2007-07-05
CVE-2012-4949 EXP SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a query… Patch early 6.5 medium 4.4% 2012-11-14
CVE-2012-4989 EXP Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote attackers to inject arbitrary w… Patch early 4.3 medium 4.4% 2012-10-22
CVE-2006-2451 EXP The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of… Patch early 4.6 medium 4.4% 2006-07-07
CVE-2005-3747 EXP Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files… Patch early 5.0 medium 4.4% 2005-11-22
CVE-2007-6110 EXP Cross-site scripting (XSS) vulnerability in htsearch in htdig 3.2.0b6 allows remote attackers to inject arbitrary web script or HTML via the sort para… Patch early 4.3 medium 4.4% 2007-11-23
CVE-2000-0698 EXP Minicom 1.82.1 and earlier on some Linux systems allows local users to create arbitrary files owned by the uucp user via a symlink attack. Patch early 5.0 medium 4.4% 2000-10-20
CVE-2006-4140 EXP Directory traversal vulnerability in IPCheck Server Monitor before 5.3.3.639/640 allows remote attackers to read arbitrary files via modified .. (dot… Patch early 5.0 medium 4.4% 2006-08-14
CVE-2007-5105 EXP Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 and 2.0.1 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 4.4% 2007-09-26
CVE-2006-4923 EXP Cross-site scripting (XSS) vulnerability in search.php in eSyndiCat Portal System allows remote attackers to inject arbitrary web script or HTML via t… Patch early 4.3 medium 4.4% 2006-09-21
CVE-2020-15930 EXP An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag. Patch early 6.1 medium 4.4% 2020-09-24
CVE-2006-1995 EXP Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via ".." sequences in the p paramet… Patch early 5.0 medium 4.4% 2006-04-25
CVE-2007-4088 EXP Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) id,… Patch early 4.3 medium 4.4% 2007-07-30
CVE-2013-6017 EXP Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary web script or HTML via the bo… Patch early 4.3 medium 4.4% 2014-01-12
CVE-2007-6495 EXP inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1)… Patch early 6.5 medium 4.4% 2007-12-20
CVE-2007-5310 EXP PHP remote file inclusion vulnerability in admin.wmtportfolio.php in the webmaster-tips.net wmtportfolio 1.0 (com_wmtportfolio) component for Joomla!… Patch early 6.8 medium 4.4% 2007-10-09
CVE-2007-5390 EXP PHP remote file inclusion vulnerability in index.php in PicoFlat CMS 0.4.14 and earlier allows remote attackers to execute arbitrary PHP code via a UR… Patch early 6.8 medium 4.4% 2007-10-12
CVE-2006-6225 EXP Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a URL in the _CONF[path] parame… Patch early 5.1 medium 4.4% 2006-12-02
CVE-2004-1906 EXP Mcafee FreeScan allows remote attackers to cause a denial of service and possibly arbitrary code via a long string in the ScanParam property of a COM… Patch early 5.0 medium 4.4% 2004-12-31
CVE-2009-1218 EXP Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Ser… Patch early 4.3 medium 4.4% 2009-04-01
CVE-2002-1006 EXP Cross-site scripting (XSS) vulnerability in BBC Education Text to Speech Internet Enhancer (Betsie) 1.5.11 and earlier allows remote attackers to exec… Patch early 6.8 medium 4.4% 2002-10-04
CVE-2003-1472 EXP Buffer overflow in 3D-FTP client 4.0 allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long ban… Patch early 5.0 medium 4.4% 2003-12-31
CVE-2009-2705 EXP CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "… Patch early 4.3 medium 4.4% 2009-08-11
CVE-2006-4917 EXP Cross-site scripting (XSS) vulnerability in search.php in PT News 1.7.8 allows remote attackers to inject arbitrary web script or HTML via the pgname… Patch early 4.3 medium 4.4% 2006-09-21
CVE-2006-2331 EXP Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via (1) a .. (… Patch early 6.4 medium 4.4% 2006-05-12
CVE-2013-4098 EXP ServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote attackers to inject arbitrary error-page text via the message parameter. Patch early 5.0 medium 4.4% 2013-06-28
CVE-2009-2043 EXP nsViewManager.cpp in Mozilla Firefox 3.0.2 through 3.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and applicati… Patch early 4.3 medium 4.4% 2009-06-12
CVE-2006-2736 EXP PHP remote file inclusion vulnerability in blend_data/blend_common.php in Blend Portal 1.2.0, as used with phpBB when register_globals is enabled, all… Patch early 5.1 medium 4.4% 2006-06-01
CVE-2005-1492 EXP Cross-site scripting (XSS) vulnerability in user.cgi in Gossamer Threads Links SQL 2.x and 3.0 allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 4.4% 2005-05-11
← previous page 124 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt